HP 6125XLG R2306-HP 6125XLG Blade Switch ACL and QoS Command Reference - Page 33

Usage guidelines, Table 15, ICMPv6 message names supported in IPv6 advanced ACL rules

Page 33 highlights

Table 15 ICMPv6 message names supported in IPv6 advanced ACL rules ICMPv6 message name echo-reply echo-request err-Header-field frag-time-exceeded hop-limit-exceeded host-admin-prohib host-unreachable neighbor-advertisement neighbor-solicitation network-unreachable packet-too-big port-unreachable redirect router-advertisement router-solicitation unknown-ipv6-opt unknown-next-hdr ICMPv6 message type 129 128 4 3 3 1 1 136 135 1 2 1 137 134 133 4 4 ICMPv6 message code 0 0 0 1 0 1 3 0 0 0 0 4 0 0 0 2 1 Usage guidelines If an ACL is for QoS traffic classification: • Do not specify the vpn-instance or fragment keyword. • Do not specify neq for the operator argument. • Do not specify the routing, hop-by-hop, or flow-label keyword, nor set the protocol argument to 0, 43, 44, 51, or 60, if the ACL is for outbound QoS traffic classification. If an ACL is for packet filtering: • Do not specify the vpn-instance, routing, hop-by-hop, fragment, or flow-label keyword. • Do not specify neq for the operator argument. • Do not set the protocol argument to 0, 43, 44, 51, or 60. If an ACL is to match information in the IPv6 packet payload, it cannot match the packet with more than two extension headers or with the Encapsulating Security Payload Header. Within an ACL, the permit or deny statement of each rule must be unique. If the ACL rule you are creating or editing has the same deny or permit statement as another rule in the ACL, your creation or editing attempt fails. You can edit ACL rules only when the match order is config. If no optional keywords are provided in the undo rule command, you delete the entire rule. If optional keywords or arguments are provided, you delete the specified attributes. To view rules in an ACL and their rule IDs, use the display acl ipv6 all command. 28

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114

28
Table 15
ICMPv6 message names supported in IPv6 advanced ACL rules
ICMPv6 message name
ICMPv6 message type
ICMPv6 message code
echo-reply
129
0
echo-request
128
0
err-Header-field
4
0
frag-time-exceeded
3
1
hop-limit-exceeded
3
0
host-admin-prohib
1
1
host-unreachable
1
3
neighbor-advertisement
136
0
neighbor-solicitation
135
0
network-unreachable
1
0
packet-too-big
2
0
port-unreachable
1
4
redirect
137
0
router-advertisement
134
0
router-solicitation
133
0
unknown-ipv6-opt
4
2
unknown-next-hdr
4
1
Usage guidelines
If an ACL is for QoS traffic classification:
Do not specify the
vpn-instance
or
fragment
keyword.
Do not specify
neq
for the
operator
argument.
Do not specify the
routing
,
hop-by-hop
, or
flow-label
keyword, nor set the
protocol
argument to 0,
43, 44, 51, or 60, if the ACL is for outbound QoS traffic classification.
If an ACL is for packet filtering:
Do not specify the
vpn-instance
,
routing
,
hop-by-hop
,
fragment
, or
flow-label
keyword.
Do not specify
neq
for the
operator
argument.
Do not set the
protocol
argument to 0, 43, 44, 51, or 60.
If an ACL is to match information in the IPv6 packet payload, it cannot match the packet with more than
two extension headers or with the Encapsulating Security Payload Header.
Within an ACL, the permit or deny statement of each rule must be unique. If the ACL rule you are creating
or editing has the same deny or permit statement as another rule in the ACL, your creation or editing
attempt fails.
You can edit ACL rules only when the match order is config.
If no optional keywords are provided in the
undo rule
command, you delete the entire rule. If optional
keywords or arguments are provided, you delete the specified attributes.
To view rules in an ACL and their rule IDs, use the
display acl ipv6 all
command.