659
aspf icmp-error reply
Use
aspf icmp-error reply
to enable the device to send ICMP error messages for packet dropping
by security policies applied to zone pairs.
Use
undo aspf icmp-error reply
to restore the default.
Syntax
aspf icmp-error reply
undo aspf icmp-error reply
Default
The device does not send ICMP error messages when the device drops packets that do not match
security policies applied to zone pairs.
Views
System view
Predefined user roles
network-admin
Usage guidelines
Typically, to reduce useless packets transmitted over the network and save bandwidth, do not use
this command.
However, you must use this command when you use traceroute, for ICMP error messages in this
situaiton are required.
Examples
# Enable ICMP error message sending for packet dropping by security policies applied to zone pairs.
<Sysname> system-view
[Sysname] aspf icmp-error reply
aspf policy
Use
aspf policy
to create an ASPF policy and enter its view, or enter the view of an existing ASPF
policy.
Use
undo aspf policy
to remove an ASPF policy.
Syntax
aspf policy
aspf-policy-number
undo aspf policy
aspf-policy-number
Default
No ASPF policies exist.
Views
System view
Predefined user roles
network-admin
Parameters
aspf-policy-number
: Assigns a number to the ASPF policy. The value range for this argument is 1 to
256.
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...