D-Link DES-3828 Product Manual - Page 341

D-Link DES-3828 - xStack Switch - Stackable Manual

Page 341 highlights

xStack DES-3800 Series Layer 3 Stackable Fast Ethernet Managed Switch CLI Manual create cpu access_profile Purpose Used to create an access profile specifically for CPU Interface Filtering on the Switch and to define which parts of each incoming frame's header the Switch will examine. Masks can be entered that will be combined with the values the Switch finds in the specified frame header fields. Specific values for the rules are entered using the config cpu access_profile command, below. Syntax Description create cpu access_profile [ethernet {vlan | source_mac | destination_mac | ethernet_type} | ip {vlan | source_ip_mask | destination_ip_mask | dscp | [icmp {type | code} | igmp {type} | tcp {src_port_mask | dst_port_mask } | flag_mask [all | {urg | ack | psh | rst | syn | fin}]} | udp {src_port_mask | dst_port_mask } | protocol_id {user_mask } ]} | packet_content_mask {offset 0-15 | offset 16-31 | {offset 32-47 | {offset 48-63 | {offset 64-79 }] [profile_id value 1-5>] The create cpu access_profile command is used to create an access profile used only for CPU Interface Filtering. Masks can be entered that will be combined with the values the Switch finds in the specified frame header fields. Specific values for the rules are entered using the config cpu access_profile command, below. Parameters ethernet − Specifies that the Switch will examine the layer 2 part of each packet header. • vlan − Specifies that the Switch will examine the VLAN part of each packet header. • source_mac - Specifies to examine the source MAC address mask. • destination_mac - Specifies to examine the destination MAC address mask. • ethernet_type − Specifies that the switch will examine the Ethernet type value in each frame's header. ip − Specifies that the switch will examine the IP address in each frame's header. • vlan − Specifies a VLAN mask. • source_ip_mask − Specifies an IP address mask for the source IP address. • destination_ip_mask − Specifies an IP address mask for the destination IP address. • dscp − Specifies that the switch will examine the DiffServ Code Point (DSCP) field in each frame's header. • icmp − Specifies that the switch will examine the Internet Control Message Protocol (ICMP) field in each frame's header. • type − Specifies that the switch will examine each frame's ICMP Type field. • code − Specifies that the switch will examine each frame's ICMP Code field. • igmp − Specifies that the switch will examine each frame's Internet Group Management Protocol (IGMP) field. • type − Specifies that the switch will examine each frame's IGMP Type field. • tcp − Specifies that the switch will examine each frames Transport Control Protocol (TCP) field. • src_port_mask − Specifies a TCP port mask for the source port. • dst_port_mask − Specifies a TCP port mask for the destination port. • flag_mask - all | {urg | ack | psh | rst | syn | fin - Enter the appropriate flag_mask parameter. All incoming packets have TCP port numbers contained in them as the forwarding criterion. These numbers have flag bits associated with them which are parts of a packet that determine what to do with the packet. The user may deny packets by denying certain flag bits within the packets. The user may choose between all, urg (urgent), ack (acknowledgement), psh (push), rst (reset), syn (synchronize) and fin (finish). • udp − Specifies that the switch will examine each frame's User Datagram Protocol (UDP) field. • src_port_mask − Specifies a UDP port mask for the source port. 337

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452

xStack DES-3800 Series Layer 3 Stackable Fast Ethernet Managed Switch CLI Manual
337
create cpu access_profile
Purpose
Used to create an access profile specifically for
CPU Interface Filtering
on the Switch and to define which
parts of each incoming frame’s header the Switch will examine. Masks can be entered that will be combined
with the values the Switch finds in the specified frame header fields. Specific values for the rules are
entered using the
config cpu access_profile
command, below.
Syntax
create cpu access_profile [ethernet {vlan | source_mac <macmask> | destination_mac <macmask> |
ethernet_type} | ip {vlan | source_ip_mask <netmask> | destination_ip_mask <netmask> | dscp |
[icmp {type | code} | igmp {type} | tcp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-
0xffff>} | flag_mask [all | {urg | ack | psh | rst | syn | fin}]} | udp {src_port_mask <hex 0x0-0xffff> |
dst_port_mask <hex 0x0-0xffff>} | protocol_id {user_mask <hex 0x0-0xffffffff>} ]} |
packet_content_mask {offset 0-15 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex
0x0-0xffffffff>| offset 16-31 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-
0xffffffff> | {offset 32-47 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-
0xffffffff> | {offset 48-63 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-
0xffffffff> | {offset 64-79 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-
0xffffffff>}] [profile_id value 1-5>]
Description
The
create cpu access_profile
command is used to create an access profile used only for CPU Interface
Filtering. Masks can be entered that will be combined with the values the Switch finds in the specified frame
header fields. Specific values for the rules are entered using the
config cpu access_profile
command,
below.
Parameters
ethernet
Specifies that the Switch will examine the layer 2 part of each packet header.
vlan
Specifies that the Switch will examine the VLAN part of each packet header.
source_mac <macmask> -
Specifies to examine the source MAC address mask.
destination_mac <macmask> -
Specifies to examine the destination MAC address mask.
ethernet_type
Specifies that the switch will examine the Ethernet type value in each frame’s header.
ip
Specifies that the switch will examine the IP address in each frame’s header.
vlan
Specifies a VLAN mask.
source_ip_mask <netmask>
Specifies an IP address mask for the source IP address.
destination_ip_mask <netmask>
Specifies an IP address mask for the destination IP address.
dscp
Specifies that the switch will examine the DiffServ Code Point (DSCP) field in each frame’s
header.
icmp
Specifies that the switch will examine the Internet Control Message Protocol (ICMP) field in
each frame’s header.
type
Specifies that the switch will examine each frame’s ICMP Type field.
code
Specifies that the switch will examine each frame’s ICMP Code field.
igmp
Specifies that the switch will examine each frame’s Internet Group Management Protocol
(IGMP) field.
type
Specifies that the switch will examine each frame’s IGMP Type field.
tcp
Specifies that the switch will examine each frames Transport Control Protocol (TCP) field.
src_port_mask <hex 0x0-0xffff>
Specifies a TCP port mask for the source port.
dst_port_mask <hex 0x0-0xffff>
Specifies a TCP port mask for the destination port.
flag_mask - all | {urg | ack | psh | rst | syn | fin
– Enter the appropriate flag_mask parameter. All
incoming packets have TCP port numbers contained in them as the forwarding criterion. These
numbers have flag bits associated with them which are parts of a packet that determine what to do
with the packet. The user may deny packets by denying certain flag bits within the packets. The user
may choose between
all
,
urg
(urgent),
ack
(acknowledgement),
psh
(push),
rst
(reset),
syn
(synchronize) and
fin
(finish).
udp
Specifies that the switch will examine each frame’s User Datagram Protocol (UDP) field.
src_port_mask <hex 0x0-0xffff>
Specifies a UDP port mask for the source port.