xStack DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual

2

======================================================================

Access Profile ID: 3TYPE : Packet Content

======================================================================

MASK Option :

Offset 0-15 : 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF

Offset 16-31 : 0x0000FFFF 0xFFFF0000 0x0000000F 0x0F000000

Access ID : 1 Mode: Deny

Ports: 1:1

Offset 0-15 : 0x11111111 0x11111111 0x11111111 0x11111111

Offset 16-31 : 0x00001111 0x11110000 0x00000001 0x01000000

======================================================================

Total Entries: 3

DES-6500:4#

create cpu access_profile

Purpose

Syntax

Description

Parameters

Used to create an access profile specifically for CPU Interface Filtering on the Switch and to define which parts of each incoming frame’s header the Switch will examine. Masks can be entered that will be combined with the values the Switch finds in the specified frame header fields. Specific values for the rules are entered using the config cpu access_profile command, below.

create cpu access_profile profile_id <value 1-5> [ethernet {vlan source_mac <macmask> destination_mac <macmask> ethernet_type} ip {vlan source_ip_mask <netmask> destination_ip_mask <netmask> dscp [icmp {type code} igmp {type} tcp {src_port_mask <hex 0x0-0xffff> dst_port_mask <hex 0x0-0xffff>} flag_mask [all {urg ack psh rst syn fin}]} udp {src_port_mask <hex 0x0-0xffff> dst_port_mask <hex 0x0- 0xffff>} protocol_id {user_mask <hex 0x0-0xffffffff>} ]} packet_content_mask {offset 0-15 <hex 0x0-0xffffffff> <hex 0x0- 0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> offset 16-31 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0- 0xffffffff> {offset 32-47 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> {offset 48-63 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> {offset 64-79 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> }]

The create cpu access_profile command is used to create an access profile used only for CPU Interface Filtering. Masks can be entered that will be combined with the values the Switch finds in the specified frame header fields. Specific values for the rules are entered using the config cpu access_profile command, below.

profile_id <value 1-5>Specifies an index number that will identify the access profile being created with this command.

ethernet Specifies that the Switch will examine the layer 2 part of each packet header.

vlan Specifies that the Switch will examine the VLAN part of each packet header.

source_mac <macmask> - Specifies to examine the source MAC

227

Page 230
Image 230
D-Link TM DES-6500 manual Create cpu accessprofile