
Policy Classification Configuration Command Set
Assigning Classification Rules to Policy Profiles
8-32
Matrix DFE-Platinum and Diamond Series Configuration Guide
Command Defaults
•
If
mask
is not specified, all data bits will be considered relevant.
Command Type
Switch command.
Command Mode
Read-Write.
Examples
This example shows how to use
Table 8-3
to create (and enable) a VLAN classification rule to
policy 2, classification 65, to drop packets from a source IP address of 172.16.1.2:
ipxsource
Classifies based on source IPX address.
ipxdest
Classifies based on destination IPX address.
udpportsource
UDP port source - (0 - 65535)
udpportdest
UDP port destination - (0 - 65535)
tcpportsource
TCP port source - (0 - 65535)
tcpportdest
TCP port destination - (0 - 65535)
ipxsourcesocket
Classifies based on source IPX socket.
ipxdestsocket
Classifies based on destination IPX socket.
macsource
Classifies based on MAC source address.
macdest
Classifies based on MAC destination address.
ipfrag
Classifies based on IP fragmentation value.
icmptype
Classifies based on ICMP type.
vlantag
Classifies based on VLAN tag.
tci
Classifies based on Tag Control Information.
port
Classifies based on port-string.
class-data-val
Data Value of meaning
class-data-mask
Number of mask bits to apply to Data Value
Matrix(rw)->
set policy classify 2 65 vlan drop ipsource 172.16.1.2