
UNP Overview
Configuring Universal Network Profiles
page 27-14
OmniSwitch AOS Release 7 Network Configuration Guide
June 2013
What are UNP Classification Rules?
The UNP classification rules allow the administrator to assign devices to a profile based on the source IP,
source MAC address, or VLAN tag of a device connected to a UNP port. Classification rules are associ-
ated with a profile and are applied to traffic received on UNP-enabled ports. When any of the traffic
matches one of the UNP rules, the traffic is then dynamically assigned to the VLAN or service associated
with the matching UNP.
Enabling classification and defining classification rules is optional with UNP. When enabled, however,
classification rules are only applied to UNP-ports when one of the following occurs:
•
MAC authentication is disabled on the port.
•
MAC authentication is enabled but the RADIUS server is not configured.
•
MAC authentication is enabled but RADIUS authentication failed.
If classification is disabled on a UNP port, classification rules are not applied to traffic received on that
port. If both authentication and classification are disabled on a UNP port, traffic received on that port is
blocked, unless a default UNP or trust VLAN tag is configured for that port.
Rule Type and Precedence
When UNP port traffic matches one of the classification rules, the UNP with the matching rule is applied
to that traffic. The device sending the traffic is then dynamically assigned to the VLAN associated with
that UNP.
In the event that UNP port traffic matches more than one classification rule, the following rule precedence
is applied to determine which UNP to apply to the traffic.
“Configuring UNP Classification Rules” on page 27-36
.
Precedence Step/Rule Type
Matching Condition
1. MAC a VLAN tag
Packet contains a matching source MAC address
and
VLAN ID tag.
2. MAC address
Packet contains a matching source MAC address.
3. MAC address range + VLAN tag
Packet contains a source MAC address that falls
within a specified range of MAC addresses
and
a
matching VLAN ID tag.
4. MAC address range
Packet contains a source MAC address that falls
within a specified range of MAC addresses.
5. IP a VLAN tag
Packet contains a matching source IP address
and
VLAN ID tag.
6. IP address
Packet contains a matching source IP address.
7. VLAN tag
Packet contains a matching VLAN ID tag.