Specifications
Configuring Policy
May 18, 2009 Page 18 of 32
• trap - (Optional) An enhanced policy that
enables or disables sending SNMP trap
messages on first rule use.
• disable-port - (Optional) An enhanced policy
that enables or disables the ability to disable
the ingress port on first rule use.
2. In switch command mode, optionally configure
policy rules to associate with a policy role.
See Table 1 on page 8 for traffic
classification-type descriptions and enhanced
policy information.
See the set policy rule command discussion in
the command reference guide that comes with
your device for traffic classification data and
mask information.
• port-string - (Optional) Applies this policy
rule to a specific ingress port. N-Series
devices with firmware versions 3.00.xx and
higher also support the set policy port
command as an alternative way to assign a
profile rule to a port.
• storage-type - (Optional) An enhanced
policy that adds or removes this entry from
non-volatile storage.
• vlan - (Optional) Classifies this rule to a
VLAN ID.
• drop | forward - (Optional) Specifies that
packets within this classification will be
dropped or forwarded.
• cos - (Optional) Specifies that this rule will
classify to a Class-of-Service ID. Valid values
are 0 - 255. A value of -1 indicates that no
CoS forwarding behavior modification is
desired.
• syslog - (Optional) An enhanced policy that
enables or disables sending of syslog
messages on first rule use.
• trap - (Optional) An enhanced policy that
enables or disables sending SNMP trap
messages on first rule use.
• disable-port - (Optional) An enhanced policy
that enables or disables the ability to disable
the ingress port on first rule use.
set policy rule profile-index
classification-type [data] [mask
mask] [port-string port-string]
[storage-type {non-volatile |
volatile}] [vlan vlan] | [drop |
forward] [admin-pid admin-pid
]
[cos cos] [syslog {enable |
disable}][trap { enable | disable}]
[disable-port {enable | disable}]
3. Optionally, for enhanced policy capable devices,
assign a policy role to a port.
set policy port port-name admin-id
4. Optionally, for enhanced policy capable devices,
assign a list of allowed traffic rules that can be
applied to the admin profile for one or
more ports.
set policy allowed-type
port-string traffic-rule rule-list
[append | clear]
Procedure 2 Configuring Classification Rules (continued)
Step Task Command(s)