xStack
create access_profile (IP)
|
|
| _mask <hex |
Description | This command will allow the user to create a profile for packets that |
| may be accepted or denied by the Switch by examining the IP part of |
| the packet header. Specific values for rules pertaining to the IP part |
| of the packet header may be defined by configuring the config |
| access_profile command for IP, as stated below. |
Parameters | profile_id <value |
| that will identify the access profile being created with this command. |
| ip - Specifies that the Switch will look into the IP fields in each packet |
| with special emphasis on one or more of the following: |
| • vlan − Specifies a VLAN mask. |
| • source_ip_mask <netmask> − Specifies an IP address mask |
| for the source IP address. |
| • destination_ip_mask <netmask> − Specifies an IP address |
| mask for the destination IP address. |
| • dscp − Specifies that the Switch will examine the DiffServ |
| Code Point (DSCP) field in each frame’s header. |
| • icmp − Specifies that the Switch will examine the Internet |
| Control Message Protocol (ICMP) field in each frame’s header. |
| • type − Specifies that the Switch will examine each frame’s |
| ICMP Type field. |
| • code − Specifies that the Switch will examine each frame’s |
| ICMP Code field. |
| • igmp − Specifies that the Switch will examine each frame’s |
| Internet Group Management Protocol (IGMP) field. |
| • type − Specifies that the Switch will examine each frame’s |
| IGMP Type field. |
| • tcp − Specifies that the Switch will examine each frames |
| Transport Control Protocol (TCP) field. |
| • src_port_mask <hex |
| mask for the source port. |
| • dst_port_mask <hex |
| mask for the destination port. |
| • flag_mask [all {urg ack psh rst syn fin}] – Enter the |
| appropriate flag_mask parameter. All incoming packets have |
| TCP port numbers contained in them as the forwarding |
| criterion. These numbers have flag bits associated with them |
| which are parts of a packet that determine what to do with the |
| packet. The user may deny packets by denying certain flag bits |
| within the packets. The user may choose between all, urg |
| (urgent), ack (acknowledgement), psh (push), rst (reset), syn |
| (synchronize) and fin (finish). |
| • udp − Specifies that the Switch will examine each frame’s |
| Universal Datagram Protocol (UDP) field. |
| • src_port_mask <hex |
| mask for the source port. |
| • dst_port_mask <hex |
216