682 IPv6 Access Control List Commands
[icmp-type
icmp-
type
[
icmp-code
icmp-code
] |
icmp-message
icmp-message
]
This option is available only if the protocol is
icmpv6.
Specifies a match condition for ICMP packets.
When icmp-type is specified, IPv6 ACL rule
matches on the specified ICMP message type, a
number from 0 to 255.
When icmp-code is specified, IPv6 ACL rule
matches on the specified ICMP message code, a
number from 0 to 255.
Specifying icmp-message implies both icmp-type
and icmp-code are specified. The following icmp-
messages are supported:
destination-
unreachable, echo-reply, echo-request,
header, hop-limit, mld-query, mld-
reduction, mld-report, nd-na, nd-ns, next-
header, no-admin, no-route, packet-too-
big
, port-unreachable, router-
solicitation, router-advertisement,
router-renumbering, time-exceeded, and
unreachable.
The ICMP message is decoded into the
corresponding ICMP type and ICMP code within
that ICMP type.
Fragments
Specifies that IPv6 ACL rule matches on fragmented
IPv6 packets (Packets that have the next header field
is set to 44).
Routing
Specifies that IPv6 ACL rule matches on IPv6
packets that have routing extension headers (the next
header field is set to 43).
Log
Specifies that this rule is to be logged.
Parameter Description