Service Policy Profile
The Service Policy profile allows you to configure how services are advertised on the network. It allows administrators to enable or disable services, and control access by allowing or disallowing specific user roles and VLANs. You can also configure policies to define service visibility and access. Advanced options provide additional control over how services are discovered and Service IDs, helping maintain a secure and efficient network.
The Service Policy profile can only be configured at the Global scope. However, you can override the profile configuration at Site Collections, Sites, and Device Groups scope.
The Services Management page provides the following information:
Table 1: Service Policy Parameters
|
Parameter |
Description |
|---|---|
|
Name |
Displays the name of the profile. |
|
Profile Type |
Displays the type of profile. For example, User defined or Predefined. |
|
Inherits From |
Displays the scope from which the profile is inherited. |
|
State |
Displays the operational status of the profile. For example, Enabled or Disabled. |
|
Assigned Device Function |
Displays the device function assigned to the profile. |
|
Assigned Scope |
Displays the scope assigned to the profile. |
|
Overrides |
Displays the number of overrides on the profile. |
Figure 1: Service Policy Profile
Disabling a Predefined Profile
To disable a predefined profile, complete the following steps:
-
On the Services Management page, hover over the profile that you wish to disable.
-
Click the
ellipsis icon. -
Click Disable.
Enabling a Predefined Profile
To enable a predefined profile, complete the following steps:
-
On the Services Management page, hover over the profile that you wish to enable.
-
Click the
ellipsis icon. -
Click Enable.
Editing a Predefined Profile
To edit a profile, complete the following steps:
-
On the Services Management page, click the profile row you wish to edit.
The Edit Profile side panel is displayed. -
Edit the following parameters:
-
Enable—Allows you to enable or disable specific services.
-
User Role—Allows or denies specific user profiles from discovering the service. By default, all user profiles are allowed.
-
Allow—To allow the user to discover the service, select the user roles from the User Roles drop-down list. and then select Allow from the Services for User Roles section.
-
Deny—To deny the user from discovering the service, select the user roles from the User Roles drop-down list and then select Deny from the Services for User Roles section.
-
-
VLAN—Allows or denies the services on the specified VLANs.
-
Allow—To allow the service on the selected VLANs, enter the VLAN number and the range in the For these VLANs text box and then select Allow from the Services on VLAN section.
-
Deny—To deny the service on the selected VLANs, enter the VLAN number and the range in the For these VLANs text box and then select Deny from the Services on VLAN section.
Note:Enter VLANs as a comma-separated list, range, or both. Do not use spaces. Valid VLAN range is 1–4094.
-
-
Advanced—Select the Advanced check box to view the advanced configuration parameters.
-
Server Expiration Period—Enter, scroll, or use the up and down arrows to set the time in minutes for which you wish the server to be discoverable.
-
Service ID—Allows you to create service IDs for the Services Discovery profile. By default, all the service IDs are allowed. You can configure the following:
-
To create a service ID, enter the service ID in the Service ID text box.
-
To create another service ID, click the
Add icon and then enter the service ID in the Service ID text box. -
To delete a service ID, click the
Delete icon next to the service ID.
Note:You can enable or disable predefined service IDs, but you cannot delete them. To change the status of a service ID, select the service ID from the Service ID drop-down list and check or uncheck the corresponding checkbox to enable or disable it.
-
-
-
-
Click Update.
Figure 2: Editing a Profile
Creating a User-Defined Profile
To create a profile, complete the following steps:
-
On the Services Management page, click Create Profile.
The Create Profile side panel is displayed. -
Enter the following parameters:
-
Device Function—Under Device Function, Campus Access Point device type is selected by default.
-
Name—Enter a name for the profile.
-
Enable—Allows you to enable or disable specific services.
-
User Role—Allows or denies specific user profiles from discovering the service. By default, all user profiles are allowed.
-
Allow—To allow the user to discover the service, select the user roles from the User Roles drop-down list. and then select Allow from the Services for User Roles section.
-
Deny—To deny the user from discovering the service, select the user roles from the User Roles drop-down list and then select Deny from the Services for User Roles section.
-
-
VLAN—Allows or denies the services on the specified VLANs.
-
Allow—To allow the service on the selected VLANs, enter the VLAN number and the range in the For these VLANs text box and then select Allow from the Services on VLAN section.
-
Deny—To deny the service on the selected VLANs, enter the VLAN number and the range in the For these VLANs text box and then select Deny from the Services on VLAN section.
Note:Enter VLANs as a comma-separated list, range, or both. Do not use spaces. Valid VLAN range is 1–4094.
-
-
Advanced—Select the Advanced check box to view the advanced configuration parameters.
-
Server Expiration Period—Enter, scroll, or use the up and down arrows to set the time in minutes for which you wish the server to be discoverable.
-
Service ID—Allows you to create service IDs for the Services Discovery profile. By default, all the service IDs are allowed. You can configure the following:
-
To create a service ID, enter the service ID in the Service ID text box.
-
To create another service ID, click the
Add icon and then enter the service ID in the Service ID text box. -
To delete a service ID, click the
Delete icon next to the service ID.
Note:You can enable or disable predefined service IDs, but you cannot delete them. To change the status of a service ID, select the service ID from the Service ID drop-down list and check or uncheck the corresponding checkbox to enable or disable it
A maximum of 32 service IDs can be created per service, with an overall limit of 100 service IDs.
-
-
-
-
Click Create.
Figure 3: Creating a Profile