Security
7950 SR OS System Management Guide
Page 179
Description
This command specifies fragmented or non-fragmented IP packets as an IP filter match criterion.
Note that an entry containing Layer 4 match criteria will not match non-initial (2nd, 3rd, etc)
fragments of a fragmented packet since only the first fragment contains the Layer 4 information.
This command enables match on existence of IPv6 Fragmentation Extension Header in the IPv6 filter
policy. To match first fragment of an IP fragmented packet, specify additional Layer 4 matching
criteria in a filter policy entry. The no version of this command ignores IPv6 Fragmentation Extension
Header presence/absence in a packet when evaluating match criteria of a given filter policy entry.
The
no
form of the command removes the match criterion.
This command enables match on existence of IPv6 Fragmentation Extension Header in the IPv6 filter
policy. To match first fragment of an IP fragmented packet, specify additional Layer 4 matching
criteria in a filter policy entry. The no version of this command ignores IPv6 Fragmentation Extension
Header presence/absence in a packet when evaluating match criteria of a given filter policy entry.
Default
no fragment
Parameters
true —
Specifies to match on all fragmented IP packets. A match will occur for all packets that have
either the MF (more fragment) bit set or have the Fragment Offset field of the IP header set to a
non-zero value. For IPv6, packet matches if it contains IPv6 Fragmentation Extension Header.
false —
Specifies to match
on all non-fragmented IP packets. Non-fragmented IP packets are packets
that have the MF bit set to zero and have the Fragment Offset field also set to zero. For IPv6,
packet matches if it does not contain IPv6 Fragmentation Extension Header.
hop-by-hop-opt
Syntax
hop-by-hop-opt
{
true
|
false
}
no hop-by-hop-opt
Context
config>sys>sec>cpm>ipv6-filter>entry
>
match
Description
This command enables match on existence of Hop-by-Hop Options Extension Header in the IPv6 fil-
ter policy.
The
no
form of this command ignores Hop-by-Hop Options Extension Header presence/absence in a
packet when evaluating match criteria of a given filter policy entry.
Default
no hop-by-hop-opt
Parameters
true —
Match if a packet contains Hop-by-Hop Options Extension Header.
false —
Match if a packet does not contain Hop-by-Hop Options Extension Header.
Summary of Contents for 7950 SR
Page 10: ...Page 10 7950 SR OS System Management Guide List of Figures...
Page 14: ...About This Guide Page 14 7950 SR OS System Management Guide...
Page 16: ...Alcatel Lucent 7950 SR Router Configuration Process Page 16 7950 SR OS System Management Guide...
Page 56: ...Configuration Notes Page 56 7950 SR OS System Management Guide...
Page 88: ...Configuring Login Controls Page 88 7950 SR OS System Management Guide...
Page 106: ...Security Command Reference Page 106 7950 SR OS System Management Guide...
Page 206: ...Distributed CPU Protection Commands Page 206 7950 SR OS System Management Guide...
Page 244: ...Debug Commands Page 244 7950 SR OS System Management Guide...
Page 254: ...Configuration Notes Page 254 7950 SR OS System Management Guide...
Page 276: ...SNMP Security Commands Page 276 7950 SR OS System Management Guide...
Page 296: ...Show Commands Page 296 7950 SR OS System Management Guide...
Page 322: ...Configuration Notes Page 322 7950 SR OS System Management Guide...
Page 358: ...Log Management Tasks Page 358 7950 SR OS System Management Guide...
Page 454: ...Facility Alarm List Page 454 7950 SR OS System Management Guide...
Page 460: ...Standards and Protocols Page 460 Standards and Protocols...