Juniper ACX1000 Configuration Manual page 1117

Junos os; acx series universal access router
Hide thumbs Also See for ACX1000:
Table of Contents

Advertisement

Table 74: Firewall Filter Match Conditions for IPv6 Traffic (continued)
Match Condition
icmp-code message-code
icmp-type message-type
Copyright © 2017, Juniper Networks, Inc.
Description
Match the ICMP message code field.
If you configure this match condition, we recommend that you also configure the
or
match condition in the same term.
icmp
next-header icmp6
If you configure this match condition, you must also configure the
condition in the same term. An ICMP message code provides more specific information than an
ICMP message type, but the meaning of an ICMP message code is dependent on the associated
ICMP message type.
In place of the numeric value, you can specify one of the following text synonyms (the field values
are also listed). The keywords are grouped by the ICMP type with which they are associated:
parameter-problem:
ip6-header-bad
(2)
time-exceeded:
ttl-eq-zero-during-reassembly
destination-unreachable:
administratively-prohibited
(0),
no-route-to-destination
Match the ICMP message type field.
If you configure this match condition, we recommend that you also configure the
or
match condition in the same term.
icmp
next-header icmp6
In place of the numeric value, you can specify one of the following text synonyms (the field values
are also listed):
certificate-path-advertisement
(1),
destination-unreachable
echo-reply
home-agent-address-discovery-reply
inverse-neighbor-discovery-advertisement
membership-query
(130),
membership-report
mobile-prefix-advertisement-reply
(136),
neighbor-advertisement
(139),
node-information-request
(100),
private-experimentation-100
(200),
private-experimentation-201
(138),
router-renumbering
router-solicit
For
private-experimentation-201
brackets.
(0),
unrecognized-next-header
(1),
ttl-eq-zero-during-transit
(1),
address-unreachable
(4)
port-unreachable
(149),
certificate-path-solicitation
(129),
(128),
echo-request
(145),
home-agent-address-discovery-request
(142),
inverse-neighbor-discovery-solicitation
(131),
membership-termination
(147),
mobile-prefix-solicitation
(135),
neighbor-solicit
node-information-reply
(2),
packet-too-big
parameter-problem
private-experimentation-101
(201),
(137),
redirect
router-advertisement
(133), or
time-exceeded
(201), you can also specify a range of values within square
Chapter 32: Configuring Firewall Filters
next-header
icmp-type message-type
match
(1),
unrecognized-option
(0)
(3),
next-header
(148),
(144),
(141),
(132),
(146),
(140),
(4),
(101),
private-experimentation-200
(134),
(3).
1059

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Acx5048Acx5096Acx500Acx1100Acx2000Acx2100 ... Show all

Table of Contents