clear policy rule
SecureStack C2 Configuration Guide 11-13
ThisexampleshowshowtouseTable 11‐3toassignaruletopolicyprofile1thatwilldropIP
sourcetrafficfromIPaddress1.2.3.4.Ifmask32isnotspecif iedasshown,adefaultmaskof48bits
(IPaddress+port)wouldbeapplied:
C2(su)->set policy rule 1 ipsourcesocket 1.2.3.4 mask 32 drop
clear policy rule
Usethiscommandtodeletepolicyclassificationruleentries.
Syntax
Thiscommandhastwoformsofsyntax—onetoclearan adminrule(forpolicyID0),andtheother
toclearaclassificationrule.
clear policy rule admin-profile {vlantag data [mask mask]
clear policy rule profile-index {all-pid-entries | {ether | icmptype | ipproto |
ipdestsocket | ipsourcesocket | iptos | macdest | macsource | tcpdestport |
tcpsourceport | udpdestport | udpsourceport}}
Parameters
Thefollowingparametersapplytodeletinganadminrule.
Thefollowingparametersapplytodeletingaclassificationrule.
admin‐profile SpecifiesthattheruletobedeletedisanadminruleforpolicyID0.
vlantagdata DeletestherulebasedonVLANtagspecifiedbydata.Valueofdatacan
rangefrom
1to4094or0xFFF.
maskmask (Optional)Specifiesthenumberofsignificantbitstomatch,dependent
onthedatavalueentered.Valueofmaskcanrangefrom1to12.
RefertoTable 11‐3forvalidvaluesforeachclassificationtypeanddata
value.
profile‐index Specifiesapolicyprofileforwhichtodeleteclassificationrules.Valid
profile‐indexvaluesare1‐255.
all‐pid‐entries Deletesallentriesassociatedwiththespecifiedpolicyprofile.
ether DeletesassociatedEthernetIIclassificationrule.
icmptype DeletesassociatedICMPclassificationrule.
ipproto DeletesassociatedIPprotocolclassificationrule.
ipdestsocket DeletesassociatedIP
destination classificationrule.
ipsourcesocket DeletesassociatedIPsourceclassificationrule.
iptos DeletesassociatedIPTypeofServiceclassificationrule.
macdest DeletesassociatedMACdestinationaddressclassificationrule.
macsource DeletesassociatedMACsourceaddressclassificationrule.
tcpdestport DeletesassociatedTCPdestinationportclassificationrule.
tcpsourceport DeletesassociatedTCPsourceportclassificationrule.