DES-1228/ME Metro Ethernet Managed Switch CLI Reference Guide
215
create access_profile
for the rules are entered using the config access_profile command, below.
Parameters
ethernet
−
Specifies that the Switch will examine the layer 2 part of each packet header.
vlan
−
Specifies a VLAN mask. Only the last 12 bits of the mask will be considered.
source_mac <macmask>
−
Specifies a MAC address mask for the source MAC address.
This mask is entered in a hexadecimal format.
destination_mac <macmask>
−
Specifies a MAC address mask for the destination MAC
address.
802.1p
−
Specifies that the Switch will examine the 802.1p priority value in the frame’s
header.
ethernet_type
−
Specifies that the Switch will examine the Ethernet type value in each
frame’s header.
ip
−
Specifies that the Switch will examine the IP fields in each frame’s header.
vlan
−
Specifies a VLAN mask. Only the last 12 bits of the mask will be considered.
source_ip_mask <netmask>
−
Specifies an IP address mask for the source IP address.
destination_ip_mask <netmask>
−
Specifies an IP address mask for the destination IP
address.
dscp
−
Specifies that the Switch will examine the DiffServ Code Point (DSCP) field in each
frame’s header.
icmp
−
Specifies that the Switch will examine the Internet Control Message Protocol
(ICMP) field in each frame’s header.
type
−
Specifies that the Switch will examine each frame’s ICMP Type field.
code
−
Specifies that the Switch will examine each frame’s ICMP Code field.
igmp
−
Specifies that the Switch will examine each frame’s Internet Group Management
Protocol (IGMP) field.
type – Specifies that the Switch will examine each frame’s IGMP Type field.
tcp
−
Specifies that the Switch will examine each frames Transport Control Protocol (TCP)
field.
src_port_mask <hex 0x0-0xffff>
−
Specifies a TCP port mask for the source port.
dst_port_mask <hex 0x0-0xffff>
−
Specifies a TCP port mask for the destination port.
flag_mask – Enter the appropriate flag_mask parameter. All incoming packets have TCP
port numbers contained in them as the forwarding criterion. These numbers have flag
bits associated with them which are parts of a packet that determine what to do with
the packet. The user may deny packets by denying certain flag bits within the packets.
The user may choose among all, urg (urgent), ack (acknowledgement), psh (push), rst
(reset), syn (synchronize) and fin (finish).
udp
−
Specifies that the Switch will examine each frame’s Universal Datagram Protocol (UDP)
field.
src_port_mask <hex 0x0-0xffff>
−
Specifies a UDP port mask for the source port.
dst_port_mask <hex 0x0-0xffff>
−
Specifies a UDP port mask for the destination port.
protocol_id_mask
−
Specifies that the Switch will examine the protocol field in each packet
and if this field contains the value entered here, apply the following rules.
ipv6 - Specifies IPv6 filtering mask.
class – Specifies the IPv6 class.
flowlabel – Specifies the IPv6 flow label.
source_ipv6_mask – Specifies an IPv6 source submask. The device only supports filtering of
the last 44 bits (LSB) of the source IPv6 address.
src_port_mask – Specifies an IPv6 L4 (TCP/UDP) source port submask.
dst_port_mask - Specifies an IPv6 L4 (TCP/UDP) destination port submask.
profile_id <value 1-256>
−
Sets the relative priority for the profile. Priority is set relative to
other profiles where the lowest profile ID has the highest priority. The user may enter a profile