xStack DES-6500 Modular Layer 3 Chassis Ethernet Switch CLI Manual
2
======================================================================
Access Profile ID: 3 TYPE : Packet Content
======================================================================
MASK Option :
Offset 0-15 : 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF
Offset 16-31 : 0x0000FFFF 0xFFFF0000 0x0000000F 0x0F000000
Access ID : 1 Mode: Deny
Ports: 1:1
Offset 0-15 : 0x11111111 0x11111111 0x11111111 0x11111111
Offset 16-31 : 0x00001111 0x11110000 0x00000001 0x01000000
======================================================================
Total Entries: 3
DES-6500:4#
create cpu access_profile
Purpose
Used to create an access profile specifically for
CPU Interface Filtering
on the Switch and to define which parts of each incoming frame’s header
the Switch will examine. Masks can be entered that will be combined
with the values the Switch finds in the specified frame header fields.
Specific values for the rules are entered using the
config cpu
access_profile
command, below.
Syntax
create cpu access_profile profile_id <value 1-5> [ethernet {vlan |
source_mac <macmask> | destination_mac <macmask> |
ethernet_type} | ip {vlan | source_ip_mask <netmask> |
destination_ip_mask <netmask> | dscp | [icmp {type | code} | igmp
{type} | tcp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex
0x0-0xffff>} | flag_mask [all | {urg | ack | psh | rst | syn | fin}]} |
udp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-
0xffff>} | protocol_id {user_mask <hex 0x0-0xffffffff>} ]} |
packet_content_mask {offset 0-15 <hex 0x0-0xffffffff> <hex 0x0-
0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff>| offset 16-31 <hex
0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-
0xffffffff> | {offset 32-47 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex
0x0-0xffffffff> <hex 0x0-0xffffffff> | {offset 48-63 <hex 0x0-0xffffffff>
<hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> | {offset
64-79 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff>
<hex 0x0-0xffffffff> }]
Description
The
create cpu access_profile
command is used to create an access
profile used only for CPU Interface Filtering. Masks can be entered that
will be combined with the values the Switch finds in the specified frame
header fields. Specific values for the rules are entered using the
config
cpu access_profile
command, below.
Parameters
profile_id <value 1-5>
−
Specifies an index number that will identify the
access profile being created with this command.
ethernet
−
Specifies that the Switch will examine the layer 2 part of each
packet header.
•
vlan
−
Specifies that the Switch will examine the VLAN part of each
packet header.
•
source_mac <macmask> -
Specifies to examine the source MAC
227