RE: PCLS classes deprecated in PCELS
"Pana, Mircea" <[email protected]> Wed, 24 Sep 2003 08:15:13 -0500
| Newsgroups | gmane.ietf.policy |
|---|---|
| Message-ID | <[email protected]> |
This message is in MIME format. Since your mail reader does not understand
this format, some or all of this message may not be legible.
------_=_NextPart_001_01C3829D.E3B6CBF0
Content-Type: text/plain;
charset="iso-8859-1"
David,
PCLS recommends:
"A policy rule may have its conditions attached to itself and its actions
attached to other entries, or it may have its actions attached to itself
and its conditions attached to other entries. However, it SHALL NOT have
either its conditions or its actions attached both to itself and to
other entries, with one exception: a policy rule may reference its
validity periods with the pcimRuleValidityPeriodList attribute, but have
its other conditions attached to itself."
Which implies that if a pcimTPCAuxClass is attached to a pcimRule (because
pcimTPCAuxClass is a subclass of pcimConditionAuxClass) then no other
conditions shall be aggregated (referenced) by that rule except for other
validity periods aggregated through pcimRuleValidityPeriodList references. I
am not sure about the reasons behind this limitation introduced by PCLS but
in PCELS we have simply re-phrased it to make it clear for implementers.
Regards,
Mircea.
Things I disagree with:
5.6 pcimPolicyRule "If a pcimPolicyRule instance has a pcimConditionAuxClass
attached to it then the attribute pcimConditionList SHOULD NOT be present in
the same entry for the purpose of associating other conditions to the rule.
However, when such situations occur the referenced conditions MUST NOT be
considered as associated to the rule."
- this means that re-usable conditions are not easily used in conjuction
with customized conditions. ie: we use PCIM to specify rules for
policy-based filtering. For instance, we may have a pre-defined condition
that is linked through the pcimConditionList, but the individual user may
update their policy so that the rule contains a TimePeriodCondition that
specifies it only is valid between the hours of 9-5. With the above
language, this sort of amalgamation of conditions is not valid. I believe
the configuration SHOULD be correct, and the evaluation of the conditions
are done on a priority-based level.
Regards,
d.
------_=_NextPart_001_01C3829D.E3B6CBF0
Content-Type: text/html;
charset="iso-8859-1"
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<TITLE>RE: [Policy] PCLS classes deprecated in PCELS</TITLE>
<META content="MSHTML 6.00.2800.1226" name=GENERATOR>
<STYLE>@font-face {
font-family: Wingdings;
}
@font-face {
font-family: Tahoma;
}
@page Section1 {size: 8.5in 11.0in; margin: 1.0in 1.25in 1.0in 1.25in; }
P.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; FONT-FAMILY: "Times New Roman"
}
LI.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; FONT-FAMILY: "Times New Roman"
}
DIV.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; FONT-FAMILY: "Times New Roman"
}
A:link {
COLOR: blue; TEXT-DECORATION: underline
}
SPAN.MsoHyperlink {
COLOR: blue; TEXT-DECORATION: underline
}
A:visited {
COLOR: blue; TEXT-DECORATION: underline
}
SPAN.MsoHyperlinkFollowed {
COLOR: blue; TEXT-DECORATION: underline
}
P.MsoAutoSig {
FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; FONT-FAMILY: "Times New Roman"
}
LI.MsoAutoSig {
FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; FONT-FAMILY: "Times New Roman"
}
DIV.MsoAutoSig {
FONT-SIZE: 12pt; MARGIN: 0in 0in 0pt; FONT-FAMILY: "Times New Roman"
}
P {
FONT-SIZE: 12pt; MARGIN-LEFT: 0in; MARGIN-RIGHT: 0in; FONT-FAMILY: "Times New Roman"
}
P.Numbered {
FONT-SIZE: 10pt; MARGIN: 0in 0in 0pt 0.8in; TEXT-INDENT: -0.25in; LINE-HEIGHT: 200%; FONT-FAMILY: "Times New Roman"
}
LI.Numbered {
FONT-SIZE: 10pt; MARGIN: 0in 0in 0pt 0.8in; TEXT-INDENT: -0.25in; LINE-HEIGHT: 200%; FONT-FAMILY: "Times New Roman"
}
DIV.Numbered {
FONT-SIZE: 10pt; MARGIN: 0in 0in 0pt 0.8in; TEXT-INDENT: -0.25in; LINE-HEIGHT: 200%; FONT-FAMILY: "Times New Roman"
}
P.Bulletted {
FONT-SIZE: 10pt; MARGIN: 0in 0in 0pt 1.5in; TEXT-INDENT: -0.25in; LINE-HEIGHT: 200%; FONT-FAMILY: "Times New Roman"
}
LI.Bulletted {
FONT-SIZE: 10pt; MARGIN: 0in 0in 0pt 1.5in; TEXT-INDENT: -0.25in; LINE-HEIGHT: 200%; FONT-FAMILY: "Times New Roman"
}
DIV.Bulletted {
FONT-SIZE: 10pt; MARGIN: 0in 0in 0pt 1.5in; TEXT-INDENT: -0.25in; LINE-HEIGHT: 200%; FONT-FAMILY: "Times New Roman"
}
SPAN.EmailStyle20 {
COLOR: navy; FONT-FAMILY: Arial
}
DIV.Section1 {
page: Section1
}
OL {
MARGIN-BOTTOM: 0in
}
UL {
MARGIN-BOTTOM: 0in
}
</STYLE>
</HEAD>
<BODY lang=EN-US vLink=blue link=blue>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN class=323184012-24092003><SPAN
class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN class=323184012-24092003><FONT face=Arial
color=#0000ff>David,</FONT></SPAN></SPAN></FONT></SPAN></SPAN></SPAN></FONT></SPAN></DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN class=323184012-24092003><SPAN
class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN class=323184012-24092003><FONT face=Arial
color=#0000ff></FONT></SPAN></SPAN></FONT></SPAN></SPAN></SPAN></FONT></SPAN> </DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN class=323184012-24092003><SPAN
class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN class=323184012-24092003><FONT face=Arial
color=#0000ff>PCLS
recommends:</FONT></SPAN></SPAN></FONT></SPAN></SPAN></SPAN></FONT></SPAN></DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN class=323184012-24092003> "A policy rule may
have its conditions attached to itself and its actions <BR>attached to other
entries, or it may have its actions attached to itself <BR>and its conditions
attached to other entries. However, it SHALL NOT have <BR>either its conditions
or its actions attached both to itself and to <BR>other entries, with one
exception: a policy rule may reference its <BR>validity periods with the
pcimRuleValidityPeriodList attribute, but have <BR>its other conditions attached
to itself."</SPAN></SPAN></FONT></SPAN></DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN
class=323184012-24092003></SPAN></SPAN></FONT></SPAN> </DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN class=323184012-24092003><FONT face=Arial
color=#0000ff>Which implies that if a pcimTPCAuxClass is attached to a
pcimRule (because pcimTPCAuxClass is a subclass of pcimConditionAuxClass) then
no other conditions shall be aggregated (referenced) by that rule
except for other validity periods aggregated through pcimRuleValidityPeriodList
references. I am not sure about the reasons behind this limitation
introduced by PCLS but in PCELS we have simply re-phrased it to make it
clear for implementers.</FONT></DIV>
<DIV><FONT face=Arial color=#0000ff></FONT><FONT face=Arial
color=#0000ff></FONT><FONT face=Arial color=#0000ff></FONT><FONT face=Arial
color=#0000ff></FONT><FONT face=Arial color=#0000ff></FONT><FONT face=Arial
color=#0000ff></FONT><FONT face=Arial color=#0000ff></FONT><FONT face=Arial
color=#0000ff></FONT><FONT face=Arial color=#0000ff></FONT><FONT face=Arial
color=#0000ff></FONT><FONT face=Arial color=#0000ff></FONT><FONT face=Arial
color=#0000ff></FONT><BR></DIV></SPAN></SPAN></FONT></SPAN>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN class=323184012-24092003><FONT face=Arial
color=#0000ff>Regards,</FONT></SPAN></SPAN></FONT></SPAN></DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN class=323184012-24092003><FONT face=Arial
color=#0000ff>Mircea.</FONT></SPAN></SPAN></FONT></SPAN></DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003><SPAN
class=323184012-24092003> </SPAN></SPAN></FONT></SPAN></DIV>
<BLOCKQUOTE dir=ltr
style="PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #0000ff 2px solid; MARGIN-RIGHT: 0px">
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003></SPAN></FONT></SPAN><SPAN
class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003></SPAN></FONT></SPAN> </DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003>Things I disagree with:</SPAN></FONT></SPAN></DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003>5.6 pcimPolicyRule "If a pcimPolicyRule instance has
a pcimConditionAuxClass attached to it then the attribute pcimConditionList
SHOULD NOT be present in the same entry for the purpose of associating other
conditions to the rule. However, when such situations occur the referenced
conditions MUST NOT be considered as associated to the
rule."</SPAN></FONT></SPAN></DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003> - this means that re-usable conditions are not
easily used in conjuction with customized conditions. ie: we use PCIM to
specify rules for policy-based filtering. For instance, we may have a
pre-defined condition that is linked through the pcimConditionList, but the
individual user may update their policy so that the rule contains a
TimePeriodCondition that specifies it only is valid between the hours of 9-5.
With the above language, this sort of amalgamation of conditions is not valid.
I believe the configuration SHOULD be correct, and the evaluation of the
conditions are done on a priority-based level.</SPAN></FONT></SPAN></DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003></SPAN></FONT></SPAN> </DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003></SPAN></FONT></SPAN> </DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003>Regards,</SPAN></FONT></SPAN></DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003>d.</SPAN></FONT></SPAN></DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003></SPAN></FONT></SPAN> </DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003></SPAN></FONT></SPAN> </DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New" size=2><SPAN
class=327314716-17092003></SPAN></FONT></SPAN> </DIV>
<DIV><SPAN class=327314716-17092003><FONT face="Courier New"
size=2></FONT></SPAN> </DIV></BLOCKQUOTE></BODY></HTML>
------_=_NextPart_001_01C3829D.E3B6CBF0--