xStack® DES-3200 Series Layer 2 Ethernet Managed Switch CLI Reference Manual
21
9
DES-3200-28:4#show access_profile
Command: show access_profile
Access Profile Table
================================================================================
Profile ID: 101 Type: IPv4 Frame Filter - ICMP
================================================================================
Masks Option
VLAN Source IP Dest. IP DSCP Prot
---------------- --------------- --------------- ---- ----
0xFFF 20.0.0.0 10.0.0.0 ICMP
================================================================================
Total Profile Entries: 1
Total Used Rule Entries: 0
Total Unused Rule Entries: 512
DES-3200-28:4#
create cpu access_profile
Used to creat
e an access profile specifically for CPU Interface Filtering on the Switch and to
define which parts of each incoming frame’s header the Switch will examine. Masks can be
entered that will be combined with the values the Switch finds in the specified frame header
fields. Specific values for the rules are entered using the config cpu access_profile command,
below.
Purpose
cre
ate cpu access_profile profile_id <value 1-3> [ethernet {vlan | source_mac <macmask> |
destination_mac <macmask> | 802.1p | ethernet_type} (1) | ip { vlan | source_ip_mask
<netmask> | destination_ip_mask <netmask> | dscp | [ icmp {type | code } | igmp {type } | tcp
{src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-0xffff> | flag_mask [ all | {urg | ack |
psh | rst | syn | fin} (1) ] } | udp {src_port_mask <hex 0x0-0xffff> | dst_port_mask <hex 0x0-0xffff>}
protocol_id_mask <hex 0x0-0xff> {user_define_mask <hex 0x0-0xffffffff>} ]} (1) |
packet_content_mask {offset_0-15 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff>
<hex 0x0-0xffffffff>|offset_16-31 <hex 0x0-0xffffffff><hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex
0x0-0xffffffff>|offset_32-47 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-
0xffffffff>|offset_48-63 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-
0xffffffff>|offset_64-79 <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-0xffffffff> <hex 0x0-
0xffffffff> } (1) | ipv6 {[{ class | flowlabel | source_ipv6_mask <ipv6mask> | destination_ipv6_mask
<ipv6mask>]} (1) ]
Syntax
This
command is used to create an access profile used only for CPU Interface Filtering. Masks
can be entered that will be combined with the values the Switch finds in the specified frame
header fields. Specific values for the rules are entered using the config cpu access_profile
command, below.
Description
Parameters
ethernet Specifies that the Switch will examine the layer 2 part of each packet header.
vlan Specifies that the Switch will examine the VLAN part of each packet header.
source_mac <macmask> Specifies to examine the source MAC address mask.
destination_mac <macmask> Specifies to examine the destination MAC address mask.
802.1p Specifies that the Switch will examine the 802.1p priority value in the frame’s header.
ethernet_type Specifies that the Switch will examine the Ethernet type value in each frame’s