HP 6125G HP 6125G & 6125G/XG Blade Switches Layer 3 - IP Services Conf - Page 106

Enabling sending of ICMPv6 destination unreachable messages

Page 106 highlights

Enabling sending of ICMPv6 destination unreachable messages If the device fails to forward a received IPv6 packet because of one of the following reasons, it drops the packet and sends a corresponding ICMPv6 Destination Unreachable error message to the source. • If no route is available for forwarding the packet, the device sends a "no route to destination" ICMPv6 error message to the source. • If the device fails to forward the packet because of an administrative prohibition (such as a firewall filter or an ACL), the device sends the source a "destination network administratively prohibited" ICMPv6 error message. • If the device fails to deliver the packet because the destination is beyond the scope of the source IPv6 address (for example, the source IPv6 address of the packet is a link-local address whereas the destination IPv6 address of the packet is a global unicast address), the device sends the source a "beyond scope of source address" ICMPv6 error message. • If the device fails to resolve the corresponding link layer address of the destination IPv6 address, the device sends the source an "address unreachable" ICMPv6 error message. • If the packet with the destination being local and transport layer protocol being UDP and the packet's destination port number does not match the running process, the device sends the source a "port unreachable" ICMPv6 error message. If an attacker sends abnormal traffic that causes the device to generate ICMPv6 destination unreachable messages, end users may be affected. To prevent such attacks, you can disable the device from sending ICMPv6 destination unreachable messages. To enable sending of ICMPv6 destination unreachable messages: Step Command 1. Enter system view. system-view 2. Enable sending of ICMPv6 destination unreachable messages. ipv6 unreachables enable Remarks N/A Disabled by default Displaying and maintaining IPv6 basics configuration Task Display the IPv6 FIB entries. Display the IPv6 FIB entry of a specified destination IPv6 address. Display the IPv6 information of the interface. Command Remarks display ipv6 fib [ acl6 acl6-number | ipv6-prefix ipv6-prefix-name ] [ | { begin | exclude | include } Available in any view regular-expression ] display ipv6 fib ipv6-address [ prefix-length ] [ | { begin | exclude | include } regular-expression ] Available in any view display ipv6 interface [ interface-type [ interface-number ] ] [ brief ] [ | { begin | exclude Available in any view | include } regular-expression ] 98

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165

98
Enabling sending of ICMPv6 destination unreachable
messages
If the device fails to forward a received IPv6 packet because of one of the following reasons, it drops the
packet and sends a corresponding ICMPv6 Destination Unreachable error message to the source.
If no route is available for forwarding the packet, the device sends a "no route to destination"
ICMPv6 error message to the source.
If the device fails to forward the packet because of an administrative prohibition (such as a firewall
filter or an ACL), the device sends the source a "destination network administratively prohibited"
ICMPv6 error message.
If the device fails to deliver the packet because the destination is beyond the scope of the source
IPv6 address (for example, the source IPv6 address of the packet is a link-local address whereas the
destination IPv6 address of the packet is a global unicast address), the device sends the source a
"beyond scope of source address" ICMPv6 error message.
If the device fails to resolve the corresponding link layer address of the destination IPv6 address, the
device sends the source an "address unreachable" ICMPv6 error message.
If the packet with the destination being local and transport layer protocol being UDP and the
packet's destination port number does not match the running process, the device sends the source
a "port unreachable" ICMPv6 error message.
If an attacker sends abnormal traffic that causes the device to generate ICMPv6 destination unreachable
messages, end users may be affected. To prevent such attacks, you can disable the device from sending
ICMPv6 destination unreachable messages.
To enable sending of ICMPv6 destination unreachable messages:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable sending of ICMPv6 destination
unreachable messages.
ipv6 unreachables enable
Disabled by default
Displaying and maintaining IPv6 basics
configuration
Task
Command
Remarks
Display the IPv6 FIB entries.
display ipv6 fib
[
acl6
acl6-number
|
ipv6-prefix
ipv6-prefix-name
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the IPv6 FIB entry of a
specified destination IPv6
address.
display
ipv6 fib
ipv6-address
[
prefix-length
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the IPv6 information of
the interface.
display ipv6 interface
[
interface-type
[
interface-number
] ] [
brief
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view