Set Condition

The Unified Policies Set Condition Screen contains a list of Conditions that you can configure for the Policy (e.g., MAC Condition, IP Condition). When you create a Condition, the Condition(s) you configure must be true before traffic is allowed to flow. Click on a Condition to display the configuration options for the Condition. (Click again on the Condition to close the configuration options.) When you have completed all of the parameters for the Condition(s), click the Next button at the bottom of the screen or click on Set Action on the left side of the screen to move to the next step. If necessary, you can also click the Back button to return to the screen.

Conditions

A brief description of each Condition is provided below. Click the hyperlink for each Condition for detailed configuration instructions.

Note: Some conditions are not supported on certain devices. Please refer to detailed notes of each condition below for supported conditions.

L2 MACs

A MAC Condition applies the Policy to traffic flowing from/to a MAC Address/Group. Note that Layer 2 Conditions (conditions that specify MAC Addresses) are "lost" when traffic passes through a router. For this reason, it may be advisable to specify other types of Conditions (such as a Layer 3 Condition, which specifies IP Addresses) when traffic is expected to travel more than one router hop.

Select the parameter(s) you want to configure by selecting the applicable checkbox. Click on Single to configure a single MAC Address or Group to configure a MAC Group, then enter a MAC address or select a MAC Group from the drop-down menu. (You can also click the Add icon to go to the Groups application and create a new MAC Group.)

L3 IPs

An IP Condition applies the Policy to traffic originating from, or flowing to, an IP Address/Network group. Any IP Address can be masked. Note that a Condition that specifies both a Source and Destination IP Address/Network Group will be rejected by the switch as invalid. However, if you wish to create policies for both Source and Destination traffic, you can create one policy for the Source traffic and a second policy for the Destination traffic.

Select the parameter(s) you want to configure by selecting the applicable checkbox. For Source/Destination IP Address, click on Single to configure a single IP Address (and Shorthand or Subnet Mask, if applicable), or click on Group to configure a Network Group, then enter an IP Address or select a Network Group from the drop-down menu. (You can also click the Add icon to go to the Groups application and create a new Network Group.)

Notes:

Important Note: When creating an IP Condition for a NAT Action you must specify a Network Group in the Condition. NAT will only work when both the Condition and Action specify network groups. To create a "One-to-Many" Condition and action, create a Network Group with a single entry for the Condition.

L3 DSCP/TOS

A DSCP/TOS Condition applies the Policy to incoming traffic that has a specified value in either the DSCP (Differentiated Services Code Point) byte or in the TOS (Type of Service) byte. Both DSCP and TOS are mechanisms used to convey QoS information in the IP header of frames. DSCP and TOS are mutually exclusive - you can use either DSCP or TOS but not both. Click on the applicable button (DSCP or TOS) and enter a value.

L4 Services

A Service Condition applies the policy to Service Protocol traffic (TCP or UDP) flowing from/to two TCP or UDP ports, or to traffic flowing from/to a TCP or UDP Service or Service Group. Select a type of Service Condition you want to configure, then configure the parameter(s) as described below.

L7 Application Visibility

An Application Visibility Condition applies the policy to traffic flowing to/from an Application Group or Application. Note that the drop-down menus are populated with the Application Groups/Applications contained in the Signature Profile for the selected switch. If you select multiple switches, only those Application Groups/Applications common to all switches will be displayed. Also note that the App Name button will not be displayed if you select any OS6900 Switches, as this option is not offered for these devices. If all of the selected switches are OS6860 devices, both the App Group and App Name buttons are displayed.