DGS-3700 Series Layer 2 Managed Gigabit Ethernet Switch CLI Reference Guide
Page | 370
config access_profile
<ipv6addr> {mask <ipv6mask>} | destination_ipv6 <ipv6addr> {mask
<ipv6mask>}]}] [ port [<portlist>|all] | vlan_based [vlan <vlan_name 32> |
vlan_id <vlanid 1-4094>] ] [permit {priority <value 0-7> {replace_priority}
|[replace_dscp_with <value 0-63>|replace_tos_precedence_with <value 0-
7>]|couner[enable|disable]} |mirror |deny] {time_range <range_name
32>}|delete access_id <value 1-128>]
Description
This command is used to configure an access profile on the Switch and to enter
specific values that will be combined, using a logical AND operational method,
with masks entered with the
create access_profile
command, above.
Parameters
profile_id <value 1-12>
−
Enter an integer used to identify the access profile that will
be configured with this command. This value is assigned to the access profile when
it is created with the
create access_profile
command. The profile ID sets the
relative priority for the profile and specifies an index number that will identify the
access profile being created with this command. Priority is set relative to other
profiles where the lowest profile ID has the highest priority. The user may enter a
profile ID number between 1 and 12, yet, remember only 12 access profiles can be
created on the Switch.
profile_name<name 1-32>
– Specifies the name of the profile. The maximum length
is 32 characters.
add access_id <value 1-128>
−
Adds an additional rule to the above specified access
profile. The value is used to index the rule created. For information on number of
rules that can be created for a given port, lease see the introduction to this chapter.
ethernet
−
Specifies that the Switch will look only into the layer 2 part of each packet.
vlan <vlan_name 32>|vlan_id <value 1-4094>
−
Specifies that the access profile will
apply to only to this VLAN.
source_mac <macaddr>
−
Specifies that the access profile will apply to only packets
with this source MAC address.
destination_mac <macaddr>
−
Specifies that the access profile will
apply to only packets with this destination MAC address.
802.1p <value 0-7>
−
Specifies that the access profile will apply only to packets with
this 802.1p priority value.
ethernet_type <hex 0x0-0xffff>
−
Specifies that the access profile will apply only to
packets with this hexadecimal 802.1Q Ethernet type value in the packet header.
Parameters
ip
−
Specifies that the Switch will look into the IP fields in each packet.
vlan <vlan_name 32>|vlan_id<value 1-4094>
−
Specifies that the access profile will
apply to only this VLAN.
source_ip <ipaddr>
−
Specifies that the access profile will apply to only packets with
this source IP address.
destination_ip <ipaddr>
−
Specifies that the access profile will apply to only packets
with this destination IP address.
dscp <value 0-63>
−
Specifies that the access profile will apply only to packets that
have this value in their Type-of-Service (DiffServ code point, DSCP) field in their
IP packet header
icmp
−
Specifies that the Switch will examine the Internet Control Message
Protocol (ICMP) field within each packet.
type <value 0-65535>
−
Specifies that the access profile will apply to this ICMP
type value.
code <value 0-255>
−
Specifies that the access profile will apply to this ICMP code.
igmp
−
Specifies that the Switch will examine the Internet Group Management