Dell PowerConnect W-Airwave W-Airwave 7.2 Configuration Guide - Page 131

Security > Policies, Add New, Policy, Security > Policies > Add New Policy

Page 131 highlights

Security > Policies The Security > Policies page displays all currently configured policies, to include the policy name, type, and cites the groups, user roles, and folders to which the security policy applies. To create a new policy, click the Add New Policy button. To edit an existing policy, click the pencil icon. The Security > Policies > Add New Policy page contains the following fields, as described in Table 59: Table 59 Security > Policies > Add New Policy Field Descriptions Field Default Description General Settings Folder Name Rules IPv6 Top Blank No Source Traffic Match any Destination Traffic Match any Service Type any Set the folder with which the policy is associated. The drop-down menu displays all folders available for association with the policy. Enter the name of the policy. Select whether to use the IPv6 protocol. If you select No, AMP displays options for the IPv4 protocol instead. NOTE: As of AOS 6.0, you can mix IPv4 and IPv6 rules on one policy. The traffic source, which can be one of the following:  alias: After choosing this option, specify the network resource from the Source Alias drop-down menu that appears. Select the pencil icon to edit, or the plus icon to add a new alias.  any: match any traffic (wildcard)  host: This refers to traffic from a specific host. When this option is chosen, you must configure the source IP address of the host. For example, 2002:d81f:f9f0:1000:c7e:5d61:585c:3ab  localip: (IPv4 only) specify the local IP address to match traffic  network: This refers to a traffic that has a source IP from a subnet of IP addresses. When this option is chosen, you must configure the source address and network mask of the subnet. For example, 2002:ac10:fe:: ffff:ffff:ffff::.  user: This refers to traffic from the wireless client. The traffic destination, which can be any of the same types as the Source Traffic Match options. Type of traffic, which can be one of the following:  any: This option specifies that this rule applies to any type of traffic.  tcp: Using this option, configure a range of TCP port(s) to match for the rule to be applied.  udp: Using this option, configure a range of UDP port(s) to match for the rule to be applied.  service: Selecting this option creates a new field called Service under Service Type with a drop-down list of pre-defined services (common protocols such as HTTPS, HTTP, and others) as the protocol to match for the rule to be applied. Select the pencil icon to edit the Netservice Profile (refer to "Security > Policies > Services" on page 133), or the plus sign to create a new Netservice profile.  protocol: Using this option, specify a different layer 4 protocol (other than TCP/ UDP) by configuring the IP protocol value. Dell PowerConnect W AirWave 7.2 | Configuration Guide Dell PowerConnect W Configuration Reference | 131

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

Dell PowerConnect W AirWave 7.2
| Configuration Guide
Dell PowerConnect W Configuration Reference
|
131
Security > Policies
The
Security > Policies
page displays all currently configured policies, to include the policy name, type, and cites
the groups, user roles, and folders to which the security policy applies. To create a new policy, click the
Add New
Policy
button. To edit an existing policy, click the pencil icon.
The
Security > Policies > Add New Policy
page contains the following fields, as described in
Table 59
:
Table 59
Security > Policies > Add New Policy Field Descriptions
Field
Default
Description
General Settings
Folder
Top
Set the folder with which the policy is associated. The drop-down menu displays all
folders available for association with the policy.
Name
Blank
Enter the name of the policy.
Rules
IPv6
No
Select whether to use the IPv6 protocol. If you select No, AMP displays options for the
IPv4 protocol instead.
NOTE
: As of AOS 6.0, you can mix IPv4 and IPv6 rules on one policy.
Source Traffic Match
any
The traffic source, which can be one of the following:
alias
: After choosing this option, specify the network resource from the
Source
Alias
drop-down menu that appears. Select the pencil icon to edit, or the plus icon
to add a new alias.
any
: match any traffic (wildcard)
host
: This refers to traffic from a specific host. When this option is chosen, you
must configure the source IP address of the host. For example,
2002:d81f:f9f0:1000:c7e:5d61:585c:3ab
localip
: (IPv4 only) specify the local IP address to match traffic
network
: This refers to a traffic that has a source IP from a subnet of IP
addresses. When this option is chosen, you must configure the source address
and network mask of the subnet. For example, 2002:ac10:fe:: ffff:ffff:ffff::.
user
: This refers to traffic from the wireless client.
Destination Traffic Match
any
The traffic destination, which can be any of the same types as the Source Traffic
Match options.
Service Type
any
Type of traffic, which can be one of the following:
any
: This option specifies that this rule applies to any type of traffic.
tcp
: Using this option, configure a range of TCP port(s) to match for the rule to be
applied.
udp
: Using this option, configure a range of UDP port(s) to match for the rule to be
applied.
service
: Selecting this option creates a new field called
Service
under Service
Type with a drop-down list of pre-defined services (common protocols such as
HTTPS, HTTP, and others) as the protocol to match for the rule to be applied.
Select the pencil icon to edit the Netservice Profile (refer to
“Security > Policies >
Services” on page
133
), or the plus sign to create a new Netservice profile.
protocol
: Using this option, specify a different layer 4 protocol (other than TCP/
UDP) by configuring the IP protocol value.