Configuring a data set
Configure a data set
-
Add a policy dataset
-
Bind pattern to a policy dataset
-
Add a policy expression
-
Verify the policy configuration
Add a policy dataset
add policy dataset <name> <type>
add policy dataset ds1 ipv4 -comment numbers
Bind a pattern to the data set
bind policy dataset <name> <value> [-index <positive_integer>] [-endRange <string>] [-comment <string>]
bind policy dataset ds1 1.1.1.1 -endRange 1.1.1.10 -comment short description about the pattern bound to the data set
add policy dataset ip_set ipv4
Done
bind policy dataset ip_set 2.2.2.25
Done
bind policy dataset ip_set 2.2.2.20 -endRange 2.2.2.30
ERROR: The range overlaps an existing range or includes a value bound to the dataset.
Use policy expression in a policy data set
add policy expression exp1 http.req.body(100).contains_any("ds1")
Verify dataset configuration
show policy dataset ds1 > show policy dataset ds1
Dataset: ds1
Type: IPV4
1) Bound Dataset Range from: 1.1.1.1 through: 1.1.1.10 Index: 1
Configure a data set by using the configuration utility
-
Navigate to AppExpert > Data Sets.
-
In the details pane, under Data Sets, click Add.
-
In the Configure Data Set page, set the following parameters.
-
Name. Name of the policy data set.
-
Type. Type of value to bind to the dataset.
Configuring data set -
-
Click Insert to bind the dataset value of specific type.
-
Value. Value of the specified type associated with the dataset.
-
Index. The index value of the dataset.
-
End range. The dataset entry. This is a range
<value>to<end_range>. -
Comments. A short description about the data set.
dataset binding -
-
Click Insert and Close.
-
Enter comments.
-
Click Create and Close.
CIDR subnet notation in IPv4 and IPv6 addresses for policy dataset
<address>/<n>, where <address> is the first address in the subnet and <n> is an integer specifying the number of left-most bits set in the subnet mask, which defines the range of the subnet.
add policy dataset ds1 ipv4
bind policy dataset ds1 192.128.0.0/10
show policy dataset ds1
Dataset: ds1
Type: IPV4
Bound Dataset Value: 192.128.0.0/10 Index: 1 Comment: Subnet range from 192.128.0.0 through 192.191.255.255
add responder policy resp_ipv4_pol client.ip.src.typecast_text_t.equals_any("ds1") drop
add policy dataset ds2 ipv6
bind policy dataset ds2 2001:db8:123::/56
show policy dataset ds2
Dataset: ds2
Type: IPV61
Bound Dataset Value: 2001:db8:123::/56 Index: 1 Comment: Subnet range from 2001:db8:123:: through 2001:db8:123:ff:ffff:ffff:ffff:ffff
bind policy dataset ds1 192.168.0.0/10
Warning: Starting subnet address masked using subnet mask to create new starting address [192.128.0.0]
show policy dataset ds1
Dataset: ds1
Type: IPV4
Bound Dataset Value:192.168.0.0/10 Index: 1 Comment: Subnet range from 192.128.0.0 through 192.191.255.255
add responder policy resp_ipv6_pol client.ipv6.src.typecast_text_t.equals_any("ds2") drop