27
Table 12
ICMPv6-specific parameters for IPv6 advanced ACL rules
Parameters
Function
Description
icmp6-type
{
icmp6-type
icmp6-code
|
icmp6-message
}
Specifies the ICMPv6 message
type and code
The
icmp6-type
argument ranges from 0 to
255.
The
icmp6-code
argument ranges from 0 to
255.
The
icmp6-message
argument specifies a
message name. Supported ICMP message
names and their corresponding type and code
.
Table 13
ICMPv6 message names supported in IPv6 advanced ACL rules
ICMPv6 message name
ICMPv6 message type
ICMPv6 message code
echo-reply 129
0
echo-request 128
0
err-Header-field 4
0
frag-time-exceeded 3
1
hop-limit-exceeded 3
0
host-admin-prohib 1
1
host-unreachable 1
3
neighbor-advertisement 136
0
neighbor-solicitation 135
0
network-unreachable 1
0
packet-too-big 2
0
port-unreachable 1
4
redirect 137
0
router-advertisement 134
0
router-solicitation 133
0
unknown-ipv6-opt 4
2
unknown-next-hdr 4
1
Description
Use the
rule
command to create or edit an IPv6 advanced ACL rule. You can edit ACL rules only when
the match order is config.
Use the
undo
rule
command to delete an entire IPv6 advanced ACL rule or some attributes in the rule. If
no optional keywords are provided, you delete the entire rule. If optional keywords or arguments are
provided, you delete the specific attributes.
By default, an IPv6 advanced ACL does not contain any rule.
Within an ACL, the permit or deny statement of each rule must be unique. If the ACL rule you are creating
or editing has the same deny or permit statement as another rule in the ACL, your creation or editing
attempt will fail.