Aspf Icmp-Error Reply; Aspf Policy - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

[Sysname-zone-pair-security-Trust-Untrust] aspf apply policy 1
Related commands

aspf policy

display aspf all
zone-pair security (Fundamentals Command Reference)

aspf icmp-error reply

Use aspf icmp-error reply to enable the device to send ICMP error messages for packet dropping
by security policies applied to zone pairs.
Use undo aspf icmp-error reply to restore the default.
Syntax
aspf icmp-error reply
undo aspf icmp-error reply
Default
The device does not send ICMP error messages when the device drops packets that do not match
security policies applied to zone pairs.
Views
System view
Predefined user roles
network-admin
Usage guidelines
Typically, to reduce useless packets transmitted over the network and save bandwidth, do not use
this command.
However, you must use this command when you use traceroute, for ICMP error messages in this
situation are required.
Examples
# Enable ICMP error message sending for packet dropping by security policies applied to zone pairs.
<Sysname> system-view
[Sysname] aspf icmp-error reply
aspf policy
Use aspf policy to create an ASPF policy and enter its view, or enter the view of an existing ASPF
policy.
Use undo aspf policy to remove an ASPF policy.
Syntax
aspf policy aspf-policy-number
undo aspf policy aspf-policy-number
Default
No ASPF policies exist.
810

Advertisement

Table of Contents
loading

Table of Contents