config access_profile profile_id (for Ethernet)
written to its original value before being forwarded by the Switch.
deny
– Specifies that packets that do not match the access profile
are not permitted to be forwarded by the Switch and will be filtered.
delete access_id <value 1-100>
−
Use this command to delete a
specific rule from the Ethernet profile. Up to 100 rules may be
specified for the Ethernet access profile.
Restrictions Only
administrator-level users can issue this command.
Example usage:
DES-6500:4#config access profile profile_id 1 add access_id 1 ethernet
vlan Trinity 802.1p 1 port 1:1 permit priority 1 replace priority
Command: config access profile profile_id 1 add access_id 1 ethernet
vlan Trinity 802.1p 1 port 1:1 permit priority 1 replace priority
Success.
DES-6500:4#
To configure a rule for the Ethernet access profile:
create access_profile (IP)
Purpose
Used to create an access profile on the Switch by examining the IP
part of the packet header. Masks entered can be combined with the
values the Switch finds in the specified frame header fields. Specific
values for the rules are entered using the
config access_profile
command, below.
create access_profile ip {vlan | source_ip_mask <netmask> |
destination_ip_mask <netmask> | dscp | [icmp {type | code} | igmp
{type} | tcp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex
0x0-0xffff> | flag_mask [all | {urg | ack | psh | rst | syn | fin}]} | udp
{src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-xffff>} |
protocol_id {user _mask <hex 0x0-0xffffffff>}]} profile_id <value 1-8>}
Description
This command will allow the user to create a profile for packets that
may be accepted or denied by the Switch by examining the IP part of
the packet header. Specific values for rules pertaining to the IP part
of the packet header may be defined by configuring the
config
access_profile
command for IP, as stated below.
Parameters
ip
- Specifies that the Switch will look into the IP fields in each packet
with special emphasis on one or more of the following:
vlan
−
Specifies a VLAN mask.
dscp
−
Specifies that the Switch will examine the DiffServ Code
Point (DSCP) field in each frame’s header.
source_ip_mask <netmask>
−
Specifies an IP address mask for the
source IP address.
destination_ip_mask <netmask>
−
Specifies an IP address mask for
the destination IP address.
icmp
−
Specifies that the Switch will examine the Internet Control
Message Protocol (ICMP) field in each frame’s header.
type
−
Specifies that the Switch will examine each frame’s ICMP
Type field.
code
−
Specifies that the Switch will examine each frame’s ICMP
Code field.
igmp
−
Specifies that the Switch will examine each frame’s Internet
Group Management Protocol (IGMP) field.
Syntax
Summary of Contents for TM DES-6500
Page 6: ...Register online your D Link product at http support dlink com register vi...
Page 33: ...DES 6500 Example usage To terminate the current user s console session DES 6500 4 logout...
Page 62: ...DES 6500 4 disable rmon Command disable rmon Success DES 6500 4...
Page 128: ...DES 6500 4 disable ipif s2 Command disable ipif s2 Success DES 6500 4...
Page 262: ...DES 6500 4 config command_history 20 Command config command_history 20 Success DES 6500 4...
Page 266: ......
Page 267: ...1...