IP Subnet Specify the IP address or subnet address associated with the defined rule. Traffic from this address
will be subject to the defined rule. Valid values are:
•
User Defined. Specify the destination IP address and mask. Use this option to explicitly define
the IP/subnet aspect of the rule.
•
Any IP - Maps the rule to the associated Topology IP address.
•
Select a specific subnet value - Select to map the rule to the associated topology segment
definition (IP address/mask).
•
FQDN - Allows for filtering on fully qualified domain names.
•
Other subnet options include:
•
Sepectralink Mcst
•
Vocera Mcst
•
mDNS/Bonjour
Port
The port or port type associated with the defined rule. Traffic from this port is subject to the
defined rule. Valid values are:
•
User Defined, then type the port number. Use this option to explicitly specify the port number.
•
A specific port type. The appropriate port number or numbers are added to the Port text field.
3 Select
Save
.
All rule types are applied to the policy in top to bottom order. The policy is installed on the enforced
APs.
Application (Layer 7) Rules
An
application rule
leverages the AP's deep packet inspection (DPI) engine to detect the underlying
application to which a frame or flow belongs. The rule then applies access control and quality of service
actions to all the traffic associated with the application, not just traffic destined for specific IP addresses
or ports. The control actions regulate both access control and traffic engineering (rate limit, marking,
and prioritization) for applications and groups.
Use case examples include:
•
Identifying critical applications and assigning a higher priority and CoS value.
•
Blocking restricted web content.
•
Blocking or limiting peer-to-peer protocols to preserve bandwidth and flows for other applications.
•
Limiting bandwidth usage by non-business related traffic.
ExtremeCloud Appliance installs application policies with rules on the supported APs where
enforcement occurs.
Note
Application policies are supported by ExtremeCloud Appliance-enabled APs only, not
switches.
Rules
Application policies consist of rules with matching criteria, coupled with one or more actions to take
when a packet matches the rule's criteria. The matching criteria for an application is usually just the
name of the application. The ExtremeCloud Appliance user interface lets you first select a category of
applications, resulting in a subset of applications to choose from. Additionally, you can create a single
rule that applies to all traffic in the application category by selecting a category and then selecting 'any'
as the specific application.
Configure
ExtremeCloud Appliance User Guide for version 4.36.03
132