Skip to main content

Policy

Policy combines one or more Centralized policy definitions to create a Policy. These policies can then be activated to be applied to the SD-WAN deployment.

Diagram

Classes

centralized_policies (sdwan)

NameTypeConstraintMandatoryDefault Value
feature_policiesList[feature_policies]No

feature_policies (sdwan.centralized_policies)

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[A-Za-z0-9\-_]{1,127}$Yes
descriptionStringYes
hub_and_spoke_topologyList[hub_and_spoke_topology]No
mesh_topologyList[mesh_topology]No
custom_control_topologyList[custom_control_topology]No
vpn_membershipList[vpn_membership]No
application_aware_routingList[application_aware_routing]No
traffic_dataList[traffic_data]No
cflowdList[cflowd]No

hub_and_spoke_topology (sdwan.centralized_policies.feature_policies)

NameTypeConstraintMandatoryDefault Value
policy_definitionStringYes

mesh_topology (sdwan.centralized_policies.feature_policies)

NameTypeConstraintMandatoryDefault Value
policy_definitionStringYes

custom_control_topology (sdwan.centralized_policies.feature_policies)

NameTypeConstraintMandatoryDefault Value
policy_definitionStringYes
site_regionClass[site_region]Yes

vpn_membership (sdwan.centralized_policies.feature_policies)

NameTypeConstraintMandatoryDefault Value
policy_definitionStringYes

application_aware_routing (sdwan.centralized_policies.feature_policies)

NameTypeConstraintMandatoryDefault Value
policy_definitionStringYes
site_region_vpnClass[site_region_vpn]No

traffic_data (sdwan.centralized_policies.feature_policies)

NameTypeConstraintMandatoryDefault Value
policy_definitionStringYes
site_region_vpnList[site_region_vpn]No

cflowd (sdwan.centralized_policies.feature_policies)

NameTypeConstraintMandatoryDefault Value
policy_definitionStringYes
site_listsListString[Regex: ^[A-Za-z0-9\-_]{1,32}$]Yes

site_region (sdwan.centralized_policies.feature_policies.custom_control_topology)

NameTypeConstraintMandatoryDefault Value
site_lists_inListString[Regex: ^[A-Za-z0-9\-_]{1,32}$]No
site_lists_outListString[Regex: ^[A-Za-z0-9\-_]{1,32}$]No
region_lists_inListString[Regex: ^[A-Za-z0-9\-_]{1,32}$]No
region_lists_outListString[Regex: ^[A-Za-z0-9\-_]{1,32}$]No
region_inIntegermin: 0, max: 63No
region_outIntegermin: 0, max: 63No

site_region_vpn (sdwan.centralized_policies.feature_policies.application_aware_routing)

NameTypeConstraintMandatoryDefault Value
site_listsListString[Regex: ^[A-Za-z0-9\-_]{1,32}$]No
region_listStringRegex: ^[A-Za-z0-9\-_]{1,32}$No
regionIntegermin: 0, max: 63No
vpn_listsListString[Regex: ^[A-Za-z0-9\-_]{1,32}$]Yes

site_region_vpn (sdwan.centralized_policies.feature_policies.traffic_data)

NameTypeConstraintMandatoryDefault Value
directionChoiceservice, tunnel, allYes
site_listsListString[Regex: ^[A-Za-z0-9\-_]{1,32}$]Yes
vpn_listsListString[Regex: ^[A-Za-z0-9\-_]{1,32}$]Yes

Examples

sdwan:
centralized_policies:
feature_policies:
- name: Super_policy_test2
description: Super_policy_test2
hub_and_spoke_topology:
- policy_definition: HST_DEFINITION_TEST1
mesh_topology:
- policy_definition: MT_DEFINITION_TEST1
vpn_membership:
- policy_definition: VPN_DEFINITION_TEST1
custom_control_topology:
- policy_definition: CCT_DEFINITION_TEST1
site_region:
site_lists_in:
- CHICAGO-CCT-TEST
site_lists_out:
- DENVER-CCT-TEST
- ATLANTA-CCT-TEST
traffic_data:
- policy_definition: TD_DEFINITION_TEST1
site_region_vpn:
- direction: service
site_lists:
- GOA-TD-TEST
vpn_lists:
- VPN-LIST-TD-TEST1
- direction: all
site_lists:
- CHENNAI-TD-TEST
vpn_lists:
- VPN-LIST-TD-TEST2
cflowd:
- policy_definition: CFLOW_DEFINITION_TEST2
site_lists:
- MY-CFLOW-TEST
application_aware_routing:
- policy_definition: Test_application_aware_routing_number2
site_region_vpn:
site_lists:
- CHENNAI-TD-TEST
vpn_lists:
- VPN-LIST-TD-TEST1