User Manual

Table Of Contents
M4300 Intelligent Edge Series Fully Managed Stackable Switches
Manage Switch Security User Manual627
The IPv6 ACL rule matches the specified ICMPv6 message type. Possible
type numbers are in the range from 0 to 255.
If you specify information in the ICMP Code field, the IPv6
ACL rule matches
the specified ICMPv6 message code. Possible values for code can be in the
range from 0 to 255.
If these fields are left empty
, it means any.
- If you select the ICMP Message radio button, select the type of the ICMPv6
message to match with the selected IPv6
ACL rule. Specifying a type of message
implies that both the ICMPv6 type and ICMPv6 code are specified. The ICMPv6
message is decoded into the corresponding ICMPv6 type and ICMPv6 code
within the ICMP type.
The ICMPv6 message types are: destination-unreachable, echo-reply,
echo-request, header
, hop-limit, mld-query, mld-reduction, mld-report, nd-na,
nd-ns, next-header, no-admin, no-route, packet-too-big, port-unreachable,
router-solicitation, router-advertisement, router-renumbering, time-exceeded, and
unreachable.
Fragments. Either select Enable to allow initial fragments (that is, the fragment bit is
asserted) or leave the default setting at Disable to prevent initial fragments from
being used.
This option is not valid for rules that match L4 information such as TCP port number,
because that information is carried in the initial packet.
Flow Label. The Flow Label field is enabled only if selection from the Protocol T
ype
menu is ICMPv6. The flow label is 20-bit number that is unique to an IPv6 packet and
that is used by end stations to signify quality-of-service handling in routers. The flow
label can specified within the range 0 to 1048575.
IPv6 DSCP Service. Specify the IP Dif
fServ Code Point (DSCP) field. This is an
optional configuration.
The DSCP is defined as the high-order six bits of the service type octet in the IPv6
header. Enter an integer from 0 to 63. To select the IPv6 DSCP, select one of the
DSCP keywords. To specify a numeric value, select Other and enter the numeric
value of the DSCP.
Rate Limit Conform Data Rate. Specify the conforming data rate of IPv6
ACL rule.
Valid values are 1 to 4294967295 in Kbps.
Rate Limit Burst Size. Specify the burst size of the IPv6
ACL rule. Valid values are 1
to 128 in Kbytes.
Time Range. Specify the name of the time range that you want to associate with the
IPv6 ACL
rule.
8. Click the Apply button.
Your settings are saved.
The Rule Status field displays whether the
ACL rule is active or inactive. Blank means
that no timer schedules are assigned to the rule.