xStack® DES-3200 Series Layer 2 Managed Fast Ethernet Switch
154
feature for the CPU Filtering, the Switch allows the CPU filtering mechanism to be enabled or disabled globally,
permitting the user to create various lists of rules without immediately enabling them.
NOTE: CPU Interface Filtering is used to control traffic access to the switch directly such as protocols
transition or management access. A CPU interface filtering rule won’t impact normal L2/3 traffic
forwarding. However, an improper CPU interface filtering rule may cause the network to
To view CPU Access Profile List window, click ACL > CPU Access Profile List as shown below:
Creating an access profile for the CPU is divided into two basic parts. The first is to specify which part or parts of a
frame the Switch will examine, such as the MAC source address or the IP destination address. The second part is
entering the criteria the Switch will use to determine what to do with the frame. The entire process is described
below.
Users may globally enable or disable the CPU Interface Filtering State mechanism by using the radio buttons to
change the running state. Choose Enabled to enable CPU packets to be scrutinized by the Switch and Disabled to
disallow this scrutiny.
Figure 7-23 CPU Access Profile List window
The fields that can be configured are described below:
Parameter Description
CPU Interface Filtering
Click to enable or disable the CPU interface filtering state.
Click the Apply button to accept the changes made.
Click the Add CPU ACL Profile button to add an entry to the CPU ACL Profile List.
Click the Delete All button to remove all access profiles from this table.
Click the Show Details button to display the information of the specific profile ID entry.
Click the Add/View Rules button to view or add CPU ACL rules within the specified profile ID.
Click the Delete button to remove the specific entry.
There are four Add CPU ACL Profile windows;
• one for Ethernet (or MAC address-based) profile configuration,
• one for IPv6 address-based profile configuration,
• one for IPv4 address-based profile configuration, and
• one for packet content profile configuration.
Adding a CPU Ethernet ACL Profile
The window shown below is the Add CPU ACL Profile window for Ethernet. To use specific filtering masks in this
ACL profile, click the packet filtering mask field to highlight it red. This will add more filed to the mask.