D-Link DES-3828 Product Manual - Page 159

config access_profile profile_id packet content mask

Page 159 highlights

xStack DES-3800 Series Layer 3 Stackable Fast Ethernet Managed Switch CLI Manual config access_profile profile_id (packet content mask) | offset_16-31 | offset_32-47 | offset_48-63 | offset_64-79 } port [permit {priority {replace_priority} | replace_dscp } | deny | mirror] delete access_id ] Description This command is used to set the rule for a previously configured access profile setting based on packet content mask. These rules will determine if the Switch will forward, filter or mirror the identified packets, based on user configuration specified in this command. Users will set bytes to identify by entering them in hex form, offset from the first byte of the packet. Parameters profile_id - Enter an integer between 1 and 255 that is used to identify the access profile that will be configured with this command. This value is assigned to the access profile when it is created with the create access_profile command. The lower the profile ID, the higher the priority the rule will be given. add access_id - Adds an additional rule to the above specified access profile. • auto_assign - Adding this parameter will automatically assign an access_id to identify the rule. • - The value specifies the relative priority of the additional rule. Up to 65535 different rules may be configured for the Ethernet access profile. packet_content - Allows users to examine any specified content up to 80 bytes within a packet at one time and specifies that the Switch will mask the packet header beginning with the offset value specified as follows: • offset_0-15 - Enter a value in hex form to mask the packet from the beginning of the packet to the 15th byte. • offset_16-31 - Enter a value in hex form to mask the packet from byte 16 to byte 31. • offset_32-47 - Enter a value in hex form to mask the packet from byte 32 to byte 47. • offset_48-63 - Enter a value in hex form to mask the packet from byte 48 to byte 63. • offset_64-79 - Enter a value in hex form to mask the packet from byte 64 to byte 79. With this advanced unique Packet Content Mask (also known as Packet Content Access Control List - ACL), D-Link xStack switch family can effectively mitigate some network attacks like the common ARP Spoofing attack widely spreading today. This is for the reason that Packet Content ACL is able to inspect any specified content of a packet in different protocol layers. port - The access profile for the packet content mask may be defined for each port on the Switch. Up to 65535 rules may be configured for each port. permit - Specifies that packets that match the access profile are permitted to be forwarded by the Switch. • priority − This parameter is specified if you want to re-write the 802.1p default priority previously set in the Switch, which is used to determine the CoS queue to which packets are forwarded to. Once this field is specified, packets accepted by the Switch that match this priority are forwarded to the CoS queue specified previously by the user. • {replace_priority} − Enter this parameter if you want to re-write the 802.1p default priority of a packet to the value entered in the Priority field, which meets the criteria specified previously in this command, before forwarding it on to the specified CoS queue. Otherwise, a packet will have its incoming 802.1p user priority re-written to its original value before being forwarded by the Switch. replace_dscp − Allows you to specify a value to be written to the DSCP field of an incoming packet that meets the criteria specified in the first part 155

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452

xStack DES-3800 Series Layer 3 Stackable Fast Ethernet Managed Switch CLI Manual
155
config access_profile profile_id (packet content mask)
<hex 0x0-0xffffffff> <hex 0x0-0xffffffff> | offset_16-31 <hex 0x0-0xffffffff> <hex
0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> | offset_32-47 <hex 0x0-
0xffffffff> <hex 0x0-0xffffffff><hex 0x0-0xffffffff> <hex 0x0-0xffffffff> |
offset_48-63 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex
0x0-0xffffffff> | offset_64-79 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-
0xffffffff> <hex0x0-0xffffffff>} port <port> [permit {priority <value 0-7>
{replace_priority} | replace_dscp <value 0-63> } | deny | mirror] delete
access_id <value 1-65535>]
Description
This command is used to set the rule for a previously configured access profile
setting based on packet content mask. These rules will determine if the Switch will
forward, filter or mirror the identified packets, based on user configuration specified
in this command. Users will set bytes to identify by entering them in hex form,
offset from the first byte of the packet.
Parameters
profile_id <value 1-255>
- Enter an integer between 1 and 255 that is used to
identify the access profile that will be configured with this command. This value is
assigned to the access profile when it is created with the
create access_profile
command. The lower the profile ID, the higher the priority the rule will be given.
add access_id
- Adds an additional rule to the above specified access profile.
auto_assign
– Adding this parameter will automatically assign an
access_id to identify the rule.
<value 1-65535> -
The value specifies the relative priority of the
additional rule. Up to 65535 different rules may be configured for the
Ethernet access profile.
packet_content
– Allows users to examine any specified content up to 80 bytes
within a packet at one time and specifies that the Switch will mask the packet
header beginning with the offset value specified as follows:
offset_0-15
– Enter a value in hex form to mask the packet from the
beginning of the packet to the 15th byte.
offset_16-31
- Enter a value in hex form to mask the packet from byte 16 to
byte 31.
offset_32-47
- Enter a value in hex form to mask the packet from byte 32 to
byte 47.
offset_48-63
- Enter a value in hex form to mask the packet from byte 48 to
byte 63.
offset_64-79
- Enter a value in hex form to mask the packet from byte 64 to
byte 79.
With this advanced unique Packet Content Mask (also known as Packet
Content Access Control List - ACL),
D-Link xStack switch family can effectively
mitigate some network attacks like the common ARP Spoofing attack widely
spreading today. This is for the reason that Packet Content ACL is able to
inspect any specified content of a packet in different protocol layers.
port <portlist>
- The access profile for the packet content mask may be defined for
each port on the Switch. Up to 65535 rules may be configured for each port.
permit
– Specifies that packets that match the access profile are permitted to be
forwarded by the Switch.
priority <value 0-7>
This parameter is specified if you want to re-write the
802.1p default priority previously set in the Switch, which is used to
determine the CoS queue to which packets are forwarded to. Once this field
is specified, packets accepted by the Switch that match this priority are
forwarded to the CoS queue specified previously by the user.
{replace_priority}
Enter this parameter if you want to re-write the 802.1p
default priority of a packet to the value entered in the Priority field, which
meets the criteria specified previously in this command, before forwarding it
on to the specified CoS queue. Otherwise, a packet will have its incoming
802.1p user priority re-written to its original value before being forwarded by
the Switch.
replace_dscp <value 0-63>
Allows you to specify a value to be written to the
DSCP field of an incoming packet that meets the criteria specified in the first part