Specifications

Policy Overview
May 18, 2009 Page 10 of 32
storagedoespersistafteraresetofthedevice.Usethestoragetypeoptiontospecifythedesired
storagetypeforthispolicyruleentryinanenhancedpolicycontext.
Forward and Drop
Packetsforthisentrycanbeeitherforwardedordropped forthistrafficclassificationusingthe
forwardanddroppolicyruleoptions.
Allowed Traffic Rule-Type on a Port
Enhanced Policy
Allowedtrafficruletypeonaportisanenhancedpolicythatprovidesforthesetting,foreach
port,ofthetrafficclassificationruletypesthatwillbeallowedorignoredinanadminprofile.By
default,alltrafficruletypesareallowed.
Usethesetpolicyallowedtypecommandto
configureasubsetoftrafficruletypesthatwillbe
allowedonthespecifiedports.Allunspecifiedtraffic ruletypeswillbesettoignore.Theappend
optionprovidesfortheadditionofspecifiedruletypesforthecurrentsubsetofallowed
ruletypes.Theclearoptionprovidesforthe
subtractionofspecifiedruletypesfromthecurrent
subsetofallowedruletypes.
Usetheshowpolicyallowedtypecommandtodisplayatableofthecurrentallowedandignored
trafficruletypesforthespecifiedport(s).
SeeTable 1onpage 8foralistingofsupportedallowedtrafficclassificationruletypes.Use
the
attributeIDvalue,specifiedinTable 1,intherulelistforthesetpolicyallowedtypecommandto
identifythetrafficclassificationtobeaddedtoordeletedfromtheallowedtypelistforthe
specifiedports.
Policy Accounting
Enhanced Policy
Policyaccountingisanenhancedpolicycapabilitythatcontrolsthecollectionofclassificationrule
hits.Ifahitoccursonapolicyrule,policyaccountingflagsthatthehithasoccurredandwill
remainflaggeduntilcleared.Policyaccountingisenabledbydefault.Policyaccountingcanbe
enabledordisabledusing
thesetpolicyaccountingcommand.
Policy Syslog Rule Usage
Enhanced Policy
Policysyslogruleusageisanenhancedpolicycapabilitythatprovidesforthesettingofruleusage
messageformattingtomachine‐orhumanreadableandsetsthecontrolforextendedsyslog
messageformat.
Enablingthemachinereadableoptionformatstheruleusagemessagesinarawdataformat that
canthen
beparsedbyauserwrittenscriptingbackend.Thisprovidestheenterprisewiththe
abilitytoformatthedatainamannerthatismostusefultotheenterprise.Disablingthe
machinereadableoptionformatsthesameruleusagedatainahumanreadableformat.
Settingsyslogruleusagetoextended
formatincludesadditionalinformationintheruleusage
syslogmessage.Thedataincludedintheextendedformatisasfollows:VLANand COSassigned,
andthefollowingfieldsfoundinthepacket:DESTMAC,SRCMAC,TAG(8100:tci),EtherType,