Specifications

ack:TCP control flag (acknowledgement)
psh:TCP control flag (push)
rst:TCP control flag (reset)
syn:TCP control flag (synchronize)
fin:TCP control flag (finish)
udp – Specifies that the Switch will examine the Universal Datagram Protocol (UDP) field in each
packet.
src_port <value 0-65535> – Specifies that the access profile will apply only to packets that have this
UDP source port in their header.
dst_port <value 0-65535> – Specifies that the access profile will apply only to packets that have this
UDP destination port in their header.
protocol_id <value 0-255> – Specifies that the Switch will examine the Protocol field in each packet
and if this field contains the value entered here, apply the following rules.
user_define <hex 0x0-0xfffffff> – Enter a hexadecimal value that will identify the protocol to be
discovered in the packet header.
packet_content – Specifies that the Switch will mask the packet header beginning with the offset value
specified as follows:
offset_0-15 – Enter a value in hex form to mask the packet from the beginning of the
packet to the 15th byte.
offset_16-31 - Enter a value in hex form to mask the packet from byte 16 to byte 32.
offset_32-47 - Enter a value in hex form to mask the packet from byte 32 to byte 47.
offset_64-79- Enter a value in hex form to mask the packet from byte 64 to byte 79.
permit – Specifies that packets that match the access profile are permitted to be forwarded by the Switch.
priority <value 0-7> This parameter is specified if you want to re-write the 802.1p default
priority previously set in the Switch, which is used to determine the CoS queue to which
packets are forwarded to. Once this field is specified, packets accepted by the Switch that
match this priority are forwarded to the CoS queue specified previously by the user.
{replace_priority} – Click the corresponding box if you want to re-write the 802.1p default
priority of a packet to the value entered in the Priority field, which meets the criteria
specified previously in this command, before forwarding it on to the specified CoS queue.
Otherwise, a packet will have its incoming 802.1p user priority re-written to its original
value before being forwarded by the Switch.
replace_dscp <value 0-63> Allows you to specify a value to be written to the DSCP field of an incoming
packet that meets the criteria specified in the first part of the command.This value will over-write the value in
the DSCP field of the packet.
deny – Specifies that packets that do not match the access profile are not permitted to be forwarded by the
Switch and will be filtered.
delete access_id <value 1-50> – Specifies the access ID of a rule you want to delete.
Restrictions Only administrator-level users can issue this command.
Example usage:
To configure the access profile with the profile ID of 1 to filter frames that have IP addresses in the range between 10.42.73.0 to 10.42.73.255:
AT-9724TS:4# config access_profile profile_id 2 add
access_id 1 ip source_ip 10.42.73.1 deny
Command: config access_profile profile_id 2 add access_id 1
ip source_ip 10.42.73.1 deny
S u c c e s s .
A T - 9 7 2 4 T S : 4 #
189
Allied Telesyn AT-9724TS High-Density Layer 3 Stackable Gigabit Ethernet Switch • Command Line Interface Reference Manual