![D-Link xStack DGS-3612G series Cli Manual Download Page 260](http://html1.mh-extra.com/html/d-link/xstack-dgs-3612g-series/xstack-dgs-3612g-series_cli-manual_3519854260.webp)
xStack
®
DGS-3600 Series Layer 3 Gigabit Ethernet Managed Switch CLI Manual
257
config access_profile (IP)
•
priority <value 0-7>
−
This parameter is specified to re-write the 802.1p default priority
previously set in the Switch, which is used to determine the CoS queue to which
packets are forwarded to. Once this field is specified, packets accepted by the Switch
that match this priority are forwarded to the CoS queue specified previously by the user.
•
{replace_priority}
−
Enter this parameter to re-write the 802.1p default priority of a
packet to the value entered in the Priority field, which meets the criteria specified
previously in this command, before forwarding it on to the specified CoS queue.
Otherwise, a packet will have its incoming 802.1p user priority re-written to its original
value before being forwarded by the Switch.
replace_dscp <value 0-63>
−
Allows the user to specify a value to be written to the DSCP
field of an incoming packet that meets the criteria specified in the first part of the command.
This value will over-write the value in the DSCP field of the packet.
rx_rate
−
Use this to limit Rx bandwidth for the profile being configured. This rate is
implemented using the following equation – 1 value = 64kbit/sec. (ex. If the user selects a rx
rate of 10 then the ingress rate is 640kbit/sec.) The user many select a value between 1-
156249 or no limit. The default setting is no limit.
counter [enable | disable]
– Use this parameter to enable the counter function. When
enabled, this counter will count the number of packets that match the profile stated with this
command. If the counter command is enabled using the flow_meter command, the conter
command here will be overridden and therefore will not count packets. This command is
optional and the default setting is
disabled
.
mirror
−
Selecting
mirror
specifies that packets that match the access profile are mirrored to a
port defined in the
config mirror port
command. Port Mirroring must be enabled and a target
port must be set.
deny
– Specifies that packets that do not match the access profile are not permitted to be
forwarded by the Switch and will be filtered.
{time_range <range_name 32>}
– Choose this parameter and enter the name of the Time
Range settings that has been previously configured using the
config time_range
command.
This will set specific times when this access rule will be enabled or disabled on the Switch.
delete access_id <value 1-128>
−
Use this command to delete a specific rule from the IP
profile. Up to 128 rules may be specified for the IP access profile.
Restrictions
Only Administrator and Operator-level users can issue this command.
Example usage:
To configure a rule for the IP access profile:
DGS-3627:5#config access_profile profile_id 2 add access_id 2 ip protocol_id 2
port 2 deny
Command: config access_profile profile_id 2 add access_id 2 ip protocol_id 2
port 2 deny
Success.
DGS-3627:5#
create access_profile (packet content )
Purpose
Used to create an access profile on the Switch by examining the Ethernet part of the
packet header. Packet content masks entered will specify certain bytes of the packet
header to be identified by the Switch. When the Switch recognizes a packet with the
identical byte as the one configured, it will either forward or filter the packet, based on
the users command. Specific values for the rules are entered using the
config
access_profile
command, below.
Syntax
create access_profile profile_id <value 1-14> packet_content_mask
{offset_chunk_1 <value 0-31> <hex 0x0-0xffffffff> | offset_chunk_2 <value 0-31>
<hex 0x0-0xffffffff> | offset_chunk_3 <value 0-31> <hex 0x0-0xffffffff> |