Security Command Reference
86 7705 SAR OS System Management Guide
next-header
Syntax [no] next-header next-header
Context config>system>security>management-access-filter>ipv6-filter>entry
Description This command specifies the next header to match as a management access filter match criterion.
This command applies to IPv6 filters only.
Parameters next-header — the IPv6 next header to match. This parameter is similar to the protocol parameter
used in IPv4 filter match criteria.
Values [1 to 42 | 45 to 49 | 52 to 59 | 61 to 255] — (values can be expressed
in decimal, hexadecimal, or binary – DHB)
keywords: none, crtp, crudp, egp, eigrp, encap, ether-ip, gre, icmp,
idrp, igmp, igp, ip, ipv6, ipv6-frag, ipv6-icmp, ipv6-no-nxt, isis,
iso-ip, l2tp, ospf-igp, pim, pnni, ptp, rdp, rsvp, stp, tcp, udp, vrrp
* — udp/tcp wildcard
protocol
Syntax [no] protocol protocol-id
Context config>system>security>management-access-filter>ip-filter>entry
Description This command configures an IP protocol type to be used as a management access filter match criterion.
The protocol type is identified by its respective protocol number. Well-known protocol numbers
include ICMP (1), TCP (6), and UDP (17).
This command applies to IPv4 filters only.
The no form of the command removes the protocol from the match criteria.
Default n/a
Parameters protocol-id — the protocol number for the match criterion
Values 1 to 255 (decimal)