Adding a Rule Above an Existing Policy Rule

A policy rule can be added above an existing policy rule.

To add a policy rule above an existing policy rule, complete the following steps:

  1. In the HPE Aruba Networking Central landing page, select a site from the Sites menu.

    Alternatively, you can click the expand icon on the Sites menu to search for a site from the list.

    The site dashboard is displayed with the network and connectivity information for the site.

  2. Click the configuration icon.

  3. Click the Roles & Policies tab.

  4. Under Security Policies card, click Manage.

  5. Under Role-based Policies tile, click Manage.

  6. In the Role-based Policies table, expand an existing policy.

  7. Hover over an existing policy rule and click the ellipsis icon.

  8. Click Add Rule Above.

    The Create Rule panel is displayed on the right.

  9. Configure the following parameters:

    • Description—Enter a description of the rule.

    • Source—Select a source from the drop-down list. The following options are available:

      • Any

      • Access Role

      • Network

      • Host

      • Network Destination

      Note:

      When you select Network or Host from the Service/Application drop-down list, the Use Alias check box is displayed. When you select the check box, the corresponding Alias parameter is displayed. Click the New Alias option to create a new alias under the rule. For more information, see Creating a Service.

    • Source Role Options——Select role options from the drop-down list. The following options are available:

      • Role

      • Network Destination

      • Host

      • Network

      • Local IP

      • User

      • Any

    • Destination—Select a destination from the drop-down list.

    • Access Role—Select an access role from the drop-down list. You can also create a new access role by clicking the New Role option under Access Role. For more information, see Creating a Role.

    • Service/Application—Select a service or an application from the drop-down list. The following options are available:

      • Any

      • Service

      • Application

      • Application Category

      • Web Category/Reputation

      Note:

      Depending on the option that you select from the Service/Application drop-down list, the corresponding parameter is displayed.

      When you select Service from the Service/Application drop-down list, the corresponding Service parameter is displayed. You can also create a new service by clicking the New Service option under Service. For more information, see Creating a Service.

    • Service/Application/Application Category/Web Category/Reputation—Select one from the drop-down list.

    • Action—Select an action from the drop-down list.

    • Time Profile—Allows you to apply the rule only during certain times (e.g., business hours).

    • Log—Enable logging for traffic that matches this rule.

    • QoS—Select Quality of Service options for both dropdowns: DSCP and 802.1P.

      • DSCP —Differentiated Services Code Point for prioritizing traffic.

      • 802.1P —Layer 2 priority marking for traffic classification.

    • Create Another—Quickly create another rule after saving this one.

  10. Click Create.

    The new policy rule is added above the existing policy rule to the specified role-based policy.

Note:

Gateways and policies do not support alias IPv6 configuration. Hence, the Network and Host options under Source and Destination drop-down list are not applicable to IPv6 configuration of gateways.

The following image displays the option to add a policy rule above an existing policy rule.

Figure 1: Add a Rule Above an Existing Policy Rule