set policy rule
10-10 Policy Classification Configuration
Syntax
Thiscommandhastwoformsofsyntax—onetocreateanadminrule(forpolicyID0),andthe
othertocreateaclassificationruleandattach ittoapolicyprofile.
set policy rule admin-profile {vlantag data [mask mask] admin-pid profile-index}
[port-string port-string]
set policy rule profile-index {ether |ipproto | ipdestsocket | ipsourcesocket |
iptos | macdest | macsource |tcpdestport | tcpsourceport | udpdestport |
udpsourceport} data [mask mask] [vlan vlan] [cos cos] | [drop | forward]
Parameters
Thefollowingparametersapplytocreatinganadminrule.
Thefollowingparametersapplytocreatingaclassificationrule.
Note: C3, B3, and G3 devices support the following numbers of unique rules per system.
• 128 L2 DA/SA MAC rules
• 128 L2 Ethertype rules
• 511 L3/L4 rules
These rules can be shared on different ports with different users, but are not shared between
profiles.
Note: Classification rules are automatically enabled when created.
admin‐profile SpecifiesthatthisisanadminruleforpolicyID0.
vlantagdata Classifiesbased onVLANtagspecifiedbydata.Valueofdatacanrange
from1to4094or0xFFF.
maskmask (Optional)Specifiesthenumberofsignificantbitstomatch,dependent
onthedatavalueentered.Valueof
maskcanrangefrom1to12.
RefertoTable 10‐3forvalidvaluesforeachclassificationtypeanddata
value.
admin‐pid
profile‐index
Associatesthisadminrulewithapolicyprofile,identifiedbyitsindex
number.Policyprofilesareconfiguredwiththesetpolicyprofile
commandasdescribed
in“setpolicyprofile”onpage 10‐3.
Validprofile‐indexvaluesare1‐255.
port‐stringport‐string (Optional)Assignsthisruletothespecifiedpolicyprofileonspecific
ingressport(s).Rulewouldnotbeuseduntilpolicyisassignedtothe
specifiedport(s)usingthesetpolicyportcommand
asdescribedin“set
policyport”onpage 10‐14.
profile‐index Specifiesapolicyprofilenumbertowhichthisrulewillbeassigned.
Policyprofilesareconfiguredwiththesetpolicyprofilecommandas
describedin“setpolicyprofile”onpage 10‐3.Validprofile‐indexvalues
are1‐255.
ether ClassifiesbasedontypefieldinEthernetIIpacket.
ipproto
ClassifiesbasedonProtocolfieldinIPpacket.