Users Guide

Table Of Contents
Syntax
deny icmp {source address mask | any | host ipv6-address} {destination
address | any | host ipv6-address} [type] [message-type] [ttl operator]
[count [byte]] | [log [interval minutes] [threshold-in-msgs [count]]
[monitor]
To remove this filter, you have two choices:
Use the no seq sequence-number command syntax if you know the filters sequence number
Use the no deny icmp {source address mask | any | host ipv6-address}
{destination address | any | host ipv6-address} command
Parameters
source address
mask
Enter a network mask in /prefix format (/x) or A.B.C.D. The mask, when specified
in A.B.C.D format, may be either contiguous or non-contiguous.
any Enter the keyword any to specify that all routes are subject to the filter.
host
ip-
v6address
Enter the keyword host then the IPv6 address to specify a host IP address.
destination
Enter the IP address of the network or host to which the packets are sent.
type
Enter the ICMP packet type. The following types are available:
For IPv4:
echo count
echo-reply count
host-unreachable count
host-unknown count
network-unknown count
net-unreachable count
packet-too-big count
parameter-problem count
port-unreachable count
source-quench count
time-exceeded count
For IPv6:
echo count
echo-reply count
nd-ns count
nd-na count
packet-too-big count
parameter-problem count
time-exceeded count
port-unreachable count
The ICMP packets cannot be filtered using mirroring ACL.
ttl
Enter the keyword ttl to deny a packet based on the time to live value. The range
is from 1 to 255.
operator
Enter one of the following logical operand:
eq(equal to) matches packets that contain a ttl value that is equal to the
specified ttl value.
neq(not equal to) matches packets that contain a ttl value that is not equal
to the specified ttl value.
gt(greater than) matches packets that contain a ttl value that is greater
than the specified ttl value.
lt (less than) matches packets that contain a ttl value that is less than the
specified ttl value.
range(inclusive range of values) matches packets that contain a ttl value
that falls between the specified range of ttl values.
Access Control Lists (ACL) 303