HP 6125XLG R2306-HP 6125XLG Blade Switch Layer 3 - IP Services Configuration G - Page 141

Enabling replying to multicast echo requests, Enabling sending ICMPv6 destination unreachable messages

Page 141 highlights

Enabling replying to multicast echo requests The device does not respond to multicast echo requests by default. In some scenarios, however, you must enable the device to answer multicast echo requests so the source host can obtain needed information. To enable the device to answer multicast echo requests: Step 1. Enter system view. 2. Enable replying to multicast echo requests. Command system-view ipv6 icmpv6 multicast-echo-reply enable Remarks N/A By default, this function is not enabled. Enabling sending ICMPv6 destination unreachable messages The device sends ICMPv6 destination unreachable messages as follows: • If a packet does not match any route, the device sends a No Route to Destination ICMPv6 error message to the source. • If the device fails to forward the packet because of administrative prohibition (such as a firewall filter or an ACL), the device sends the source a Destination Network Administratively Prohibited ICMPv6 error message. • If the device fails to deliver the packet because the destination is beyond the scope of the source IPv6 address (for example, the source IPv6 address is a link-local address whereas the destination IPv6 address is a global unicast address), the device sends the source a Beyond Scope of Source Address ICMPv6 error message. • If the device fails to resolve the link layer address for the destination IPv6 address, the device sends the source an Address Unreachable ICMPv6 error message. • If a UDP packet received is destined for the device but its UDP destination port number does not match any process, the device sends the source a Port Unreachable ICMPv6 error message. If a device is generating ICMPv6 destination unreachable messages abnormally, disable the sending of ICMPv6 destination unreachable messages to prevent attack risks. To enable sending ICMPv6 destination unreachable messages: Step 1. Enter system view. 2. Enable sending ICMPv6 destination unreachable messages. Command system-view ipv6 unreachables enable Remarks N/A By default, this function is disabled. Enabling sending ICMPv6 time exceeded messages The device sends ICMPv6 Time Exceeded messages as follows: • If a received packet is not destined for the device and its hop limit is 1, the device sends an ICMPv6 Hop Limit Exceeded message to the source. 133

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230

133
Enabling replying to multicast echo requests
The device does not respond to multicast echo requests by default. In some scenarios, however, you must
enable the device to answer multicast echo requests so the source host can obtain needed information.
To enable the device to answer multicast echo requests:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable replying to multicast
echo requests.
ipv6 icmpv6 multicast-echo-reply
enable
By default, this function is not
enabled.
Enabling sending ICMPv6 destination unreachable messages
The device sends ICMPv6 destination unreachable messages as follows:
If a packet does not match any route, the device sends a No Route to Destination ICMPv6 error
message to the source.
If the device fails to forward the packet because of administrative prohibition (such as a firewall filter
or an ACL), the device sends the source a Destination Network Administratively Prohibited ICMPv6
error message.
If the device fails to deliver the packet because the destination is beyond the scope of the source
IPv6 address (for example, the source IPv6 address is a link-local address whereas the destination
IPv6 address is a global unicast address), the device sends the source a Beyond Scope of Source
Address ICMPv6 error message.
If the device fails to resolve the link layer address for the destination IPv6 address, the device sends
the source an Address Unreachable ICMPv6 error message.
If a UDP packet received is destined for the device but its UDP destination port number does not
match any process, the device sends the source a Port Unreachable ICMPv6 error message.
If a device is generating ICMPv6 destination unreachable messages abnormally, disable the sending of
ICMPv6 destination unreachable messages to prevent attack risks.
To enable sending ICMPv6 destination unreachable messages:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable sending ICMPv6 destination
unreachable messages.
ipv6 unreachables enable
By default, this function is
disabled.
Enabling sending ICMPv6 time exceeded messages
The device sends ICMPv6 Time Exceeded messages as follows:
If a received packet is not destined for the device and its hop limit is 1, the device sends an ICMPv6
Hop Limit Exceeded message to the source.