Specifications
Policy Overview
May 18, 2009 Page 10 of 32
storagedoespersistafteraresetofthedevice.Usethestorage‐typeoptiontospecifythedesired
storagetypeforthispolicyruleentryinanenhancedpolicycontext.
Forward and Drop
Packetsforthisentrycanbeeitherforwardedordropped forthistrafficclassificationusingthe
forwardanddroppolicyruleoptions.
Allowed Traffic Rule-Type on a Port
Enhanced Policy
Allowedtrafficrule‐typeonaportisanenhancedpolicythatprovidesforthesetting,foreach
port,ofthetrafficclassificationrule‐typesthatwillbeallowedorignoredinanadmin‐profile.By
default,alltrafficrule‐typesareallowed.
Usethesetpolicyallowed‐typecommandto
configureasubsetoftrafficrule‐typesthatwillbe
allowedonthespecifiedports.Allunspecifiedtraffic rule‐typeswillbesettoignore.Theappend
optionprovidesfortheadditionofspecifiedrule‐typesforthecurrentsubsetofallowed
rule‐types.Theclearoptionprovidesforthe
subtractionofspecifiedrule‐typesfromthecurrent
subsetofallowedrule‐types.
Usetheshowpolicyallowed‐typecommandtodisplayatableofthecurrentallowedandignored
trafficrule‐typesforthespecifiedport(s).
SeeTable 1onpage 8foralistingofsupportedallowedtrafficclassificationrule‐types.Use
the
attributeIDvalue,specifiedinTable 1,intherulelistforthesetpolicyallowed‐typecommandto
identifythetrafficclassificationtobeaddedtoordeletedfromtheallowed‐typelistforthe
specifiedports.
Policy Accounting
Enhanced Policy
Policyaccountingisanenhancedpolicycapabilitythatcontrolsthecollectionofclassificationrule
hits.Ifahitoccursonapolicyrule,policyaccountingflagsthatthehithasoccurredandwill
remainflaggeduntilcleared.Policyaccountingisenabledbydefault.Policyaccountingcanbe
enabledordisabledusing
thesetpolicyaccountingcommand.
Policy Syslog Rule Usage
Enhanced Policy
Policysyslogruleusageisanenhancedpolicycapabilitythatprovidesforthesettingofruleusage
messageformattingtomachine‐orhuman‐readableandsetsthecontrolforextendedsyslog
messageformat.
Enablingthemachine‐readableoptionformatstheruleusagemessagesinarawdataformat that
canthen
beparsedbyauser‐writtenscriptingbackend.Thisprovidestheenterprisewiththe
abilitytoformatthedatainamannerthatismostusefultotheenterprise.Disablingthe
machine‐readableoptionformatsthesameruleusagedatainahumanreadableformat.
Settingsyslogruleusagetoextended
‐formatincludesadditionalinformationintheruleusage
syslogmessage.Thedataincludedintheextendedformatisasfollows:VLANand COSassigned,
andthefollowingfieldsfoundinthepacket:DESTMAC,SRCMAC,TAG(8100:tci),EtherType,