Creating Policies
66
ETEP CLI User Guide
On the ETEP, policies are prioritized in three broad categories: policies based on appliance
configurations, local-site policies, and distributed key policies. Appliance configuration settings have
the highest priority. Passing TLS traffic in the clear is an example of a policy based on an appliance
configuration setting. Local-site policies have the next highest priority range, and take precedence
over EncrypTight distributed key policies.
When you add a new policy, the ETEP automatically assigns it a priority. To avoid duplicate policy
priorities, the ETEP decrements the priority by one from the highest priority it finds. For example, if
you have two policies with priorities of 65500 and 65499, the ETEP will assign priority 65498 to a
new policy. If you have two policies with non-consecutive priorities, such as 65400 and 65200, a new
policy will be assigned 65399. In many cases you will want to override the default priority
assignments to ensure that traffic is processed in the order in which you intend.
●
Policy keying (protect policies only)
Encryption policies are manually keyed. These keys are static and refreshed only when the policy is
updated.
Related topics:
●
“Assigning Policy Names” on page 66
●
“Configuring a Local Site Bypass or Discard Policy” on page 67
●
“Configuring a Local Site Encryption Policy” on page 69
●
“Policy Deployment” on page 72
Assigning Policy Names
Before you can perform any policy configuration, you must add a policy “container” and give it a name.
The name is referenced in all subsequent policy configuration actions.
Policy names must conform to the following conventions:
●
Policy names can range from 1-32 characters.
●
Valid characters are upper and lower case alpha characters (a-z), numeric characters (0-9), _
(underscore), and - (dash).
●
Policy names must start with an alpha character or an underscore. The first character cannot be a
numeric digit or a dash.
●
Policy names cannot contain a space.
●
Names are case-sensitive.
To add a policy:
1 Enter local-site policy configuration mode.
admin>
configure
config>
policies
policies>
local-site-policies
local-site-policy>
2 Add a policy and assign it a name.
policy-add <name>
3 Repeat step 2 for each policy that you want to add to the ETEP.
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...