Operation Manual - Security Defence
H3C SecPath F1800-A Firewall
II. Type of Packet Matched with ICMP Protocol
Advanced ACL can also match ICMP packets based on the message type and
message code in the ICMP packet header. For instance, the message type for ICMP
packet of "destination addresses is unreachable" is 3. If the further message for the
packet is "unreachable network", then the message code is 0. If the message is
"unreachable host", the message code is 1.
The type of ICMP packets and message code can be specified in number (from 0 to
255) or mnemonic symbol.
The mnemonic symbols are shown in
Table 1-3 Mnemonic symbol for ICMP packet type
Mnemonic symbol
echo
echo-reply
fragmentneed-DFset
host-redirect
host-tos-redirect
host-unreachable
information-reply
information-request
net-redirect
net-tos-redirect
net-unreachable
parameter-problem
port-unreachable
protocol-unreachable
reassembly-timeout
source-quench
source-route-failed
timestamp-reply
timestamp-request
ttl-exceeded
Table
1-3.
Type=8, Code=0
Type=0, Code=0
Type=3, Code=4
Type=5, Code=1
Type=5, Code=3
Type=3, Code=1
Type=16,Code=0
Type=15,Code=0
Type=5, Code=0
Type=5, Code=2
Type=3, Code=0
Type=12,Code=0
Type=3, Code=3
Type=3, Code=2
Type=11, Code=1
Type=4, Code=0
Type=3, Code=5
Type=14, Code=0
Type=13, Code=0
Type=11, Code=0
6-10
Chapter 1 ACL
Meaning
Need help?
Do you have a question about the H3C SecPath F1800-A and is the answer not in the manual?