Use the CLI commands in this procedure to add an IP address or subnet by configuring a policy configuration rule to a network whitelist. You enter each rule separately. You can add up to 256 network whitelist rules.
Note
After you add a rule to a network whitelist, use the
policymgr refresh-policycommand in the CLI configuration mode to refresh the policy configuration.
Go to CLI configuration mode.
hostname > enable hostname # configure terminalTo add the policy configuration for the destination IP address:
hostname (config) # policymgr network dst <IPAddress> <maskLength>{allow | interface <interfaceType> | vlan <vlanID}<IPAddress>is the destination IP address that matches the defined IP address or mask.<maskLength>is the valid Classless Inter-Domain Routing (CIDR) mask for the host prefix.allow is the policy action to allow traffic from the specified host, network, or VLAN.
interface <interfaceName>is the name of the interface to apply the network whitelist.vlan <vlanID>is the VLAN identification number to add to the network whitelist. The default value is "ALL". The range is from 1 to 4094.
To add the policy configuration for the source IP address:
hostname (config) # policymgr network src <IPAddress> <maskLength>{allow | interface <interfaceType> | vlan <vlanID}<IPAddress>is the source IP address that matches the defined IP address or mask.<maskLength>is the valid CIDR mask for the host prefix.allow
is the policy action to allow traffic from the specified host, network, or VLAN.interface <interfaceName>is the name of the interface to apply the network whitelist.vlan <vlanID>is the VLAN identification number to add to the network whitelist. The default value is "ALL". The range is from 1 to 4094.
To add the policy configuration for the host IP address:
<IPAddress>is the source IP address or destination IP address that matches the defined IP address or mask.<maskLength>is the valid CIDR mask for the host prefix.allow
is the policy action to allow traffic from the specified host, network, or VLAN.interface <interfaceName>is the name of the interface to apply the network whitelist.vlan <vlanID>is the VLAN identification number to add to the network whitelist. The default value is "ALL". The range is from 1 to 4094.monitor
is the policy action to monitor and allow traffic from the specified host, network, or VLAN.
Repeat the previous step for each additional rule you want to add.
Save your changes.
hostname (config) # write memoryRefresh the policy configuration.
hostname (config) # policymgr refresh-policyVerify the configuration for a network whitelist.
hostname (config) # show policymgr networks
Example
This example shows how to add the policy configuration for the destination IP address mask length to a network whitelist.
hostname (config) # policymgr network dst 23.1.1.2/32 interface ALL allowhostname (config) # policymgr refresh-policy
This example shows how to add the policy configuration for the source IP address and mask length to a network whitelist.
hostname (config) # policymgr network src 23.1.1.1/32 interface ALL allow hostname (config) # policymgr refresh-policy
This example shows how to add the policy configuration for the host IP address and mask length to a network whitelist.
hostname (config) # policymgr network host 1.1.1.1/32 interface ALL allow
hostname (config) # policymgr refresh-policy
hostname (config) # show policymgr networks
Whitelist Entries: 3 / 256
Whitelist: VLAN INTF MONITOR IP MODE(source|destination|host) ALL ALL no 1.1.1.1/32 host ALL ALL n/a 23.1.1.1/32 src ALL ALL n/a 23.1.1.2/32 dst