Cisco Cisco Tunnel Terminating Gateway (TTG) Fascicule
IPv6 ACL Configuration Mode Commands
▀ redirect context (by source ICMP packets)
▄ Cisco ASR 5x00 Command Line Interface Reference
6360
dest_address
The IP address(es) to which the packet is to be sent.
This option is used to filter all packets to a specific IP address or a group of IP addresses.
When specifying a group of addresses, the initial address is configured using this parameter. The range can
then be configured using the
This option is used to filter all packets to a specific IP address or a group of IP addresses.
When specifying a group of addresses, the initial address is configured using this parameter. The range can
then be configured using the
dest_wildcard
parameter.
dest_wildcard
This option is used in conjunction with the
dest_address
option to specify a group of addresses for which
packets are to be filtered.
The mask must be entered as a complement:
The mask must be entered as a complement:
Zero-bits in this parameter mean that the corresponding bits configured for the
dest_address
parameter must be identical.
One-bits in this parameter mean that the corresponding bits configured for the
dest_address
parameter must be ignored.
Important:
The mask must contain a contiguous set of one-bits from the least significant bit (LSB).
icmp_type
Specifies that all ICMP packets of a particular type are to be filtered. Type is an integer from 0 through 255.
icmp_code
Specifies that all ICMP packets of a particular code are to be filtered type is an integer from 0 through 255.
Usage
Define a rule to block ICMP packets which can be used for address resolution and possibly be a security risk.
The IP redirecting allows flexible controls for pairs of individual hosts or groups by IP masking which allows
the redirecting of entire subnets if necessary.
The IP redirecting allows flexible controls for pairs of individual hosts or groups by IP masking which allows
the redirecting of entire subnets if necessary.
Important:
The maximum number of rules that can be configured per ACL varies depending on how the ACL is
to be used. For more information, refer to the Engineering Rules appendix in the System Administration Guide. Also
note that “redirect” rules are ignored for ACLs applied to specific subscribers or all subscribers facilitated by a specific
context.
note that “redirect” rules are ignored for ACLs applied to specific subscribers or all subscribers facilitated by a specific
context.
Example
The following command defines a rule that redirects packets to the context with the context ID of
23
, and
ICMP packets coming from the host with the IP address
2002::c6a2:6419
:
redirect context 23 icmp host 2002::c6a2:6419
The following sets the insertion point to before the first rule defined above:
before redirect context 23 icmp host 2002::c6a2:6419
The following command sets the insertion point after the second rule defined above:
after redirect context 23 icmp host 2002::c6a2:6419