D-Link DGS-3200 Series User Manual page 248

Layer 2 gigabit ethernet managed switch
Hide thumbs Also See for DGS-3200 Series:
Table of Contents

Advertisement

Configuration
The configuration logic is as follows:
1. Only if the ARP matches Source MAC address in Ethernet, Sender MAC address and Sender IP address in ARP protocol can
pass through the switch. (In this example, it is gateway's ARP.)
2. The switch will deny all other ARP packets which claim they are from the gateway's IP.
The design of Packet Content ACL on the Switch enables users to inspect any offset chunk. An offset chunk is a 4-byte block in a
HEX format, which is utilized to match the individual field in an Ethernet frame. Each profile is allowed to contain up to a
maximum of four offset chunks. Furthermore, only one single profile of Packet Content ACL can be supported per switch. In
other words, up to 16 bytes of total offset chunks can be applied to each profile and a switch. Therefore, a careful consideration is
needed for planning and configuration of the valuable offset chunks.
In Table-6, you will notice that the Offset_Chunk0 starts from the 127
the offset chunk is scratched from 1 but not zero.
Table-6: Chunk and packet offset
Offset
Offset
Offset
Offset
Chunk
Chunk0
Chunk1
Chunk2
Byte
127
3
7
Byte
128
4
8
Byte
1
5
9
Byte
2
6
10
Offset
Offset
Offset
Offset
Chunk
Chunk15
Chunk16
Chunk17
Byte
63
67
71
Byte
64
68
72
Byte
65
69
73
Byte
66
70
74
The following table indicates a completed ARP packet contained in Ethernet frame which is the pattern for the calculation of
packet offset.
Table-7: A completed ARP packet contained in Ethernet frame
Ethernet Header
Destination
Source address
address
(6-byte)
(6-byte)
01 02 03 04 05 06
DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch
Offset
Offset
Offset
Offset
Chunk3
Chunk4
Chunk5
Chunk6
11
15
19
12
16
20
13
17
21
14
18
22
Offset
Offset
Offset
Offset
Chunk18
Chunk19
Chunk20
Chunk21
75
79
83
76
80
84
77
81
85
78
82
86
Ethernet
H/W type Protocol
type
type
(2-byte)
(2-byte)
(2-byte)
0806
th
byte and ends at the 128
Offset
Offset
Offset
Chunk7
Chunk8
Chunk9
23
27
31
35
24
28
32
36
25
29
33
37
26
30
34
38
Offset
Offset
Offset
Chunk22
Chunk23
Chunk24
87
91
95
99
88
92
96
100
89
93
97
101
90
94
98
102
H/W
Protocol
Operation
address
address
length
length
(1-byte)
(1-byte)
(2-byte)
234
th
byte. It also can be found that
Offset
Offset
Offset
Chunk10
Chunk11
Chunk12
39
43
47
40
44
48
41
45
49
42
46
50
Offset
Offset
Offset
Chunk25
Chunk26
Chunk27
103
107
111
104
108
112
105
109
113
106
110
114
ARP
Sender
Sender
protocol
H/W
address
address
(6-byte)
(4-byte)
0a5a5a5a
(10.90.90.90)
Offset
Offset
Offset
Chunk13
Chunk14
Chunk15
51
55
59
52
56
60
53
57
61
54
58
62
Offset
Offset
Offset
Chunk28
Chunk129
Chunk30
115
119
123
116
120
124
117
121
125
118
122
126
Target
Target
H/W
protocol
address
address
(6-byte)
(4-byte)

Advertisement

Table of Contents
loading

Table of Contents