D-Link xStackTM DGS/DXS-3300 Series Switch User Manual


 
xStack DGS/DXS-3300 Series Layer 3 Stackable Gigabit Ethernet Switch CLI Manual
235
config cpu access_profile
packet_content_mask – Specifies that the Switch will mask the packet
header beginning with the offset value specified as follows:
offset_0-15 - Enter a value in hex form to mask the packet from byte 0
to byte 15.
offset_16-31 - Enter a value in hex form to mask the packet from byte
16 to byte 31.
offset_32-47 - Enter a value in hex form to mask the packet from byte
32 to byte 47.
offset_48-63 - Enter a value in hex form to mask the packet from byte
48 to byte 63.
offset_64-79 - Enter a value in hex form to mask the packet from byte
64 to byte 79.
ipv6 - Specifies that the Switch will look into the IPv6 fields in each packet, with
emphasis on one or more of the following fields:
class <value 0-255> - Entering this parameter will instruct the Switch to
examine the class field of the IPv6 header. This class field is a part of the
packet header that is similar to the Type of Service (ToS) or Precedence
bits field in IPv4.
flowlabel <hex 0x0-fffff> - Entering this parameter will instruct the Switch to
examine the flow label field of the IPv6 header. This flow label field is used
by a source to label sequences of packets such as non-default quality of
service or real time service packets. This field is to be defined by the user
in hex form.
source_ipv6 <ipv6addr> - Specifies an IP address mask for the source
IPv6 address.
destination_ipv6 <ipv6addr> - Specifies an IP address mask for the
destination IPv6 address.
permit – Specifies that packets that match the access profile are permitted to be
forwarded by the Switch.
deny – Specifies that packets that match the access profile are not permitted to
be forwarded by the Switch and will be filtered.
delete access_id <value 1-5> - Use this to remove a previously created access
rule in a profile ID.
Restrictions Only administrator-level users can issue this command.
Example usage:
To configure cpu access list entry:
DGS-3324SRi:4#config cpu access_profile profile_id 10 add access_id 1 ip vlan default
source_ip 20.2.2.3 destination_ip 10.1.1.252 dscp 3 icmp type 11 code 32 deny
Command: config cpu access_profile profile_id 10 add access_id 1 ip vlan default
source_ip 20.2.2.3 destination_ip 10.1.1.252 dscp 3 icmp type 11 code 32 deny
Success.
DGS-3324SRi:4#