Adding a Rule Above an Existing Policy Rule
A policy rule can be added above an existing policy rule.
To add a policy rule above an existing policy rule, complete the following steps:
-
In the HPE Aruba Networking Central landing page, select a site from the Sites menu.
Alternatively, you can click the expand
icon on the Sites menu to search for a site from the list.The site dashboard is displayed with the network and connectivity information for the site.
-
Click the configuration
icon. -
Click the Roles & Policies tab.
-
Under Security Policies card, click Manage.
-
Under Role-based Policies tile, click Manage.
-
In the Role-based Policies table, expand an existing policy.
-
Hover over an existing policy rule and click the ellipsis
icon. -
Click .
The Create Rule panel is displayed on the right.
-
Configure the following parameters:
-
Description—Enter a description of the rule.
-
Source—Select a source from the drop-down list. The following options are available:
-
Any
-
Access Role
-
Network
-
Host
-
Network Destination
Note:When you select Network or Host from the Service/Application drop-down list, the Use Alias check box is displayed. When you select the check box, the corresponding Alias parameter is displayed. Click the New Alias option to create a new alias under the rule. For more information, see Creating a Service.
-
-
Source Role Options——Select role options from the drop-down list. The following options are available:
-
Role
-
Network Destination
-
Host
-
Network
-
Local IP
-
User
-
Any
-
-
Destination—Select a destination from the drop-down list.
-
Access Role—Select an access role from the drop-down list. You can also create a new access role by clicking the New Role option under Access Role. For more information, see Creating a Role.
-
Service/Application—Select a service or an application from the drop-down list. The following options are available:
-
Any
-
Service
-
Application
-
Application Category
-
Web Category/Reputation
Note:Depending on the option that you select from the Service/Application drop-down list, the corresponding parameter is displayed.
When you select Service from the Service/Application drop-down list, the corresponding Service parameter is displayed. You can also create a new service by clicking the New Service option under Service. For more information, see Creating a Service.
-
-
Service/Application/Application Category/Web Category/Reputation—Select one from the drop-down list.
-
Action—Select an action from the drop-down list.
-
Time Profile—Allows you to apply the rule only during certain times (e.g., business hours).
-
Log—Enable logging for traffic that matches this rule.
-
QoS—Select Quality of Service options for both dropdowns: DSCP and 802.1P.
-
DSCP —Differentiated Services Code Point for prioritizing traffic.
-
802.1P —Layer 2 priority marking for traffic classification.
-
-
Create Another—Quickly create another rule after saving this one.
-
-
Click Create.
The new policy rule is added above the existing policy rule to the specified role-based policy.
Gateways and policies do not support alias IPv6 configuration. Hence, the Network and Host options under Source and Destination drop-down list are not applicable to IPv6 configuration of gateways.
The following image displays the option to add a policy rule above an existing policy rule.
Figure 1: Add a Rule Above an Existing Policy Rule