Page 91 / 160 Scroll up to view Page 86 - 90
DGS-3224TGR Gigabit Ethernet Switch User’s Guide
79
Select
Ethernet
to instruct the Switch to examine the layer 2 part of each packet
header.
Select
IP
to instruct the Switch to examine the IP address in each frame's header.
Offset
This field will instruct the Switch to mask the packet header beginning with the offset
value specified:
value (0-15)
- Enter a value in hex form to mask the packet from the beginning of
the packet to the 15th byte.
value (16-31)
– Enter a value in hex form to mask the packet from byte 16 to byte
31.
value (32-47)
– Enter a value in hex form to mask the packet from byte 32 to byte
47.
value (48-63)
– Enter a value in hex form to mask the packet from byte 48 to byte
63.
value (64-79)
– Enter a value in hex form to mask the packet from byte 64 to byte
79.
Port
The user may set the
Access Profile Mask Setting
window
on a per-port basis by
entering a port number in this field. The port list is specified by listing the beginning
port number on that switch and the highest port number of the range. The beginning
and end of the port list range are separated by a dash. For example, 3-8 specifies all
of the ports between port 3 and port 8
in numerical order. Entering
all
will denote all
ports on the Switch.
To establish the rule for a previously created Access Profile Mask:
Select the Access Profile from the
Access Profile Mask Setting
window and click the
Edit Rule
button.
Figure 6- 62.
Access Profile Rule Setting (Ethernet) window
Page 92 / 160
DGS-3224TGR Gigabit Ethernet Switch User’s Guide
80
Figure 6- 63.
Access Profile Rule Setting (IP) window
Figure 6- 64.
Access Profile Rule Setting (Packet Content Mask) window
To create a new rule set for an access profile, click the
New
button. A new window is displayed. To remove a previously
created rule, select it and click the
Delete
button.
Page 93 / 160
DGS-3224TGR Gigabit Ethernet Switch User’s Guide
81
Figure 6- 65.
Access Profile Rule Setting – Add (Ethernet) window
Figure 6- 66.
Access Profile Rule Setting – Add (IP) window
Page 94 / 160
DGS-3224TGR Gigabit Ethernet Switch User’s Guide
82
Figure 6- 67.
Access Profile Rule Setting – Add (Package Content Mask) window
Configure the following Access Profile Rule Settings:
Parameter
Description
Profile ID
This is the identifier number for this profile set.
Access Rule ID
Type in a unique identifier number for this access. This value can be set from 0 to 255.
Page 95 / 160
DGS-3224TGR Gigabit Ethernet Switch User’s Guide
83
Access Profile
Selected profile based on Ethernet (MAC Address), IP address, or Packet Content Mask.
Ethernet
instructs the Switch to examine the layer 2 part of each packet header.
IP
instructs the Switch to examine the IP address in each frame's header.
Packet Content Mask
instructs the Switch to examine the packet header
Mode
Select Permit to specify that the packets that match the access profile are forwarded by
the Switch, according to any additional rule added (see below).
Select Deny to specify that packets that do not match the access profile are not forwarded
by the Switch and will be filtered.
VLAN
Selecting this option instructs the Switch to examine the VLAN part of each packet header
and use this as the, or part of the criterion for forwarding.
replace
priority
(0-7)
Select this option to instruct the switch to replace the 802.1p value (in a packet that meets
the selected criteria). In this way, packets meeting the criteria can have their priority
handling modified for use within the switch, and then have a different priority value
assigned when they leave the switch.
replace_dscp (0-
63)
Select this option to instruct the switch to replace the DSCP value (in a packet that meets
the selected criteria) with the value entered in the adjacent field.
Protocol
Selecting this option instructs the Switch to examine the protocol type value in each
frame's header. You must then specify what protocol(s) to include according to the
following guidelines:
Select ICMP to instruct the Switch to examine the Internet Control Message Protocol
(ICMP) field in each frame's header.
Offset Settings:
This field will instruct the Switch to mask the packet header beginning with the offset value
specified:
value (0-15)
- Enter a value in hex form to mask the packet from the beginning of the
packet to the 15th byte.
value (16-31)
- Enter a value in hex form to mask the packet from byte 16 to
byte 31.
value (32-47)
- Enter a value in hex form to mask the packet from byte 32 to byte 47.
value (48-63)
- Enter a value in hex form to mask the packet from byte 48 to byte 63.
value (64-79)
- Enter a value in hex form to mask the packet from byte 64 to byte 79.
Port Security
A given port’s (or a range of port’s) dynamic MAC address learning can be locked such that the current source MAC
addresses entered into the MAC address forwarding table can not be changed once the port lock is enabled. The port can be
locked by changing the Admin State pull-down menu to
Enabled
on the
Port Security Settings – Edit
window, shown
below, and clicking
Apply
.
This is a security feature that prevents unauthorized computers (with source MAC addresses unknown to the switch prior to
locking the port (or ports) from connecting to the switch’s locked ports and gaining access to the network.

Rate

4 / 5 based on 1 vote.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top