Creating a New Policy
EPICenter Software Installation and User Guide
417
Figure 204: Example of a schedul
e
5
Select the type of policy you want to create. The type of policy you choose will determine the type of
information you need to provide.
The policy type acts as a sort of template, requiring definition only of the components relevant to the
particular policy type.
Select the appropriate Policy Type as follows:
—
select Type to generate access list rules for implementation on the devices in the policy scope.
—
Select Security to specify the components of a policy for traffic between resources and
dynamically obtained user endpoints. A policy of this type will generate access list rules for
implementation of the devices in the access domain. These rules are generated whenever an
authorized user logs on and will be deleted when that user logs off.
—
Select IP to specify the components of a policy for traffic between endpoints, such as a server and
specific clients or a particular service and server.
—
Select VLAN to specify the components (VLANs) of a policy for traffic originating from the
member ports of one or more VLANs. A policy of this type will generate VLAN QoS rules for
implementation on the devices in the policy scope.
—
Select Source Port to specify the components of a policy for traffic originating from specific
ingress ports. A policy of this type generates source physical port QoS rules for implementation
on the devices in the policy scope.
6
Specify the endpoints that will define the traffic flows to which this policy will apply.
For a Security policy:
You must specify two sets of endpoints for a Security policy, which are
classified as network resources and users. The resources you select are typically hosts or users, but
do not need to be in a conventional “client-server” relationship. They simply represent the endpoints
(source and destination, translated to an IP address and port) of the traffic flow. You can specify
individual endpoints, or groups that contain the endpoints. The user end of the specification does
not need to have a specific IP address assigned to it, although it may.
You must also specify the traffic direction to which the policy should apply. The default for an
Access-based Security policy is user to resource.
For an IP policy:
You must specify two sets of endpoints for an IP policy, which are classified as
servers and clients. The resources you select are typically hosts or users, but do not need to be in a
conventional “client-server” relationship. They simply represent the endpoints (source and
destination, translated to an IP address and port) of the traffic flow. You can specify individual
endpoints, or groups that contain the endpoints. You can also specify a subnet address or the “Any”
wildcard as an endpoint.
Summary of Contents for EPICenter 4.1
Page 20: ...20 EPICenter Software Installation and User Guide Preface ...
Page 46: ...46 EPICenter Software Installation and User Guide EPICenter and Policy Manager Overview ...
Page 190: ...190 EPICenter Software Installation and User Guide Configuration Manager ...
Page 204: ...204 EPICenter Software Installation and User Guide Using the Interactive Telnet Application ...
Page 242: ...242 EPICenter Software Installation and User Guide Using the IP MAC Address Finder ...
Page 266: ...266 EPICenter Software Installation and User Guide Using ExtremeView ...
Page 284: ...284 EPICenter Software Installation and User Guide Real Time Statistics ...
Page 436: ...436 EPICenter Software Installation and User Guide Using the Policy Manager ...
Page 454: ...454 EPICenter Software Installation and User Guide The ACL Viewer ...
Page 468: ...468 EPICenter Software Installation and User Guide Troubleshooting ...
Page 504: ...504 EPICenter Software Installation and User Guide EPICenter External Access Protocol ...
Page 510: ...510 EPICenter Software Installation and User Guide EPICenter Database Views ...
Page 522: ...522 EPICenter Software Installation and User Guide EPICenter Backup ...
Page 526: ...526 EPICenter Software Installation and User Guide Dynamic Link Context System DLCS ...
Page 546: ......