DGS-3200 Series Layer 2 Gigabit Managed Switch CLI Manual
413
flag_mask [ al | {urg | ack | psh| rst| syn | fin}] } |
udp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-0xffff>} |
protocol_id_mask <hex 0x0-0xff> {user_define_mask <hex 0x0-0xffffffff>}]}
| packet_content_mask
{offset_chunk_1 <value 0-31> <hex 0x0-0xffffffff>
offset_chunk_2 <value 0-31> <hex 0x0-0xffffffff>
offset_chunk_3 <value 0-31> <hex 0x0-0xffffffff>
offset_chunk_4 <value 0-31> <hex 0x0-0xffffffff>} | ipv6
{class | flowlabel | source_ipv6_mask<ipv6mask> | destination_ipv6_mask <ipv6mask>} ]
Description
The
create access_profile
command creates access list rules.
Note: Please see the Appendix section entitled “Mitigating ARP Spoofing Attacks Using Packet Content
ACL” for a configuration example and further information.
Parameters
Parameters
Description
vlan
Specifies a VLAN mask.
source_mac
Specifies the source MAC mask.
destination_mac
Specifies the destination MAC mask.
802.1p
Specifies 802.1p priority tag mask.
ethernet_type
Specifies the Ethernet type mask.
vlan
Specifies a VLAN mask.
source_ip_mask
Specifies an IP source submask.
destination_ip_mask
Specifies an IP destination submask.
dscp
Specifies the DSCP mask.
Specifies that the rule applies to icmp traffic.
type
Specifies the ICMP packet type.
icmp
code
Specifies the ICMP code.
Specifies that the rule applies to IGMP traffic.
igmp
type
Specifies the IGMP packet type
Specifies that the rule applies to TCP traffic.
src_port_mask
Specifies the TCP source port mask.
dst_port_mask
Specifies the TCP destination port mask.
tcp
flag_mask
Specifies the TCP flag field mask.
Specifies that the rule applies to UDP traffic.
src_port_mask
Specifies the TCP source port mask.
udp
dst_port_mask
Specifies the TCP destination port mask.
protocod_id_mask
Specifies that the rule applies to the IP protocol ID traffic.