1-17
To do…
Use the command…
Remarks
Enter system view
system-view
—
Configure the
capacity and
update interval of
the token bucket
Ipv6 icmp-error
{
bucket
bucket-size
| ratelimit
interval
} *
Optional
By default, the capacity of a token bucket is 10
and the update interval is 100 milliseconds. That
is, at most 10 IPv6 ICMP error packets can be
sent within 100 milliseconds.
The update interval “0” indicates that the number
of ICMPv6 error packets sent is not restricted.
Enable Sending of Multicast Echo Replies
If hosts are capable of answering multicast echo requests, Host A can attack Host B by sending an echo
request with the source being Host B to a multicast address, then all the hosts in the multicast group will
send echo replies to Host B. Therefore, to prevent such an attack, a device is disabled from replying
multicast echo requests by default.
Follow these steps to enable sending of multicast echo replies:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable sending of multicast
echo replies
ipv6 icmpv6
multicast-echo-reply enable
Not enabled by default.
Enabling Sending of ICMPv6 Time Exceeded Packets
A device sends an ICMPv6 time exceeded packet in the following cases.
z
If a received IPv6 packet’s destination IP address is not the local address and its hop count is 1, the
device sends an ICMPv6 time-to-live count exceeded packet to the source.
z
Upon receiving the first fragment of an IPv6 datagram with the destination IP address being the
local address, the device starts a timer. If the timer expires before all the fragments arrive, an
ICMPv6 fragment reassembly time exceeded packet is sent to the source.
If large amounts of malicious packets are received, the performance of a device degrades greatly
because it has to send back ICMP time exceeded packets. You can disable sending of ICMPv6
time-to-live count exceeded packets.
Follow these steps to enable sending of ICMPv6 time exceeded packets:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable sending of ICMPv6 time
exceeded packets
ipv6 hoplimit-expires enable
Optional
Enabled by default.
Содержание S5500-SI Series
Страница 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Страница 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Страница 250: ...3 3 SwitchB system view SwitchB interface vlan interface 1 SwitchB Vlan interface1 ip address dhcp alloc...
Страница 310: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1...
Страница 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Страница 493: ...2 8...
Страница 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...