True Action Selection Panel
Extreme Networks Policy Manager (EPM) 1.2 User Guide
75
True Action Selection Panel
This panel allows you to select from a list of actions for the compare TRUE condition. If the match
conditions are evaluated TRUE, then the actions specified here are executed.
Match Condition Selection Panel
This panel allows you to select from a list of match conditions.
permit
Changes the existing ACL to permit. All packets that match the conditional
statements of the specified ACL are allowed to pass to their destinations.
deny
Changes the existing ACL to deny. All packets that match the conditional
statements of the specified ACL are dropped.
qosprofile
Modifies an existing ACL to set the QoS profile for traffic that matches that
rule.
mirror
This action modifies an existing ACL rule to mirror traffic that matches that
rule, or to stop mirroring that traffic. The mirroring port must be enabled when
mirroring on an ACL rule is turned on. This could be configured earlier, or use
the CLI action to execute CLI commands to configure mirroring at the same
time.
cli
This action executes a CLI command. There is no authentication or checking
the validity of each command. If a command fails, the CLI will log a message
in the EMS log. The message (FieldOne) must be placed in quotes.
snmptrap
This action sends an SNMP trap message to the trap server, with a
configurable ID and message string, when the rule is triggered. The message is
sent periodically with interval <period> seconds. If <period> is 0, or if this
optional parameter is not present, the message is sent only once when the rule
is triggered. The interval must be a multiple of the rule sampling/evaluation
interval, or the value will be rounded down to a multiple of the rule sampling/
evaluation interval. The message (FieldTwo) must be placed in quotes.
syslog
This action sends log messages to the ExtremeXOS EMS sever. The possible
values for message level are: DEBU, INFO, NOTI, WARN, ERRO, and CRIT.
The message is sent periodically with interval <period> seconds. If <period> is
0, or if this optional parameter is not present, the message is sent only once
when the rule is triggered. The interval must be a multiple of the rule
sampling/evaluation interval, or the value will be rounded down to a multiple of
the rule sampling/evaluation interval. The messages are logged on both MSMs,
so if the backup log is sent to the primary MSM, then the primary MSM will
have duplicate log messages. The message (FieldOne) must be placed in
quotes.
global-rule
The global-rule statement is optional and affects how the counters are treated.
An ACL that defines counters can be applied to more than one interface. In
the original release of CLEAR-Flow, however, any counters used in an
expression were only evaluated for that particular interface that the CLEAR-
Flow rule was applied to. Beginning with the ExtremeXOS 11.2 release, you
can specify the global-rule statement so that counters are evaluated for all the
applied interfaces. For example, if a policy that defines a counter is applied to
port 1:1 and 2:1, a CLEAR-Flow rule that used the global-rule statement would
sum up the counts from both ports. Without the global-rule statement, the
CLEAR-Flow rule would only look at the counts received on one port at a time.