Security
54
"FD 100/320Gbps NT and FX NT IHub System
Basics, Management and OAM Guide"
3HH-11982-AAAA-TQZZA Issue: 10
4.4.2.6 match
Table 41 match command
Table 42 IP Protocol Names
Item Description
Syntax [no] match [protocol protocol-id]
Context configure>system>security>cpu-filter>ip-filter>entry
Description This command enables the context to enter match criteria for the filter entry. When the match
criteria have been satisfied the action associated with the match criteria is executed.
If more than one match criteria (within one match statement) are configured then all criteria
must be satisfied (AND function) before the action associated with the match is executed.
A match context may consist of multiple match criteria, but multiple match statements cannot
be entered per entry.
The no form of the command removes the match criteria for the entry-id.
Parameters protocol — The protocol keyword configures an IP protocol to be used as an IP filter match
criterion. The protocol type such as TCP or UDP is identified by its respective protocol number.
protocol-id — Configures the decimal value representing the IP protocol to be used as an IP
filter match criterion. Well known protocol numbers include ICMP(1), TCP(6), UDP(17). The no
form the command removes the protocol from the match criteria.
Values: 0 — 255: protocol numbers accepted in DHB
keywords - none|crtp|crudp|egp|eigrp|encap|ether-ip| gre|icmp|
idrp|igmp| igp|ip|ipv6|ipv6-frag|ipv6-icmp|ipv6-no-nxt|ipv6-opts|
ipv6-route|isis|iso-ip|l2tp| ospf-igp|pim|pnni|ptp|rdp|rsvp|stp|tcp|
udp|vrrp
* — udp/tcp wildcard
Protocol Protocol ID Description
icmp 1 Internet Control Message
igmp 2 Internet Group Management
ip 4 IP in IP (encapsulation)
tcp 6 Transmission Control Protocol
egp 8 Exterior Gateway Protocol
igp 9 any private interior gateway (used by Cisco for their IGRP)
udp 17 User Datagram
rdp 27 Reliable Data Protocol
ipv6 41 IPv6
ipv6-route 43 Routing Header for IPv6
ipv6-frag 43 Fragment Header for IPv6
idrp 45 Inter-Domain Routing Protocol
(1 of 2)