DGS-1510/ME Series Metro Ethernet Switch CLI Reference Guide
73
6-1
create access_profile
Description
This command is used to create access control list profiles.
When creating ACL, each profile can have 128 rules/access IDs. However, when creating ACL type as Ethernet or
IPv4 at the first time, 62 rules are reserved for the system. In this case, only 66 rules are available to configure.
You can use the
show access_prfile
command to see the available rules.
Profile ID 1 is reserved for Ethernet profile, and profile ID 2 is reserved for IPv4 profile. Both IDs cannot be deleted
from the Switch.
The Switch supports the following profile types:
1. MAC DA, MAC SA, Ethernet Type, Outer VLAN Tag
2. Outer VLAN Tag, Source IPv4, Destination IPv4, DSCP, Protocol ID, TCP/UDP Source Port, TCP/UDP
Destination Port, ICMP type/code, IGMP type, TCP flags
3. Source IPv6 Address, Class, Flow Label, IPv6 Protocol (Next Header)
4. Destination IPv6 Address, Class, Flow Label, IPv6 Protocol (Next Header)
5. Class, Flow Label, IPv6 Protocol (Next Header), TCP/UDP source port, TCP/UDP destination port, ICMP
type/code, Outer VLAN Tag
6. Packet Content, Outer VLAN Tag
7. MAC SA, Ethernet Type, Source IPv4/ARP sender IP, Outer VLAN Tag
8. LLC Header/SNAP Header, Outer VLAN Tag
9. Source IPv6 Address, Class, IPv6 Protocol (Next Header), Outer VLAN Tag
10. Destination IPv6 Address, Class, IPv6 Protocol (Next Header), Outer VLAN Tag
Format
create access_profile profile_id <value 1-512> {profile_name <name 32>} [ethernet{vlan {<hex 0x0-0x0fff>}
| source_mac <macmask 000000000000-ffffffffffff> | destination_mac <macmask 000000000000-ffffffffffff> |
802.1p | ethernet_type}|ip {vlan {<hex 0x0-0x0fff>} | source_ip_mask <netmask> | destination_ip_mask
<netmask> | dscp | [icmp {type | code} | igmp {type} | tcp {src_port_mask <hex0x0-0xffff> | dst_port_mask
<hex 0x0-0xffff> | flag_mask [all | {urg | ack | psh | rst | syn | fin}]} | udp {src_port_mask <hex 0x0-0xffff> |
dst_port_mask <hex 0x0-0xffff>} | protocol_id_mask <hex 0x0-0xff> {user_define_mask <hex 0x0-
0xffffffff>}]} | packet_content_mask {offset_chunk_1 <value 0-31> <hex 0x0-0xffffffff> | offset_chunk_2
<value 0-31> <hex 0x0-0xffffffff> | offset_chunk_3<value 0-31> <hex 0x0-0xffffffff> | offset_chunk_4 <value
0-31> <hex 0x0-0xffffffff>} | ipv6 {class | flowlabel | source_ipv6_mask <ipv6mask> |
destination_ipv6_mask <ipv6mask> | [tcp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-
0xffff>} | udp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-0xffff>} | icmp {type | code}]}]
Parameters
<value 1-512>
- Enter the profile ID here. This value must be between 1 and512.
profile_name
– (Optional) Specifies the name of the profile. The maximum length is 32 characters.
<name 32>
- Enter the profile name here.
ethernet
- Specifies this is an Ethernet mask.
vlan
- (Optional) Specifies a VLAN mask. Only the last 12 bits of the mask will be considered.
<hex 0x0-0x0fff>
- Enter the VLAN mask value here.
source_mac
- (Optional) Specifies the source MAC mask.
<macmask>
- Enter the source MAC address used here.
destination_mac
- (Optional) Specifies the destination MAC mask.
<macmask>
- Enter the destination MAC address used here.
802.1p
- (Optional) Specifies the 802.1p priority tag mask.
Содержание DGS-1510/ME Series
Страница 1: ......