clear policy rule
SecureStack C3 Configuration Guide
11-13
This
example
shows
how
to
use
Table 11
‐
3
to
assign
a
rule
to
policy
profile
1
that
will
drop
IP
source
traffic
from
IP
address
1.2.3.4.
If
mask
32
is
not
specified
as
shown,
a
default
mask
of
48
bits
(IP
address
+
port)
would
be
applied:
C3(su)->set policy rule 1 ipsourcesocket 1.2.3.4 mask 32 drop
clear policy rule
Use
this
command
to
delete
policy
classification
rule
entries.
Syntax
This
command
has
two
forms
of
syntax—one
to
clear
an
admin
rule
(for
policy
ID
0),
and
the
other
to
clear
a
classification
rule.
clear policy rule admin-profile
{
vlantag
data
[
mask
mask
]
clear policy rule profile-index
{
all-pid-entries
| {
ether
|
ipproto
|
ipdestsocket
|
ipsourcesocket
|
iptos
|
macdest
|
macsource
|
tcpdestport
|
tcpsourceport
|
udpdestport
|
udpsourceport
}}
Parameters
The
following
parameters
apply
to
deleting
an
admin
rule.
The
following
parameters
apply
to
deleting
a
classification
rule.
admin
‐
profile
Specifies
that
the
rule
to
be
deleted
is
an
admin
rule
for
policy
ID
0.
vlantag
data
Deletes
the
rule
based
on
VLAN
tag
specified
by
data
.
Value
of
data
can
range
from
1
to
4094
or
0xFFF.
mask
mask
(Optional)
Specifies
the
number
of
significant
bits
to
match,
dependent
on
the
data
value
entered.
Value
of
mask
can
range
from
1
to
12.
Refer
to
Table 11
‐
3
for
valid
values
for
each
classification
type
and
data
value
.
profile
‐
index
Specifies
a
policy
profile
for
which
to
delete
classification
rules.
Valid
profile
‐
index
values
are
1
‐
255
.
all
‐
pid
‐
entries
Deletes
all
entries
associated
with
the
specified
policy
profile.
ether
Deletes
associated
Ethernet
II
classification
rule.
ipproto
Deletes
associated
IP
protocol
classification
rule.
ipdestsocket
Deletes
associated
IP
destination
classification
rule.
ipsourcesocket
Deletes
associated
IP
source
classification
rule.
iptos
Deletes
associated
IP
Type
of
Service
classification
rule.
macdest
Deletes
associated
MAC
destination
address
classification
rule.
macsource
Deletes
associated
MAC
source
address
classification
rule.
tcpdestport
Deletes
associated
TCP
destination
port
classification
rule.
tcpsourceport
Deletes
associated
TCP
source
port
classification
rule.
udpdestport
Deletes
associated
UDP
destination
port
classification
rule.
udpsourceport
Deletes
associated
UDP
source
port
classification
rule.
Summary of Contents for SECURESTACK C3
Page 2: ......
Page 34: ...xxxii...
Page 40: ...Getting Help xxxviii About This Guide...
Page 126: ...clear license 4 6 Activating Licensed Features...
Page 132: ...set port inlinepower 5 6 Configuring System Power and PoE...
Page 228: ...clear port protected name 7 60 Port Configuration...
Page 270: ...clear snmp interface 8 42 SNMP Configuration...
Page 396: ...clear port txq 12 10 Port Priority Configuration...
Page 414: ...ip igmp robustness 13 18 IGMP Configuration...
Page 542: ...clear arpinspection statistics 17 32 DHCP Snooping and Dynamic ARP Inspection...
Page 546: ...Enabling Router Configuration Modes 18 4 Preparing for Router Mode...
Page 640: ...traceroute ipv6 21 10 IPv6 Management...
Page 698: ...show ipv6 dhcp binding 24 20 DHCPv6 Configuration...
Page 746: ...show ipv6 ospf virtual link 25 48 OSPFv3 Configuration...
Page 834: ...ip access group 26 88 Authentication and Authorization Configuration...
Page 848: ...TACACS Configuration clear tacacs interface 27 14...
Page 866: ...sFlow Configuration show sflow agent 28 18...
Page 872: ...Index 4...