SecureStack C2 Configuration Guide 9-1
9
Policy Classification Configuration
ThischapterdescribesthePolicyClassificationsetofcommandsandhowtousethem.
Policy Classification Configuration Summary
SecureStackC2devicessupportpolicyprofile‐basedprovisioningofnetworkresourcesby
allowingITadministratorsto:
•Create,changeorremovepolicyprofilesbasedonbusiness‐specificuseofnetworkservices.
•Permitordenyaccesstospecificservicesbycreatingandassigningclassificationruleswhich
mapuserprofilestoprotocol‐basedframefiltering
policiesconfiguredforaparticularVLAN
orClassofService(CoS).
• Assignorunassignportstopolicyprofilessothatonlyportsactivatedforaprofilewillbe
allowedtotransmitframesaccordingly.
Configuring Policy Profiles
Purpose
Toreview,create,changeandremoveuserprofilesthatrelatetobusiness‐drivenpoliciesfor
managingnetworkresources.
For information about... Refer to page...
Policy Classification Configuration Summary 9-1
Configuring Policy Profiles 9-1
Configuring Classification Rules 9-5
Assigning Ports to Policy Profiles 9-14
Configuring Policy Class of Service (CoS) 9-15
Note: It is recommended that you use Enterasys Networks NetSight Policy Manager as an
alternative to CLI for configuring policy classification on the SecureStack C2 devices.
Note: B3, C3, and G3 devices support profile-based CoS traffic rate limiting only. Policy rules
specifying CoS will only rate limit on C2 and B2 devices, including when they are configured on
mixed stacks containing B3 and C3 devices.