データセットの構成
データセットの構成
-
ポリシーデータセットの追加
-
パターンをポリシーデータセットにバインドする
-
ポリシー式を追加する
-
ポリシー設定の検証
ポリシーデータセットの追加
add policy dataset <name> <type>
add policy dataset ds1 ipv4 -comment numbers
パターンをデータセットにバインドする
bind policy dataset <name> <value> [-index <positive_integer>] [-endRange <string>] [-comment <string>]
bind policy dataset ds1 1.1.1.1 -endRange 1.1.1.10 -comment short description about the pattern bound to the data set
add policy dataset ip_set ipv4
Done
bind policy dataset ip_set 2.2.2.25
Done
bind policy dataset ip_set 2.2.2.20 -endRange 2.2.2.30
ERROR: The range overlaps an existing range or includes a value bound to the dataset.
ポリシーデータセットでポリシー式を使用する
add policy expression exp1 http.req.body(100).contains_any("ds1")
データセット設定の検証
show policy dataset ds1 > show policy dataset ds1
Dataset: ds1
Type: IPV4
1) Bound Dataset Range from: 1.1.1.1 through: 1.1.1.10 Index: 1
構成ユーティリティを使用してデータセットを構成する
-
AppExpert > データセットに移動します。
-
-
種類。データセットにバインドする値の型。
-
-
価値。データセットに関連付けられた、指定された型の値。
-
インデックス。データセットのインデックス値。
-
終了範囲。データセットエントリ。これは
<value>から<end_range>への範囲です。
-
-
コメントを入力します。
ポリシーデータセットの IPv4 および IPv6 アドレスにおける CIDR サブネット表記
<address>/<n>。 <address> はサブネット内の最初のアドレス、 <n> はサブネットの範囲を定義するサブネットマスクに設定された左端のビット数を指定する整数です。
add policy dataset ds1 ipv4
bind policy dataset ds1 192.128.0.0/10
show policy dataset ds1
Dataset: ds1
Type: IPV4
Bound Dataset Value: 192.128.0.0/10 Index: 1 Comment: Subnet range from 192.128.0.0 through 192.191.255.255
add responder policy resp_ipv4_pol client.ip.src.typecast_text_t.equals_any("ds1") drop
add policy dataset ds2 ipv6
bind policy dataset ds2 2001:db8:123::/56
show policy dataset ds2
Dataset: ds2
Type: IPV61
Bound Dataset Value: 2001:db8:123::/56 Index: 1 Comment: Subnet range from 2001:db8:123:: through 2001:db8:123:ff:ffff:ffff:ffff:ffff
bind policy dataset ds1 192.168.0.0/10
Warning: Starting subnet address masked using subnet mask to create new starting address [192.128.0.0]
show policy dataset ds1
Dataset: ds1
Type: IPV4
Bound Dataset Value:192.168.0.0/10 Index: 1 Comment: Subnet range from 192.128.0.0 through 192.191.255.255
add responder policy resp_ipv6_pol client.ipv6.src.typecast_text_t.equals_any("ds2") drop