HP 6125XLG R2306-HP 6125XLG Blade Switch ACL and QoS Command Reference - Page 26

Parameters, Function, Description, ICMP message name, If the, argument is, set the parameters shown

Page 26 highlights

Parameters Function { ack ack-value | fin fin-value | psh psh-value | rst rst-value | syn syn-value | urg urg-value } * Specifies one or more TCP flags including ACK, FIN, PSH, RST, SYN, and URG. established Specifies the flags for indicating the established status of a TCP connection. Description Parameters specific to TCP. The value for each argument can be 0 (flag bit not set) or 1 (flag bit set). The TCP flags in a rule are ANDed. For example, a rule configured with ack 0 psh 1 matches packets that have the ACK flag bit not set and the PSH flag bit set. Parameter specific to TCP. The rule matches TCP connection packets with the ACK or RST flag bit set. If the protocol argument is icmp (1), set the parameters shown in Table 9. Table 9 ICMP-specific parameters for IPv4 advanced ACL rules Parameters Function icmp-type { icmp-type Specifies the ICMP icmp-code | message type and icmp-message } code. Description The icmp-type argument is in the range of 0 to 255. The icmp-code argument is in the range of 0 to 255. The icmp-message argument specifies a message name. Supported ICMP message names and their corresponding type and code values are listed in Table 10. Table 10 ICMP message names supported in IPv4 advanced ACL rules ICMP message name echo echo-reply fragmentneed-DFset host-redirect host-tos-redirect host-unreachable information-reply information-request net-redirect net-tos-redirect net-unreachable parameter-problem port-unreachable protocol-unreachable reassembly-timeout source-quench ICMP message type 8 0 3 5 5 3 16 15 5 5 3 12 3 3 11 4 ICMP message code 0 0 4 1 3 1 0 0 0 2 0 0 3 2 1 0 21

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114

21
Parameters
Function
Description
{
ack
ack-value
|
fin
fin-value
|
psh
psh-value
|
rst
rst-value
|
syn
syn-value
|
urg
urg-value
}
*
Specifies one or
more TCP flags
including ACK,
FIN, PSH, RST,
SYN, and URG.
Parameters specific to TCP.
The value for each argument can be 0 (flag bit not set) or 1 (flag bit
set).
The TCP flags in a rule are ANDed. For example, a rule configured
with
ack
0
psh
1 matches packets that have the ACK flag bit not set
and the PSH flag bit set.
established
Specifies the flags
for indicating the
established status
of a TCP
connection.
Parameter specific to TCP.
The rule matches TCP connection packets with the ACK or RST flag bit
set.
If the
protocol
argument is
icmp
(1), set the parameters shown in
Table 9
.
Table 9
ICMP-specific parameters for IPv4 advanced ACL rules
Parameters
Function
Description
icmp-type
{
icmp-type
icmp-code
|
icmp-message
}
Specifies the ICMP
message type and
code.
The
icmp-type
argument is in the range of 0 to 255.
The
icmp-code
argument is in the range of 0 to 255.
The
icmp-message
argument specifies a message name.
Supported ICMP message names and their corresponding
type and code values are listed in
Table 10
.
Table 10
ICMP message names supported in IPv4 advanced ACL rules
ICMP message name
ICMP message type
ICMP message code
echo
8
0
echo-reply
0
0
fragmentneed-DFset
3
4
host-redirect
5
1
host-tos-redirect
5
3
host-unreachable
3
1
information-reply
16
0
information-request
15
0
net-redirect
5
0
net-tos-redirect
5
2
net-unreachable
3
0
parameter-problem
12
0
port-unreachable
3
3
protocol-unreachable
3
2
reassembly-timeout
11
1
source-quench
4
0