Policy Configuration Example
16-14 Configuring Policy
Standard Edge
Edge Switch platforms will be rate-limited using a configured CoS that will be applied to the
student and faculty, and phoneFS policy roles. Policies will be applied dynamically at
authentication using a RADIUS authentication server and the Filter-ID attribute.
Premium Edge
The S-Series Edge Switch will be rate-limited using a configured CoS that is applied to the services
and phoneES policy role. This premium edge platform will be enabled for the following
capabilities:
• Policy Accounting
• Syslog rule usage enabled and set to machine-readable
• Invalid policy action set to drop
• TCI overwrite enabled
Premium Distribution
The S-Series Distribution Switch Router will be rate-limited using a configured CoS. Premium
distribution will be enabled for the following policy capabilities:
• Policy Accounting
• Syslog Rule Usage enabled and set to machine-readable
• Invalid policy action set to drop
• TCI overwrite enabled
Platform Configuration
This section will provide the CLI-based policy configuration on the following platforms:
• Student Fixed Switch
•Faculty Fixed Switch
The CLI configuration for the Services Edge Switch and Distribution Switch are not presented
here. Refer to the S-Series Configuration Guide for that information.
CLI configuration is performed on each platform individually. When using the NetSight Policy
Manager, configuration takes place at a central location and is pushed out to the appropriate
network devices.
For this configuration example, we assume that CoS related configuration has already been
performed. See Chapter 17, Configuring Quality of Service in this book for a complete discussion
of QoS configuration.
Note: CLI command prompts used in this configuration example have the following meaning:
• Enterasys(rw)-> – Input on all platforms used in this example.
• Fixed Switch(rw)-> – Input on all Fixed Switches.
• StudentFS-> – Input on the student Fixed Switch.
• FacultyFS-> – Input on the faculty Fixed Switch.