Specifications
Policy Overview
May 18, 2009 Page 7 of 32
•Appliesboththefilter‐IDandtheVLANtunnelattributesifallattributesexist
Ifallattributesexist,thefollowingrulesapply:
•Thepolicyrolewillbeenforced,withtheexceptionthatany portPVIDspecifiedintherole
willbereplacedwiththeVLANtunnelattributes
•Thepolicymapisignored
becausethepolicyroleisexplicitlyassigned
•VLANclassificationrulesareassignedasdefinedbythepolicyrole
vlanauthorizationmustbeenabledortheVLANtunnelattributesareignoredandthedefault
VLANisused.PleaseseetheConfiguringUserAuthenticationfeatureguidelocat edat
http://secure.enterasys.com/support/manuals/foracompleteVLANAuthorizationdiscussion.
HybridModesupporteliminatesthedependencyofVLAN assignmentbasedonroles.Asa
result,VLANscanbeassignedviathetunnel‐private‐group‐ID,asdefinedperRFC3580,while
assigningrolesviathefilter‐ID.Thisseparationgivesadministratorsmoreflexibilitytosegment
theirnetworksforefficiencybeyondthe
rolelimitsassociatedwiththeB3,C3,andG3platforms.
Device Response to Invalid Policy
Enhanced Policy
Theactionthatthedeviceshouldtakewhenaskedtoapplyaninvalidorunknownpolicycanbe
specified.Theavailableactionsare:
• Ignoretheresultandsearchforthenextpolicyassignmentrule.Ifallrulesaremissed,the
defaultpolicyisapplied.
•Blocktraffic
•Forwardtrafficasifnopolicy
hasbeenassignedusing802.1D/Qrules
Usethesetpolicyinvalidactioncommandtospecifyadefaultactiontotakewhenaskedtoapply
aninvalidorunknownpolicy.
Classification Rules
Classificationrulesassociatespecifictrafficclassificationsorpolicybehaviorswiththepolicyrole.
Therearetwoaspectsofclassificationruleconfiguration:
•Theassociationofatrafficclassificationwithapolicyrolebyassigningthetrafficclassification
toanadministrativeprofile.
•Theassignmentofpolicyrulesthatdefinedesiredpolicybehaviorsfor
thespecifiedtraffic
classificationtype.
Boththeadministrativeprofileandpolicyrulesareassociatedwiththepolicyrolebyspecifying
theadmin‐pidoption,inthecaseofanadministrativeprofile,oraprofile‐indexvalue,inthecase
ofthepolicyrule.Administrativeprofilesandpolicyrulesareconfigured
usingthe setpolicyrule
command.
Theadministrativeprofileassignsatrafficclassificationtoapolicyrolebyusingthe
admin‐profileoptionofthesetpolicyrulecommand.
Note: Standard policy supports the VLAN tag traffic classification for administrative profiles. All
other traffic classifications are enhanced policy in an administrative profile context. See Table 1 for
a listing of supported traffic classifications.