Dell PowerConnect W-Airwave W-Airwave 7.2 Configuration Guide - Page 132

Security > Policies > Destinations, Policies, Security > Policies, Add New Net Destination

Page 132 highlights

Table 59 Security > Policies > Add New Policy Field Descriptions (Continued) Field Default Description Action permit Log if ACL is applied No Mirror all session packets No Queue Priority low Time Range None Pause ARM Scanning No Blacklist user if ACL is applied TOS Value 802.1p Priority No None None Action if rule is applied, which can be one of the following: reject: deny packets. A new field will appear where you can Send Deny Response dst-nat: perform destination NAT on packets. New fields appear to specify the Dual NAT Pool and Dual NAT Port. dual-nat: perform both source and destination NAT on packets permit: forward packets redirect: specify the location to which packets are redirected, which can be one of the following:  Datapath Destination ID (0-65535)  ESI Server Group: specify the ESI server group configured with the esi group command.  Tunnel: specify the ID of the tunnel configured with the interface tunnel command src-nat: perform source NAT on packets NOTE: Permit and reject are the only available actions for IPv6. Whether to generate a log message when the rule is applied. Whether to mirror all session packets to datapath or remote destination. Assigns a matching flow to a priority queue (high/low). Define a time range for this rule. Whether to pause Adaptive Radio Management scan activity when traffic is present. Note that the Scanning setting in the ARM profile should be activated in order to be paused. Refer to "Profiles > RF > 802.11a/g Radio > ARM Profile Settings" on page 103 for this setting. Whether to blacklist any user. Value of type of service (TOS) bits to be marked in the IP header of a packet matching this rule when it leaves the controller. Specify 802.1p priority (0-7). Select Add to complete the configuration of the Policies profile, or click Save to complete the editing of an existing profile. The new policy appears on the Security > Policies page. Security > Policies > Destinations The Security > Policies > Destinations page lists the destination names currently configured, with the Policy that uses the destination and the folder. To create a new destination to be referenced by a security policy, click the Add New Net Destination button. To edit an existing policy, click the pencil icon. The Security > Policies > Add New Destinations page contains the following fields, as described in Table 60: Table 60 Security > Policies > Destinations Field Descriptions Field Default Description General Settings Folder Name Top Blank Set the folder with which the security policy is associated. The dropdown menu displays all folders available for association with the policy. Enter the name of the destination. 132 | Dell PowerConnect W Configuration Reference Dell PowerConnect W AirWave 7.2 | Configuration Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160

132
|
Dell PowerConnect W Configuration Reference
Dell PowerConnect W AirWave 7.2
| Configuration Guide
Select
Add
to complete the configuration of the
Policies
profile, or click
Save
to complete the editing of an
existing profile. The new policy appears on the
Security > Policies
page.
Security > Policies > Destinations
The Security > Policies > Destinations page lists the destination names currently configured, with the Policy
that uses the destination and the folder. To create a new destination to be referenced by a security policy, click
the
Add New Net Destination
button. To edit an existing policy, click the pencil icon.
The
Security > Policies > Add New Destinations
page contains the following fields, as described in
Table 60
:
Action
permit
Action if rule is applied, which can be one of the following:
reject
: deny packets. A new field will appear where you can Send Deny Response
dst-nat
: perform destination NAT on packets. New fields appear to specify the Dual
NAT Pool and Dual NAT Port.
dual-nat
: perform both source and destination NAT on packets
permit:
forward packets
redirect
: specify the location to which packets are redirected, which can be one of
the following:
Datapath Destination ID
(
0-65535
)
ESI Server Group
: specify the ESI server group configured with the esi group
command.
Tunnel:
specify the ID of the tunnel configured with the interface tunnel command
src-nat
: perform source NAT on packets
NOTE
: Permit and reject are the only available actions for IPv6.
Log if ACL is applied
No
Whether to generate a log message when the rule is applied.
Mirror all session packets
No
Whether to mirror all session packets to datapath or remote destination.
Queue Priority
low
Assigns a matching flow to a priority queue (high/low).
Time Range
None
Define a time range for this rule.
Pause ARM Scanning
No
Whether to pause Adaptive Radio Management scan activity when traffic is present.
Note that the Scanning setting in the ARM profile should be activated in order to be
paused. Refer to
“Profiles > RF > 802.11a/g Radio > ARM Profile Settings” on page 103
for this setting.
Blacklist user if ACL is
applied
No
Whether to blacklist any user.
TOS Value
None
Value of type of service (TOS) bits to be marked in the IP header of a packet matching
this rule when it leaves the controller.
802.1p Priority
None
Specify 802.1p priority (0-7).
Table 60
Security > Policies > Destinations Field Descriptions
Field
Default
Description
General Settings
Folder
Top
Set the folder with which the security policy is associated. The drop-
down menu displays all folders available for association with the policy.
Name
Blank
Enter the name of the destination.
Table 59
Security > Policies > Add New Policy Field Descriptions
(Continued)
Field
Default
Description