Specifications

Policy Configuration Example
May 18, 2009 Page 22 of 32
Roles
Theexampledefinesthefollowingroles:
guest‐Usedasthedefaultpolicyforallunauthenticatedports.ConnectsaPCtothenetwork
providinginternetonlyaccesstothenetwork.Providesguestaccesstoalimitednumberof
N3portstobeusedspecificallyfor internetonlyaccess.Policyisapplied
usingtheportlevel
defaultconfiguration,orbyauthentication,inthecaseoftheN3portinternetonlyaccessPCs.
student‐ConnectsadormroomPCtothenetworkthrougha“Student”SecureStackC3port.
AconfiguredCoSratelimitsthePC.Configuredrulesdenyaccesstoadministrativeand
facultyservers.
ThePCauthenticatesusingRADIUS.Hybridauthenticationisenabled.The
studentpolicyroleisappliedusingthefilterIDattribute.ThebaseVLANisappliedusingthe
tunnelattributesreturnedintheRADIUSresponsemessage.Ifallrulesaremissed,the
settingsconfiguredinthestudentpolicyprofileareapplied.
phoneSS‐ConnectsadormroomorfacultyofficeVoIPphonetothenetworkusinga
SecureStackport.AconfiguredCoSratelimitsthephoneandappliesahighpriority.The
phoneauthenticatesusingRADIUS.Hybridauthenticationisenabled.Policyisappliedusing
thefilterIDreturnedintheRADIUSresponse
message.ThebaseVLANisappliedusingthe
tunnelattributesreturnedintheRADIUSresponsemessage.Ifallrulesaremissed,the
settingsconfiguredinthephoneSSpolicyprofileareapplied.
faculty‐ConnectsafacultyofficePCtothe networkthrougha“Faculty”SecureStackC3port.
AconfiguredCoSratelimits
thePC.Aconfiguredruledeniesaccesstotheadministrative
servers.ThePCauthenticatesusingRADIUS.Hybridauthenticationisenabled.Thefaculty
policyroleisappliedusingthefilterIDattribute.ThebaseVLANisappliedusingthetunnel
attributesreturnedintheRADIUSresponsemessagefortheauthenticatinguser.
Ifallrules
aremissed,thesettingsconfiguredinthefacultypolicyprofileareapplied.
phoneN3‐ConnectsaservicesVoIPphonetothenetworkusinganN3port.Aconfigured
CoSratelimitsthephoneforbothsetupandpayload,andappliesahighpriority.Thephone
authenticatesusingRADIUS.
Tunnelauthenticationisenabled.ThebaseVLANisapplied
usingthetunnelattributesreturnedintheRADIUSresponsemessage.Policyisappliedusing
amaptableconfiguration.Ifallrulesaremissed,thesettingsconfiguredinthephoneN3
policyprofileareapplied.
services‐ConnectsaservicesPCtothenetworkthroughan
N3port.AconfiguredCoSrate
limitsthePC.Services aredeniedaccesstoboththestudentandfacultyservers.ThePC
authenticatesusingRADIUS.ThebaseVLANisappliedusingthetunnelattributesreturned
intheRADIUSresp onsemessagefortheauthenticatinguser.Theservicespolicyroleis
applied
usingapolicymaptablesetting.Thepolicyaccounting,syslog,invalidactionand TCI
overwriteenhancedpoliciesareenabledforthisrole.Ifallrulesaremissed,thesettings
configuredintheservicespolicyprofileareapplied.
distribution‐TheDistributionpolicyroleisappliedatthedistributionlayerprovidingrate
limiting.
Policy Domains
Itisusefultobreakuppolicyimplementationintologicaldomainsforeaseofunderstandingand
configuration.Forthisexample,itisusefultoconsiderfourdomains:basicedge,standardedgeon
theSecureStacks,premiumedgeontheN3,andpremiumdistribution.