EasyManuals Logo

D-Link xStack DGS-3610 Series User Manual

D-Link xStack DGS-3610 Series
703 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #617 background imageLoading...
Page #617 background image
DGS-3610 Series Configuration Guide Chapter 44 Access Control List Configuration
44-17
Letter
Meaning
Offset
Letter
Meaning
Offset
D
VLAN tag field
14
R
Source IP address
38
E
DSAP (destination
service access point)
field
18
S
Destination IP address
42
F
SSAP (source service
access point) field
19
T
TCP source port
46
G
Ctrl field
20
U
TCP destination port
48
H
Org Code field
21
V
Sequential number
50
I
Encapsulated data type
24
W
Confirmation field
54
J
IP version No.
26
XY
IP header length and
reservation bits
58
K
TOS field
27
Z
Reservation bit and flags
bit
59
L
IP packet length
28
a
Windows size field
60
M
ID
30
b
Others
62
N
Flags field
32
In the table above, the offset of each field is the same as that in the SNAP+tag 802.3 data
frame. In the user-defined access control list, the user can use two parameters, the rule
mask and offset, to abstract any byte from the first 64 bytes of the data frame, and then
compare it with the user defined rule to filter the matched data frame for corresponding
processing. The user defined rule can be some fixed attributes of the data. For example, the
user wants to filter all the TCP packets by defining the rule as 06, rule mask as FF and offset
as 35. Here, the rule mask and offset work together to abstract the contents of the TCP
protocol ID field in the received data frame, and compare it with the rule to filter all TCP
packets.
Note
DGS-3610-26P does not support ACL80. ACL80 does not support the
function of matching packets of Ethernet, 803.3snap and 802.3llc. If the
value of matching DSAP to the cntl field is set to AAAA03, it indicates the
803.3snap packet is to be matched. If the value is set to E0E003, it
indicates that the 803.3llc packet is to be matched. The field cannot be
matched for Ethernet packets.
Precautions for configuration:
Only 16 bytes can be matched at will for ACL80. If the resource is occupied, you cannot
match any other byte. For example,
DGS-3610(config)# expert access-list advanced name
DGS-3610(config-exp-dacl)#permit 11223344556677889900aabbccd
deeff ffffffffffffffffffffffffffffffff 50
Add another ACE:
DGS-3610(config-exp-dacl)#permit 11223344556677889900aabbccd

Table of Contents

Other manuals for D-Link xStack DGS-3610 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the D-Link xStack DGS-3610 Series and is the answer not in the manual?

D-Link xStack DGS-3610 Series Specifications

General IconGeneral
BrandD-Link
ModelxStack DGS-3610 Series
CategorySwitch
LanguageEnglish

Related product manuals