xStack
®
DGS-3600 Series Layer 3 Gigabit Ethernet Managed Switch CLI Manual
264
DGS-3627:5#show access_profile
Command: show access_profile
Total Unused Rule Entries : 1791
Total Used Rule Entries : 1
Access Profile ID: 1 TYPE : Packet Contact
======================================================================
Owner : ACL
MASK Option :
offset_chunk_1 : 1 value : 0x11111111
Access ID : 1 Mode: Permit
Rx Rate(64Kbps): no_limit
(Replaced)Priority: 2
Ports: 8
Time range: Tiberius
Total Matched Counter : 0
Offset_chunk_1 : 1 value : 0x11111111
======================================================================
Unused Entries : 127
DGS-3627:5#
create cpu access_profile
Purpose
Used to create an access profile specifically for
CPU Interface Filtering
on the Switch and to
define which parts of each incoming frame’s header the Switch will examine. Masks can be
entered that will be combined with the values the Switch finds in the specified frame header
fields. Specific values for the rules are entered using the
config cpu access_profile
command,
below.
Syntax
create cpu access_profile profile_id <value 1-5> [ethernet {vlan | source_mac <macmask
000000000000-ffffffffffff> | destination_mac <macmask 000000000000-ffffffffffff>
|
ethernet_type} | ip {vlan | source_ip_mask <netmask> | destination_ip_mask <netmask> |
dscp | [icmp {type | code} | igmp {type} | tcp {src_port_mask <hex 0x0-0xffff> |
dst_port_mask <hex 0x0-0xffff>} | flag_mask [all | {urg | ack | psh | rst | syn | fin}]} |
udp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-0xffff>} | protocol_id_mask
<hex 0x0-0xff>} {user_define_mask <hex 0x0-0xffffffff>}]} | packet_content_mask {offset 0-
15 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> | offset
16-31 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> |
{offset 32-47 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff>
| {offset 48-63 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-
0xffffffff> | {offset 64-79 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex
0x0-0xffffffff> | ipv6 {class | flowlabel | source_ipv6_mask <ipv6mask> |
destination_ipv6_mask <ipv6mask>}]}
Description
The
create cpu access_profile
command is used to create an access profile used only for CPU
Interface Filtering. Masks can be entered that will be combined with the values the Switch finds in
the specified frame header fields. Specific values for the rules are entered using the
config cpu
access_profile
command, below.
Parameters
ethernet
−
Specifies that the Switch will examine the layer 2 part of each packet header.
•
vlan
−
Specifies that the Switch will examine the VLAN part of each packet header.
•
source_mac <macmask>
−
Specifies to examine the source MAC address mask. MAC
address entries may be made in the following format:
000000000000-FFFFFFFFFFFF
•
destination_mac <macmask>
−
Specifies to examine the destination MAC address mask.
MAC address entries may be made in the following format:
000000000000-FFFFFFFFFFFF
•
ethernet_type
−
Specifies that the Switch will examine the Ethernet type value in each
frame’s header.
ip
−
Specifies that the Switch will examine the IP address in each frame’s header.
•
vlan
−
Specifies a VLAN mask.