Configuring Default VLAN and Class of Service for a Role

From the VLAN & Class of Service tab you can assign a previously configured topology to a role. You can also launch the Topology Configuration page to edit an existing topology or create a new one. For information about how to configure a topology, refer to Configuring a Basic Data Port Topology.
Note

Note

The Configuration Manager (CM) checks overall configuration as configuration is entered. If CM detects mixed B@AC and B@AP rules in the same role, and the role has L7 filter rules, then the configuration is rejected. For more information, see Configuration Rules with L7 Filters.

In general, CoS (Class of Service) refers to a set of attributes that define the importance of a frame while it is forwarded through the network relative to other packets, and to the maximum throughput per time unit that a station or port assigned to the role is permitted. The CoS defines actions to be taken when rate limits are exceeded.

To configure VLAN (Virtual LAN) and Class of Service for a role:

  1. From the top menu, click VNS.
  2. In the left pane expand the Roles pane and click the role you want to edit, or click New to create a new role.
    Click to expand in new window
    VLAN & Class of Service Tab
    Graphics/vns_policy_vlanCos.png
  3. Select Policy Rules to configure the policy rules for the Role. For more information, see Configuring Policy Rules.
Click to expand in new window

VLAN & Class of Service Tab - Fields and Buttons

Field/Button Description
Core
Role Name Enter a name to assign to this role.
Default Action
Access Control
Select from one of the following:
  • None - No role defined
  • No change - Default setting
  • Allow - Packets contained to role's default action's VLAN/topology.
  • Deny - Any packet not matching a rule in the Role is dropped.
  • Containment VLAN - Any packet not matching a rule is sent to defined VLAN.
VLAN
Note: VLAN is only visible when the user selects "Contain to VLAN" as the default access control action.

Select an existing Topology, Topology Group, or click New to create a new Topology.

To edit an existing Topology, select the VLAN and then click Edit. The Edit Topology page displays. For more information, see Configuring a Basic Topology.

Default Class of Service Select an existing class of service from the Default Class of Service drop-down list, or click New to create a new topology.

To edit an existing class of service, select the class of service and then click Edit. The Edit Class of Service page displays. For more information, see Configuring Classes of Service.

Traffic Mirror When enabled, this option sends a copy of the network packets to a mirroring L2 port for analysis, in an effort to monitor network traffic. The Purview Engine analyses the traffic. The assigned port can only be used for traffic analysis.

You can enable traffic mirroring from the WLAN Service, from the Role, or from the Filter Rule. Setting traffic mirroring at the Filter Rule takes precedence over settings for the Role and WLAN Service. The order of precedence for the traffic mirror setting is: Filter Rule, Role, WLAN Service. To set the L2 port, go to VNS > Global > Netflow/MirrorN Configuration.

Valid values for Filter Rule and Role are:
  • None - No traffic mirroring
  • Enable - Traffic mirroring enabled. Traffic is copied if the filter rule matches or the role is applied.
  • Prohibited - Traffic mirroring is prohibited for this role. Traffic is not copied when the filter rule matches or the role is applied.
HTTP Redirection HTTP Redirection appears when the following conditions are present:
  • Rule-based Redirection is enabled on the Filtering Mode screen.
  • A filter exits with Access Control = HTTP Redirect.

(See Understanding the Filter Rule Definition Dialog.)

Redirection URL: Select from one of the previously configured redirection URLs or click New to create a new redirection URL. For more information about setting up a redirection URL, see Managing Redirection URLs. WLAN (Wireless Local Area Network) Services with Captive Portals are included in this list.

The default value for the redirection URL is Own WLAN, which indicates the current WLAN. This is identical to the current redirection behaviour.

Status  
Synchronize Enable automatic synchronization with its availability peer. For more information about viewing synchronization status, see Using the Sync Summary. If this VNS is part of an availability pair, Extreme Networks recommends that you enable Synchronize. By default the WLAN Service is enabled. Clear this checkbox to disable the WLAN Service.
Advanced Button
Static Egress Untagged VLANs Lists those VLANs (for multicast, broadcast, unicast) that a station assigned to a role receives from, even if it hasn‘t sent on it. Choose a VLAN as follows:
  • Click a VLAN from the list of available VLANs to use
  • Click >> to move the VLAN to the active list of VLANs used
  • Click OK to permit static configuration of egress untagged VLANs.

For more information about rate control profiles, see Working with Bandwidth Control Profiles.