660 IP Access Control List Commands
[icmp-type
icmp-type
[icmp-code
icmp-
code
] | icmp-message
icmp-message
]
This option is available only if the protocol is
icmp.
Specifies a match condition for ICMP packets.
When
icmp-type is specified, the IP ACL rule
matches on the specified ICMP message type, a
number from 0 to 255.
When
icmp-code is specified, the IP ACL rule
matches on the specified ICMP message code, a
number from 0 to 255.
Specifying
icmp-message implies that both
icmp-type and icmp-code are specified. The
following icmp-messages are supported:
echo,
echo-reply, host-redirect, mobile-
redirect
, net-redirect, net-
unreachable, redirect, packet-too-big,
port-unreachable, source-quench,
router-solicitation, router-
advertisement, time-exceeded, ttl-
exceeded and unreachable.
igmp-type
igmp-type
This option is available only if the protocol is
igmp.
When igmp-type is specified, the IP ACL rule
matches on the specified IGMP message type, a
number from 0 to 255.
fragments
Specifies that the IP ACL rule matches on
fragmented IP packets.
[log]
Specifies that this rule is to be logged.
Parameter Description