EasyManua.ls Logo

Extreme Networks EPICenter Guide User Manual

Extreme Networks EPICenter Guide
268 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #174 background imageLoading...
Page #174 background image
Policy Manager Overview
EPICenter Concepts and Solutions Guide
174
traffic, in terms of the minimum and maximum bandwidth and traffic priority, may be different in each
switch because profile QP1 is configured differently in each switch.
Using Groups in Policy Definitions
In many cases, you may want to define multiple policies that should apply to the same set of endpoints,
or that should have the same set of devices as the policy domain or scope. The ability to create groups
of users, hosts, devices, ports, custom applications, and VLANs can make the definition of these policies
easier.
For example, you may want to define several Access List policies to prioritize traffic between several
different application servers and a specific set of users. To accomplish this easily, you could create a
group that contains those users, and then use the group as the user or client endpoint in the traffic
definition for each of the policies you create. Further, you may want to include the same set of network
devices in the scope for these policies. Again, you can create a group for these devices, and use that
group to define the scope for each of the policies.
You can use the Grouping Manager to define a group of users:
Use the EPICenter Grouping Manager to define the user resources, either by entering them
individually through the GUI or by importing them.
Ensure that a mapping relationship exists from each user to an IP address. This is necessary so that
the Policy Manager can use them to create identifiable traffic flows. User-host-IP address
relationships are often created as part of the import process. If Netlogin/DLCS is running on your
Extreme network devices, it may do this mapping for you. You can also create these relationships
directly through the Grouping Manager GUI. In the case of Access-based access-based Security
policies, the user IP is dynamically determined when the user logs into the system
When you have your user resources set up and mapped to IP addresses, you can create a group and
add your users as members of the group.
To create a group for the devices you want to use for the policy scope, you have two options:
You can create a Device Group in the Inventory Manager, and assign the devices to this group.
You can add devices as members of a non-exclusive resource group through the Grouping Manager.
The same device can be a member of multiple groups of this type, so future grouping requirements
do not need to impact the group you set up for your policy scope purpose.
Regardless of how you set up your group, you can then use this group to specify the scope for the
policies you create.
There is one consideration in using a group of devices in a policy scope, which is that the same QoS
profile applies to the entire group. For example, if you specify a group in the policy scope, and assign
profile QP3 to that group, all devices included in the group will then use QP3 for that policy. The
configuration of QP3 may be different on each device, but the policy will always apply QP3, however it
is defined, to the traffic flow defined by the policy. (The Policy Manager does allow you to inspect the
QoS profiles and their association with policies on devices or device ports, and you can adjust the
settings if needed).
The Grouping Manager allows groups to contain members of different resource types, including other
groups. However, when you are setting up groups for use with the Policy Manager, it is recommended
that you create relatively simple groups that contain only the resources that you intend to use for a
single purpose.

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Extreme Networks EPICenter Guide and is the answer not in the manual?

Extreme Networks EPICenter Guide Specifications

General IconGeneral
BrandExtreme Networks
ModelEPICenter Guide
CategorySoftware
LanguageEnglish

Summary

EPICenter Overview

EPICenter Features

Comprehensive overview of the EPICenter software's capabilities and advantages for network management.

Inventory Management

Manages a database of all devices, enabling discovery and status tracking of network components.

The Alarm System

Provides fault detection and alarm handling for network devices, allowing custom alarm definitions.

Getting Started with EPICenter

Starting EPICenter

Details on launching the EPICenter server and client components for initial use.

Creating the Device Inventory

First step in using EPICenter to populate the inventory database through discovery or manual addition.

Managing your Network Assets

Using Discovery to Find Network Devices

Utilizes the Inventory Manager's discovery feature to automatically find network devices running SNMP agents.

Organizing Your Inventory with Device Groups

Groups devices with common characteristics for unit management, simplifying tasks like alarm scoping.

Configuring and Monitoring Your Network

User-Defined Telnet Macros

Enables creation and execution of Telnet macros for automating configuration tasks on multiple devices.

Network-wide VLAN Configuration

Manages VLANs across multiple devices, providing network-wide visibility and configuration capabilities.

Managing Network Security

Management Access Security

Secures switch configuration and traffic monitoring, controlling user access and ensuring confidentiality.

Using RADIUS for EPICenter User Authentication

Configures EPICenter to use an external RADIUS server for robust user authentication and authorization.

Tuning and Debugging EPICenter

Monitoring and Tuning EPICenter Performance

Addresses factors affecting EPICenter performance and provides tuning strategies for optimal operation.

Tuning the Alarm System

Optimizes alarm system performance by disabling unnecessary alarms and scoping them to relevant devices.

EPICenter Utilities

The DevCLI Utility

Command-line utility for managing devices and device groups, useful for bulk operations and automation.

Inventory Export Scripts

Scripts to export device or slot information from EPICenter inventory into CSV format for analysis.

Related product manuals