Switching between local and remote policies
If you dynamically switch from local policies to remote policies by adding the PolicyServer statement or a new PolicyType parameter within that statement, the FLUSH and PURGE parameters that are specified on the PolicyServer statement (or that are configured by default from the TcpImage statement) take effect, if the parameters are supported by the policy type.
Likewise, if you dynamically switch from remote policies to local policies by removing the PolicyServer statement or a PolicyType parameter from within that statement, the FLUSH and PURGE parameters that are specified on the xxxConfig statement (or that are configured by default from the TcpImage statement) take effect, if the parameters are supported by the policy type.
When the NOFLUSH parameter is used due to one of these dynamic switches, the result is that both the local and remote policies exist in the configuration; existing policies are not deleted when NOFLUSH is in effect, as shown in Table 2.
The following examples show how switching between local and remote policies works:
- Switching from local IDS to remote IDS policies:
- The TcpImage statement is configured with the FLUSH parameter.
- The IDSConfig statement is not configured with the FLUSH or NOFLUSH parameters, so the TcpImage FLUSH value is used.
- The local IDS policies are read and installed.
- The PolicyServer statement is added with a PolicyType parameter for IDS that specifies the NOFLUSH value.
- The remote IDS policies are retrieved and installed.
- Because the NOFLUSH parameter is in effect (from the PolicyServer statement), the local IDS policies are not deleted; both the local and remote IDS policies exist.
- Switching from remote AT-TLS to local AT-TLS policies:
- The TcpImage statement is configured with the NOFLUSH parameter.
- The TTLSConfig statement is configured with the FLUSH parameter.
- The PolicyServer statement is configured with a PolicyType parameter for AT-TLS that specifies the FLUSH value.
- The remote AT-TLS policies are retrieved and installed.
- The PolicyType parameter for AT-TLS is removed from the PolicyServer statement.
- The local IDS policies are read and installed.
- Because the FLUSH parameter is in effect (from the TTLSConfig statement), the remote AT-TLS policies are deleted; only the local policies exist.