IPv6 Filters
IPv6 packets with extension headers can be filtered with an IPv6 filter, but are subject to some
restrictions:
No alarms, logs, or statistics will be reported in the above cases.
MAC Filters
7705 SAR OS Router Configuration Guide
•
if the packet contains the Hop-by-Hop Options header, slow path extraction will
occur and the packet will be processed by the CSM's CPM filter (if present);
however, the main (fast path) IPv6 filter (service or network filter) will filter packets
with the Hop-by-Hop Options header
•
if the authentication header is present in the packet and the target fields for the filter
are offset by the presence of the authentication header, the filter will not detect the
target header fields and no filter action will occur
•
If a MAC filter policy is created with an entry and entry action specified but the
packet matching criteria is not defined, then all packets processed through this filter
policy entry will pass and take the action specified. There are no default parameters
defined for matching criteria.
•
MAC filters cannot be applied to network interfaces, routable VPRN or IES services.
•
Some of the MAC match criteria fields are exclusive to each other, based on the type
of Ethernet frame. Use
Table 44: MAC Match Criteria Exclusivity Rules
Frame Format
Ethernet – II
802.3
802.3 – snap
Table 44
to determine the exclusivity of fields.
Ethertype
Yes
No
No
Filter Policies
289