PolicyCenter Sharable Attributes

All Packeteer units, regardless of whether they are configured in local or shared mode, operate with an effective configuration that is comprised of two kinds of attributes: non-sharable and sharable.

Non-sharable attributes are those parts of a unit’s effective configuration that are specific to that one Packeteer unit. These are called non-sharable because no other Packeteer device will function correctly if configured with all the same non-sharable values as another unit. Every unit will have a unique set of non-sharable attributes, though more than one unit can be individually configured with some of the same non-sharable attributes, such as DNS name or time and date. A unit’s non-sharable attributes are always stored locally on that unit. Although these attributes can be changed through the unit’s browser or command-line interfaces, non-sharable attributes cannot be configured or managed through PolicyCenter.

A unit’s sharable attributes are those parts of the unit’s configuration that can have values in common with other Packeteer units. Traffic classes, policies, partitions and routers are all examples of sharable configuration attributes, because many different units can have the same traffic classes, or share the same router. When a unit is in shared mode, it applies all the sharable attributes from its assigned PolicyCenter configuration.

PolicyCenter organizes its configurations into hierarchical groups, with parent and child configurations. With hierarchical configuration groups, a parent configuration can have more than one child configuration, and a child configuration can have children of its own, creating a PolicyCenter configuration tree with several levels of depth. A PolicyCenter child configuration will inherit the sharable attributes defined on its parent configurations.

Packeteer units can be assigned to configurations in any level of the configuration tree, not just child configurations. Non-sharable configuration values must be changed through the individual units' user interface. Sharable attributes for both unit and group configurations can be altered via PolicyCenter.

Here is a list of configuration attributes that can and cannot be shared:

Sharable Attributes Non-sharable Attributes
link speed DNS server
passwords default domain
SNMP community strings and destinations IP address/mask
traffic classes standby partner
event definitions NIC mode settings
customer portal settings and files date / time / time zone      
HTTPS over SSL port definitions gateway address
RADIUS client authentication and accounting values high availability*
command scheduling watch mode*
traffic discovery on/off host side settings**
Modem on console management port settings
SNTP settings Xpress-IP settings***
site router  
failover configuration  
inside/outside interface settings  
email settings

 

image version  
logging  
host lists  
SSH settings  
adaptive response agents  
flow detail record settings  
plug-in files  
unit access service protocols  
login message  

global Xpress tunnel settings*** , including

  • Compression on/off
  • Acceleration on/off
  • FastStart on/off
  • Prefetch on/off
  • Packing on/off
  • Tunnel options (firewall, DiffServ, automatic tunnel discovery, MTU)
  • Tunnel security
  • Tunnel mode
  • Tunnel class overrides
  • Tunnel service overrides
 

*You can configure watch mode and high availability settings for an individual PolicyCenter configuration via the PolicyCenter command-line or browser interfaces, but only the units assigned to that one configuration will apply the settings. These settings are not considered sharable, and if set on a parent configuration, will not be inherited by its child configurations. If set on a child configuration, these settings cannot be published to the child’s parent.

** Only the host side manual or host side auto setting is sharable from a parent configuration to its child configurations. All other host side settings can be configured on a PolicyCenter configuration (and applied to the units assigned to that one configuration), but will not pass from a parent configuration to a child configuration.

***Global Xpress settings, tunnel mode settings, tunnel class overrides, and service overrides are all sharable from a parent to a child configuration. Not all Xpress settings are fully sharable, however. PolicyCenter allows you to create and configure new tunnels and add and remove local and remote hosts, but only the units assigned to that one configuration will apply the settings. If these settings are configured on a parent configuration, they will not be inherited by its child configurations. If set on a child configuration, these settings cannot be published to the child’s parent. Xpress tunnel IP settings (such as IP address, gateway, and VLAN values) are not sharable and cannot be configured via PolicyCenter.

        

PacketGuide™ for PacketWise® 8.1