Programmable Internetworking & Communication Operating System Docs ... Click Spaces -> Space Directory to see docs for all releases ...
Page tree
Skip to end of metadata
Go to start of metadata

To configure a filter sequence to trust DSCP or IP Precendence in the packet header, use the set firewall filter sequence from ip trust-mode command in L2/L3 coniguration mode. To prevent a filter sequence from trusting DSCP or IP Precendence, use the delete form of the command.

Command Syntax

set firewall filter filter-name sequence number from ip trust-mode { dscp | inet-precendence }
delete firewall filter filter-name sequence number from ip trust-mode

Parameters

filter-nameFilter name.
numberFilter sequence number. The range is 0-9999.
dscpSet the trust mode of the filter sequence to DSCP (differentiated services code point).
inet-precendenceSet the trust mode of the filter sequence to IP Precedence.

Examples

The following example configures sequence 2 of the MyFilter filter to trust DSCP value in the packet header:

admin@Switch# set firewall filter MyFilter sequence 2 from ip trust-mode dscp

The following example removes the DSCP value from sequence 2 of the MyFilter filter:

admin@XorPlus# delete firewall filter MyFilter sequence 2 from ip trust-mode
Deleting: 
>   trust-mode: "dscp"
OK 
  • No labels