Redirection Policies and Role
The following procedure describes how to configure the redirection policies and user role.
1.To configure user roles to redirect the required traffic to the server(s), in the node hierarchy, navigate to the tab.
2.Click to create a new user role.
3.Enter for Role Name.
4.Click .
5.Select 的角色。
6.Click .
7.Click in table.
8.Click tab. Click to create a new policy.
9.In the pop-up, select the option. Enter the as and select as from the drop-down list.
10.Click .
11.Select the policy under the table.
12.Click in the table.
13.Select as the in popup.
14.Enter the following information in the table.
IP version as
源
.Destination as
.Service/appShort form for application. It generally refers to the application that is downloaded and used on mobile devices.as and the Protocol as
Action as
.Enter
as .Enter
as . as . refers to the direction of traffic from the untrusted client or user to the trusted server, such as the15.Click .
16.Repeat the steps to configure additional rules. This example adds a rule that specifies
17.Click .
18.Click .
19.In the window, select the check box and click .
The followingCLICommand-Line Interface. A console interface with a command line shell that allows users to execute text input as commands and convert these commands to appropriate functions.commands define the redirection filter for sending traffic to theESIExternal Services Interface. ESI provides an open interface for integrating security solutions that solve interior network problems such as viruses, worms, spyware, and corporate compliance.server and apply thefirewallFirewall is a network security system used for preventing unauthorized access to or from a private network.policy to a user role in the route-modeESIExternal Services Interface. ESI provides an open interface for integrating security solutions that solve interior network problems such as viruses, worms, spyware, and corporate compliance.topology example.
(host) [md] (config) #ip access-list sessionpolicy
any any any redirect esi‑groupgroup方向都是黑名单
//For any incoming traffic, going to any destination,
//redirect the traffic to servers in the specified ESI group.
any any any permit
//For everything else, allow the traffic to flow normally.
(host) [md] (config) #user-rolerole
access‑list {eth | mac | session}
bandwidth‑contractname
captive‑portalname
dialername
pool {l2tp | pptp}
reauthentication‑intervalminutes
session‑aclname
vlanvlan_id