D-Link 3324SRi Reference Manual - Page 232

create access_profile IP, Internet Group Management Protocol IGMP field.

Page 232 highlights

xStack Gigabit Layer 3 Switch Command Line Interface Manual create access_profile (IP) Restrictions • destination_ip_mask − Specifies an IP address mask for the destination IP address. • dscp − Specifies that the Switch will examine the DiffServ Code Point (DSCP) field in each frame's header. • icmp − Specifies that the Switch will examine the Internet Control Message Protocol (ICMP) field in each frame's header. • type − Specifies that the Switch will examine each frame's ICMP Type field. • code − Specifies that the Switch will examine each frame's ICMP Code field. • igmp − Specifies that the Switch will examine each frame's Internet Group Management Protocol (IGMP) field. • type − Specifies that the Switch will examine each frame's IGMP Type field. • tcp − Specifies that the Switch will examine each frames Transport Control Protocol (TCP) field. • src_port_mask − Specifies a TCP port mask for the source port. • dst_port_mask − Specifies a TCP port mask for the destination port. • flag_mask [all | {urg | ack | psh | rst | syn | fin}] - Enter the appropriate flag_mask parameter. All incoming packets have TCP port numbers contained in them as the forwarding criterion. These numbers have flag bits associated with them which are parts of a packet that determine what to do with the packet. The user may deny packets by denying certain flag bits within the packets. The user may choose between all, urg (urgent), ack (acknowledgement), psh (push), rst (reset), syn (synchronize) and fin (finish). • udp − Specifies that the Switch will examine each frame's Universal Datagram Protocol (UDP) field. • src_port_mask − Specifies a UDP port mask for the source port. • dst_port_mask − Specifies a UDP port mask for the destination port. • protocol_id − Specifies that the Switch will examine each frame's Protocol ID field. • user_define − Enter a hexidecimal value that will identify the protocol to be discovered in the packet header. profile_id - Specifies an index number between 1 and 8 that will identify the access profile being created with this command. Only administrator-level users can issue this command. Example usage: To configure a rule for the Ethernet access profile: 224

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357

xStack Gigabit Layer 3 Switch Command Line Interface Manual
create access_profile (IP)
destination_ip_mask <netmask>
Specifies an IP address
mask for the destination IP address.
dscp
Specifies that the Switch will examine the DiffServ
Code Point (DSCP) field in each frame’s header.
icmp
Specifies that the Switch will examine the Internet
Control Message Protocol (ICMP) field in each frame’s header.
type
Specifies that the Switch will examine each frame’s
ICMP Type field.
code
Specifies that the Switch will examine each frame’s
ICMP Code field.
igmp
Specifies that the Switch will examine each frame’s
Internet Group Management Protocol (IGMP) field.
type
Specifies that the Switch will examine each frame’s
IGMP Type field.
tcp
Specifies that the Switch will examine each frames
Transport Control Protocol (TCP) field.
src_port_mask <hex 0x0-0xffff>
Specifies a TCP port
mask for the source port.
dst_port_mask <hex 0x0-0xffff>
Specifies a TCP port
mask for the destination port.
flag_mask [all | {urg | ack | psh | rst | syn | fin}]
– Enter the
appropriate flag_mask parameter. All incoming packets have
TCP port numbers contained in them as the forwarding
criterion. These numbers have flag bits associated with them
which are parts of a packet that determine what to do with the
packet. The user may deny packets by denying certain flag bits
within the packets. The user may choose between
all
,
urg
(urgent),
ack
(acknowledgement),
psh
(push),
rst
(reset),
syn
(synchronize) and
fin
(finish).
udp
Specifies that the Switch will examine each frame’s
Universal Datagram Protocol (UDP) field.
src_port_mask <hex 0x0-0xffff>
Specifies a UDP port
mask for the source port.
dst_port_mask <hex 0x0-0xffff>
Specifies a UDP port
mask for the destination port.
protocol_id
Specifies that the Switch will examine each
frame’s Protocol ID field.
user_define <hex 0x0-0xfffffff>
Enter a hexidecimal value
that will identify the protocol to be discovered in the packet
header.
profile_id <value 1-8>
- Specifies an index number between 1 and 8
that will identify the access profile being created with this command.
Restrictions
Only administrator-level users can issue this command.
Example usage:
To configure a rule for the Ethernet access profile:
224