EasyManua.ls Logo

Alcatel-Lucent 7450 - Page 471

Alcatel-Lucent 7450
778 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Filter Policies
Router Configuration Guide 471
packet-length/payload-length — Match for the specified length value/range against
the Total Length field in IPv4 packet header or Payload Length field in IPv6 packet
header. (The IPv6 payload-length field does not account for the size of the fixed IP
header, which is 40 bytes.) This match condition is supported for drop action only
and is part of action evaluation – i.e. after packet is determined to match the entry
based on other match criteria configured. Packets that match all match criteria for a
given filter policy entry are dropped if the packet-length match criterion is met and
forwarded if the packet match criterion is not met. When a filter entry with a packet-
length condition is used as a mirror source, only forwarded packets are mirrored.
Supported for ingress filters only. Requires minimum FP-2-based line cards. The
packet-length match condition is always true if a filter is configured on egress or on
an older hardware.
ttl — Match for the specified TTL value/range against the Total Length field in IPv4
packet header. This match condition is supported for drop action only and is part of
action evaluation – i.e. after packet is determined to match the entry based on other
match criteria configured. Packets that match all match criteria for a given filter
policy entry are dropped if the TTL match criterion is met and forwarded if the TTL
match criterion is not met. When a filter entry with a TTL condition is used as a
mirror source, only forwarded packets are mirrored. When a filter entry with a TTL
condition is used in cflowd processing, the TTL condition is ignored for cflowd
processing. Supported for ingress filters only. Requires minimum FP-2-based line
cards. The TTL match condition is always true if a filter is configured on egress or
on an older hardware.
Fragmentation match criteria:
fragment — Enable fragmentation support in filter policy match. For IPv4, match
against MF bit or Fragment Offset field to determine whether the packet is a fragment
or not. For IPv6 for the 7750 SR and 7950 XRS, match against Next Header Field for
Fragment Extension Header value to determine whether the packet is a fragment or
not. Up to 6 extension headers are matched against to find Fragmentation Extension
Header. Supported on FP-2-based line cards.
Additionally, match against whether the fragment is an initial fragment or non-initial
fragment is also supported for IPv6 filters.
IPv4 match fragment criteria are supported on both ingress and egress. IPv6 match
fragment criteria are supported on ingress only and require minimum FP-2-based line
cards.
IPv4 options match criteria:
ip-option — Match for the specified option value in the first option of the IPv4
packet. Operator can optionally configure a mask to be used in a match.
option-present — Match for the presence or absence of IP options in the IPv4
packet. Padding and EOOL are also considered as IP options. Up to 6 IP options are
matched against.

Table of Contents

Other manuals for Alcatel-Lucent 7450

Related product manuals