D-Link 3312SR Reference Manual - Page 192
Access Control List (ACL) Commands, create, access_profile
![]() |
UPC - 790069263873
View all D-Link 3312SR manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 192 highlights
DGS-3312SR Layer 3 Gigabit Switch 25 ACCESS CONTROL LIST (ACL) COMMANDS The DGS-3312SR implements Access Control Lists that enable the switch to deny network access to specific devices or device groups based on IP settings or MAC address. The ACL commands in the Command Line Interface (CLI) are listed (along with the appropriate parameters) in the following table. Command create access_profile delete access_profile profile_id config access_profile profile_id show access_profile Parameters [ethernet {vlan | source_mac | destination_mac | 802.1p | ethernet_type} | ip {vlan | source_ip_mask | destination_ip_mask | dscp | [icmp {type | code} | igmp {type} | tcp {src_port_mask | dst_port_mask | flag_mask [all | {urg | ack | psh | rst | syn | fin}]} | udp {src_port_mask | dst_port_mask } | protocol_id {user_mask }]} | packet_content_mask {offset_0-15 | offset_16-31 | offset_32-47 | offset_48-63 | offset_64-79 }] {port [ | all]} [profile_id ] [add access_id [ethernet {vlan | source_mac | destination_mac | 802.1p | ethernet_type [permit {priority {replace_priority}} | deny ] | ip {vlan | source_ip | destination_ip | dscp | [icmp {type code } | igmp {type } | tcp {src_port | dst_port | flag_mask [all | {urg | ack | psh | rst | syn | fin}]} | udp {src_port | dst_port } | protocol_id {user_define }]} [permit {priority {replace_priority }} | deny ] | packet_content {offset_0-15 | offset_16-31 | offset_32-47 | offset_48-63 | offset_64-79 }] [permit {priority {replace_priority} | deny] | delete access_id ] {profile_id } Access profiles allow you to establish criteria to determine whether or not the switch will forward packets based on the information contained in each packet's header. These criteria can be specified on a VLAN-by-VLAN basis. Creating an access profile is divided into two basic parts. First, an access profile must be created using the create access_profile command. For example, if you want to deny all traffic to the subnet 10.42.73.0 to 10.42.73.255, you must first create an access profile that instructs the switch to examine all of the relevant fields of each frame: 186
![](/manual_guide/products/dlink-3312sr-reference-manual-4c3c9f4/192.png)