Enable Sending Of Multicast Echo Replies; Enabling Sending Of Icmpv6 Time Exceeded Packets - HP 4800G Series Configuration Manual

24/48 port
Table of Contents

Advertisement

successively sent exceeds the capacity of the token bucket, the additional ICMPv6 error packets cannot
be sent out until the capacity of the token bucket is restored.
Follow these steps to configure the capacity and update interval of the token bucket:
To do...
Enter system view
Configure the
capacity and update
interval of the token
bucket

Enable Sending of Multicast Echo Replies

If hosts are capable of answering multicast echo requests, Host A can attack Host B by sending an echo
request with the source being Host B to a multicast address, then all the hosts in the multicast group will
send echo replies to Host B. Therefore, to prevent such an attack, a device is disabled from replying
multicast echo requests by default.
Follow these steps to enable sending of multicast echo replies:
To do...
Enter system view
Enable sending of multicast
echo replies

Enabling Sending of ICMPv6 Time Exceeded Packets

A device sends an ICMPv6 time exceeded packet in the following cases.
If a received IPv6 packet's destination IP address is not the local address and its hop count is 1, the
device sends an ICMPv6 time-to-live count exceeded packet to the source.
Upon receiving the first fragment of an IPv6 datagram with the destination IP address being the
local address, the device starts a timer. If the timer expires before all the fragments arrive, an
ICMPv6 fragment reassembly time exceeded packet is sent to the source.
If large amounts of malicious packets are received, the performance of a device degrades greatly
because it has to send back ICMP time exceeded packets. You can disable sending of ICMPv6
time-to-live count exceeded packets.
Follow these steps to enable sending of ICMPv6 time exceeded packets:
To do...
Enter system view
Enable sending of ICMPv6 time
exceeded packets
Use the command...
system-view
Ipv6 icmp-error { bucket
bucket-size | ratelimit
interval } *
Use the command...
system-view
ipv6 icmpv6
multicast-echo-reply enable
Use the command...
system-view
ipv6 hoplimit-expires enable
1-17
Remarks
Optional
By default, the capacity of a token bucket is 10
and the update interval is 100 milliseconds.
That is, at most 10 IPv6 ICMP error packets
can be sent within 100 milliseconds.
The update interval "0" indicates that the
number of ICMPv6 error packets sent is not
restricted.
Not enabled by default.
Optional
Enabled by default.
Remarks
Remarks

Advertisement

Chapters

Table of Contents
loading

Table of Contents