set policy rule
9-10 Policy Classification Configuration
set policy rule admin-profile {vlantag data [mask mask] admin-pid profile-index}
[port-string port-string]
set policy rule profile-index {ether |icmptype | ipproto | ipdestsocket |
ipsourcesocket | iptos | macdest | macsource |tcpdestport | tcpsourceport |
udpdestport | udpsourceport} data [mask mask] [vlan vlan] [cos cos] | [drop |
forward]
Parameters
Thefollowingparametersapplytocreatinganadminrule.
Thefollowingparametersapplytocreatingaclassificationrule.
Note: Classification rules are automatically enabled when created.
admin‐profile SpecifiesthatthisisanadminruleforpolicyID0.
vlantagdata Classifiesbased onVLANtagspecifiedbydata.Valueofdatacanrange
from1to4094or0xFFF.
maskmask (Optional)Specifiesthenumberofsignificantbitstomatch,dependent
onthedatavalueentered.Valueof
maskcanrangefrom1to12.
RefertoTable 9‐3forvalidvaluesforeachclassificationtypeanddata
value.
admin‐pid
profile‐index
Associatesthisadminrulewithapolicyprofile,identifiedbyitsindex
number.Policyprofilesareconfiguredwiththesetpolicyprofile
commandasdescribed
in“setpolicyprofile”onpage 9‐3.
Validprofile‐indexvaluesare1‐255.
port‐stringport‐string (Optional)Assignsthisruletothespecifiedpolicyprofileonspecific
ingressport(s).Rulewouldnotbeuseduntilpolicyisassignedtothe
specifiedport(s)usingthesetpolicyportcommand
asdescribedin“set
policyport”onpage 9‐14.
profile‐index Specifiesapolicyprofilenumbertowhichthisrulewillbeassigned.
Policyprofilesareconfiguredwiththesetpolicyprofilecommandas
describedin“setpolicyprofile”onpage 9‐3.Validprofile‐indexvaluesare
1‐255.
ether ClassifiesbasedontypefieldinEthernetIIpacket.
icmptype
ClassifiesbasedonICMPtype.
ipproto ClassifiesbasedonProtocolfieldinIPpacket.
ipdestsocket ClassifiesbasedondestinationIPaddresswithoptionalpost‐fixedport.
ipsourcesocket ClassifiesbasedonsourceIPaddress,withoptionalpost‐fixedport.
iptos ClassifiesbasedonTypeofServicefieldinIPpacket.
macdest ClassifiesbasedonMACdestination
address.
macsource ClassifiesbasedonMACsourceaddress.
tcpdestport ClassifiesbasedonTCPdestinationport.
tcpsourceport ClassifiesbasedonTCPsourceport.