data:image/s3,"s3://crabby-images/4dbce/4dbce5be764d9c1c1598f66fffefb413babffa7d" alt="Black Box ET0010A Скачать руководство пользователя страница 67"
Creating Policies
68
ETEP CLI User Guide
Related topics:
●
“Policy Configuration” on page 65
●
“Policy Deployment” on page 72
●
Example
The following example adds a policy named BypassOSPF. It is a bypass policy that passes OSPF traffic
(protocol 89) in the clear. This policy will have the highest priority of all the policies on the ETEP.
admin>
configure
config>
policies
policies>
local-site-policies
local-site-policy>
policy-add BypassOSPF
local-site-policy>
policy-config BypassOSPF
local-site-policy>
policy-action bypass
local-site-policy> p
olicy-selector 0.0.0.0/0 0.0.0.0/0 89 any any
local-site-policy>
policy-priority 65500
Table 35
Policy selector commands
Command
Description
policy-layer2-
selector
<ethertype> <vlan>
This command configures Layer 2 selectors. It is valid only when the ETEP is
configured for Layer 2 operation.
Ethertype
The Ethertype field can be entered as a hexadecimal or decimal
value. Hexadecimal values must be preceded by 0x.
VLAN ID
{<vlanID> | any}
Enter a VLAN ID in the range of 1–4094, or enter “any” to accept any VLAN ID.
policy-selector
<remote-ip> <local-ip> <protocol> <remote-port> <local-port>
This command configures Layer 3 selectors.
The defaults are: 0.0.0.0/0 (remote ip), 0.0.0.0/0 (local ip), any (protocol), any
(remote port), any (local port).
remote-ip
IPv4 address and prefix or subnet mask of the endpoint on the far
side of the untrusted network. The ETEP accepts a CIDR prefix or dot-decimal
subnet mask. The default is set to 0.0.0.0/0, which means “process all packets”
coming from any address.
local-ip
IPv4 address and prefix or subnet mask of the local endpoint. The ETEP
accepts a CIDR prefix or dot-decimal subnet mask. The default is set to 0.0.0.0/
0, “process all packets.”
Protocol
A decimal value that identifies the IP layer protocol. “Any” accepts all
protocols. Range is 1-254.
Remote and local ports
A decimal value that identifies the transport layer protocol port number for the
remote or local endpoint. “Any” means “accept all.” Range is 1-65535.
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...