D-Link 3324SRi Reference Manual - Page 229

create access_profile for Ethernet, config access_profile profile_id for Ethernet

Page 229 highlights

xStack Gigabit Layer 3 Switch Command Line Interface Manual create access_profile (for Ethernet) } Description This command will allow the user to create a profile for packets that may be accepted or denied by the Switch by examining the Ethernet part of the packet header. Specific values for rules pertaining to the Ethernet part of the packet header may be defined by configuring the config access_profile command for Ethernet, as stated below. Parameters ethernet - Specifies that the Switch will examine the layer 2 part of each packet header with emphasis on one or more of the following: • vlan − Specifies that the Switch will examine the VLAN part of each packet header. • source_mac − Specifies a MAC address mask for the source MAC address. This mask is entered in the following hexadecimal format: 000000000000-FFFFFFFFFFFF • destination_mac − Specifies a MAC address mask for the destination MAC address in the following format: 000000000000-FFFFFFFFFFFF • 802.1p − Specifies that the Switch will examine the 802.1p priority value in the frame's header. • ethernet_type − Specifies that the Switch will examine the Ethernet type value in each frame's header. profile_id - Specifies an index number between 1 and 8 that will identify the access profile being created with this command. Restrictions Only administrator-level users can issue this command. Example usage: To create a Ethernet access profile: DGS-3324SRi:4#create access_profile ethernet vlan 802.1p profile_id 1 Command: create access_profile ethernet vlan 802.1p profile_id 1 Success. DGS-3324SRi:4# config access_profile profile_id (for Ethernet) Purpose Syntax Used to configure the Ethernet access profile on the Switch and to define specific values for the rules that will be used to by the Switch to determine if a given packet should be forwarded or filtered. Masks entered using the create access_profile command will be combined, using a logical AND operational method, with the values the Switch finds in the specified frame header fields. config access_profile profile_id [add access_id [ethernet {vlan | source_mac | destination_mac | 802.1p | ethernet_type } port [permit {priority {replace_priority} | replace_dscp } | deny] delete 221

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357

xStack Gigabit Layer 3 Switch Command Line Interface Manual
create access_profile (for Ethernet)
<value 1-8>}
Description
This command will allow the user to create a profile for packets that
may be accepted or denied by the Switch by examining the Ethernet
part of the packet header. Specific values for rules pertaining to the
Ethernet part of the packet header may be defined by configuring the
config access_profile
command for Ethernet, as stated below.
Parameters
ethernet
- Specifies that the Switch will examine the layer 2 part of
each packet header with emphasis on one or more of the following:
profile_id <value 1-8>
- Specifies an index number between 1 and 8
that will identify the access profile being created with this command.
Restrictions
Only administrator-level users can issue this command.
vlan
Specifies that the Switch will examine the VLAN part of
each packet header.
source_mac <macmask>
Specifies a MAC address mask for
the source MAC address. This mask is entered in the following
hexadecimal format: 000000000000-FFFFFFFFFFFF
destination_mac <macmask>
Specifies a MAC address
mask for the destination MAC address in the following format:
000000000000-FFFFFFFFFFFF
802.1p
Specifies that the Switch will examine the 802.1p
priority value in the frame’s header.
ethernet_type
Specifies that the Switch will examine the
Ethernet type value in each frame’s header.
Example usage:
To create a Ethernet access profile:
DGS-3324SRi:4#create access_profile ethernet vlan 802.1p profile_id 1
Command: create access_profile ethernet vlan 802.1p profile_id 1
Success.
DGS-3324SRi:4#
config access_profile profile_id (for Ethernet)
Purpose
Used to configure the Ethernet access profile on the Switch and to
define specific values for the rules that will be used to by the Switch
to determine if a given packet should be forwarded or filtered. Masks
entered using the
create access_profile
command will be
combined, using a logical AND operational method, with the values
the Switch finds in the specified frame header fields.
Syntax
config access_profile profile_id <value 1-8> [add access_id
<value 1-100> [ethernet {vlan <vlan_name 32> | source_mac
<macaddr 000000000000-ffffffffffff> | destination_mac <macaddr
000000000000-ffffffffffff> | 802.1p <value 0-7> | ethernet_type
<hex 0x0-0xffff>} port <port> [permit {priority <value 0-7>
{replace_priority} | replace_dscp <value 0-63> } | deny] delete
221