SecureStack C2 Configuration Guide 11-1
11
Policy Classification Configuration
ThischapterdescribesthePolicyClassificationsetofcommandsandhowtousethem.
Policy Classification Configuration Summary
SecureStackC2devicessupportpolicyprofile‐basedprovisioningofnetworkresourcesby
allowingITadministratorsto:
•Create,changeorremovepolicyprofilesbasedonbusiness‐specificuseofnetworkservices.
•Permitordenyaccesstospecificservicesbycreatingandassigningclassificationruleswhich
mapuserprofilestoprotocol‐basedframefiltering
policiesconfiguredforaparticularVLAN
orClassofService(CoS).
• Assignorunassignportstopolicyprofilessothatonlyportsactivatedforaprofilewillbe
allowedtotransmitframesaccordingly.
Configuring Policy Profiles
Purpose
Toreview,create,changeandremoveuserprofilesthatrelatetobusiness‐drivenpoliciesfor
managingnetworkresources.
For information about... Refer to page...
Policy Classification Configuration Summary 11-1
Configuring Policy Profiles 11-1
Configuring Classification Rules 11-6
Assigning Ports to Policy Profiles 11-15
Configuring Policy Class of Service (CoS) 11-17
Note: It is recommended that you use Enterasys Networks NetSight Policy Manager as an
alternative to CLI for configuring policy classification on the SecureStack C2 devices.
Note: B3, C3, and G3 devices support profile-based CoS traffic rate limiting only. Policy rules
specifying CoS will only rate limit on D2, C2 and B2 devices, including when C2 and B2 devices are
configured on mixed stacks containing B3 and C3 devices.