Specifications
Policy Configuration Example
May 18, 2009 Page 22 of 32
Roles
Theexampledefinesthefollowingroles:
• guest‐Usedasthedefaultpolicyforallunauthenticatedports.ConnectsaPCtothenetwork
providinginternetonlyaccesstothenetwork.Providesguestaccesstoalimitednumberof
N3portstobeusedspecificallyfor internetonlyaccess.Policyisapplied
usingtheportlevel
defaultconfiguration,orbyauthentication,inthecaseoftheN3portinternetonlyaccessPCs.
• student‐ConnectsadormroomPCtothenetworkthrougha“Student”SecureStackC3port.
AconfiguredCoSratelimitsthePC.Configuredrulesdenyaccesstoadministrativeand
facultyservers.
ThePCauthenticatesusingRADIUS.Hybridauthenticationisenabled.The
studentpolicyroleisappliedusingthefilter‐IDattribute.ThebaseVLANisappliedusingthe
tunnelattributesreturnedintheRADIUSresponsemessage.Ifallrulesaremissed,the
settingsconfiguredinthestudentpolicyprofileareapplied.
• phoneSS‐ConnectsadormroomorfacultyofficeVoIPphonetothenetworkusinga
SecureStackport.AconfiguredCoSratelimitsthephoneandappliesahighpriority.The
phoneauthenticatesusingRADIUS.Hybridauthenticationisenabled.Policyisappliedusing
thefilter‐IDreturnedintheRADIUSresponse
message.ThebaseVLANisappliedusingthe
tunnelattributesreturnedintheRADIUSresponsemessage.Ifallrulesaremissed,the
settingsconfiguredinthephoneSSpolicyprofileareapplied.
• faculty‐ConnectsafacultyofficePCtothe networkthrougha“Faculty”SecureStackC3port.
AconfiguredCoSratelimits
thePC.Aconfiguredruledeniesaccesstotheadministrative
servers.ThePCauthenticatesusingRADIUS.Hybridauthenticationisenabled.Thefaculty
policyroleisappliedusingthefilter‐IDattribute.ThebaseVLANisappliedusingthetunnel
attributesreturnedintheRADIUSresponsemessagefortheauthenticatinguser.
Ifallrules
aremissed,thesettingsconfiguredinthefacultypolicyprofileareapplied.
• phoneN3‐ConnectsaservicesVoIPphonetothenetworkusinganN3port.Aconfigured
CoSratelimitsthephoneforbothsetupandpayload,andappliesahighpriority.Thephone
authenticatesusingRADIUS.
Tunnelauthenticationisenabled.ThebaseVLANisapplied
usingthetunnelattributesreturnedintheRADIUSresponsemessage.Policyisappliedusing
amaptableconfiguration.Ifallrulesaremissed,thesettingsconfiguredinthephoneN3
policyprofileareapplied.
• services‐ConnectsaservicesPCtothenetworkthroughan
N3port.AconfiguredCoSrate
limitsthePC.Services aredeniedaccesstoboththestudentandfacultyservers.ThePC
authenticatesusingRADIUS.ThebaseVLANisappliedusingthetunnelattributesreturned
intheRADIUSresp onsemessagefortheauthenticatinguser.Theservicespolicyroleis
applied
usingapolicymaptablesetting.Thepolicyaccounting,syslog,invalidactionand TCI
overwriteenhancedpoliciesareenabledforthisrole.Ifallrulesaremissed,thesettings
configuredintheservicespolicyprofileareapplied.
• distribution‐TheDistributionpolicyroleisappliedatthedistributionlayerprovidingrate
limiting.
Policy Domains
Itisusefultobreakuppolicyimplementationintologicaldomainsforeaseofunderstandingand
configuration.Forthisexample,itisusefultoconsiderfourdomains:basicedge,standardedgeon
theSecureStacks,premiumedgeontheN3,andpremiumdistribution.