Alcatel-Lucent 7450 System Management Manual page 203

Ethernet service switch
Hide thumbs Also See for 7450:
Table of Contents

Advertisement

Context
config>sys>sec>cpm>ip-filter>entry>match
config>sys>sec>cpm>ipv6-filter>entry>match
Description
This command specifies fragmented or non-fragmented IP packets as an IP filter match criterion.
Note that an entry containing Layer 4 match criteria will not match non-initial (2nd, 3rd, etc)
fragments of a fragmented packet since only the first fragment contains the Layer 4 information.
This command enables match on existence of IPv6 Fragmentation Extension Header in the IPv6 filter
policy. To match first fragment of an IP fragmented packet, specify additional Layer 4 matching
criteria in a filter policy entry. The no version of this command ignores IPv6 Fragmentation Extension
Header presence/absence in a packet when evaluating match criteria of a given filter policy entry.
The no form of the command removes the match criterion.
This command enables match on existence of IPv6 Fragmentation Extension Header in the IPv6 filter
policy. To match first fragment of an IP fragmented packet, specify additional Layer 4 matching
criteria in a filter policy entry. The no version of this command ignores IPv6 Fragmentation Extension
Header presence/absence in a packet when evaluating match criteria of a given filter policy entry.
Default
no fragment
Parameters
true — Specifies to match on all fragmented IP packets. A match will occur for all packets that have
false — Specifies to match on all non-fragmented IP packets. Non-fragmented IP packets are packets
icmp-code
Syntax
icmp-code icmp-code
no icmp-code
Context
config>sys>sec>cpm>ip-filter>entry>match
Description
This command configures matching on ICMP code field in the ICMP header of an IP packet as an IP
filter match criterion. Note that an entry containing Layer 4 match criteria will not match non-initial
(2nd, 3rd, etc) fragments of a fragmented packet since only the first fragment contains the Layer 4
information.
The behavior of the icmp-code value is dependent on the configured icmp-type value, thus a config-
uration with only an icmp-code value specified will have no effect. To match on the icmp-code, an
associated icmp-type must also be specified.
The no form of the command removes the criterion from the match entry.
Default
no icmp-code - no match criterion for the ICMP code.
Parameters
icmp-code — Specifies the ICMP code values that must be present to match.
7450 ESS System Mangement Guide
either the MF (more fragment) bit set or have the Fragment Offset field of the IP header set to a
non-zero value. For IPv6, packet matches if it contains IPv6 Fragmentation Extension Header.
that have the MF bit set to zero and have the Fragment Offset field also set to zero. For IPv6,
packet matches if it does not contain IPv6 Fragmentation Extension Header.
Values
0 — 255
Security
Page 203

Advertisement

Table of Contents
loading

Table of Contents