Specifications

Policy Configuration Example
May 18, 2009 Page 28 of 32
•AnameofphoneN3
•AdefaultportVLANof0
•AdefaultCoSof4
BecauseVLANscanbeappliedtoN3portsusingtheappropriatetrafficclassification,theexplicit
denyallPVID0willbeappliedatpolicycreation.Separateratelimitscanbeappliedtothephone
setupandpayload
portsontheN3usingpolicyrules.AdefaultCoSof4willbeappliedatpolicy
rolecreation.
ServicesN3(rw)->set policy profile 5 name phoneN3 pvid-status enable pvid 0
cos-status enable cos 4
Assigning Traffic Classification Rules
ForwardtrafficonUDPsourceportforIPaddressrequest(68)andandforwardtrafficonUDP
destinationportsforprotocolsDHCP(67)andDNS(53)onthephoneVLAN,tofacilitatephone
autoconfigurationand IPaddressassignment.DroptrafficforprotocolsSNMP(161),SSH(22),
Telnet(23)andFTP
(20and21)onthephoneVLAN.
ServicesN3(rw)->set policy rule 5 udpsourceport 68 mask 16 forward
ServicesN3(rw)->set policy rule 5 udpdestportIP 67 mask 16 forward
ServicesN3(rw)->set policy rule 5 udpdestportIP 53 mask 16 forward
ServicesN3(rw)->set policy rule 5 udpdestportIP 161 mask 16 drop
ServicesN3(rw)->set policy rule 5 tcpdestportIP 22 mask 16 drop
ServicesN3(rw)->set policy rule 5 tcpdestportIP 23 mask 16 drop
ServicesN3(rw)->set policy rule 5 tcpdestportIP 20 mask 16 drop
ServicesN3(rw)->set policy rule 5 tcpdestportIP 21 mask 16 drop
ApplyaCoS9tophonesetupdataonVLAN11,ratelimitingthedatato5ppswithahighpriority
of7onport2427.
ApplyaCoS10tophonepayloaddataonVLAN11,ratelimitingthedatato100kbpswithahigh
priorityof7
forbothsourceanddestinationonport5004.
ServicesN3(rw)->set policy rule 5 upddestIP 2427 mask 16 vlan 11 cos 9
ServicesN3(rw)->set policy rule 5 updsourceIP 5004 mask 16 vlan 11 cos 10
ServicesN3(rw)->set policy rule 5 upddestIP 5004 mask 16 vlan 11 cos 10
Assigning the VLAN-to-Policy Association
Thenatureofservicesrelateddevicesthatmightconnecttoaswitchportisnotasstaticaswith
thestudentorfacultyroles.Servicesrelatednetworkneedscanrunthegamutfromtemporary
multimediaeventstostandardofficeusers.TheremaybemultipleVLANandpolicyrole
associationsthattake
careofservicesrelatedneeds,dependingupontheconnecteduser.Thismay
includetherequirementformultipleservicesrelatedroles.
Forservices,thenetworkadministratordesiresgreaterresourceusageflexibilityinassigningthe
policytoVLANassociation.Authenticationinthiscasewillreturnonlythetunnelattributesin
theresponse
messagebasedupontherequirementsoftheauthenticatinguser.Settingthe
VLANtopolicyassociationwillbehandledbythemaptableconfiguration,allowingforeasein
changingthepolicyassociatedwithaVLANontheflyusingPolicyManager.Specifythatthe
tunnelattributesreturnedintheRADIUSresponsemessagewill
beusedbytheauthenticating
user.AssociateVLAN11withpolicyrole5usingthesetpolicymaptablecommand.
ServicesN3(rw)->set policy maptable response tunnel
ServicesN3(rw)->set policy maptable 11 5