Руководство По Устранению Ошибки для Cisco Cisco Tunnel Terminating Gateway (TTG)
ACL Configuration Mode Commands
▀ redirect css service (by ICMP packets)
▄ Cisco ASR 5000 Series Command Line Interface Reference
OL-22948-01
This option is used in conjunction with the
option to specify a group of addresses for which
packets are to be filtered.
The mask must be entered as a complement:
The mask must be entered as a complement:
Zero-bits in this parameter mean that the corresponding bits configured for the
parameter must be identical.
One-bits in this parameter mean that the corresponding bits configured for the
parameter must be ignored.
Important:
The mask must contain a contiguous set of one-bits from the least significant bit (LSB). Therefore,
allowed masks are 0, 1, 3, 7, 15, 31, 63, 127, and 255. For example, acceptable wildcards are 0.0.0.3, 0.0.0.255, and
0.0.15.255. A wildcard of 0.0.7.15 is not acceptable since the one-bits are not contiguous.
0.0.15.255. A wildcard of 0.0.7.15 is not acceptable since the one-bits are not contiguous.
Specifies that all ICMP packets of a particular type are to be filtered. The type can be any integer value
between 0 and 255.
between 0 and 255.
Specifies that all ICMP packets of a particular code are to be filtered. The type can be any integer value
between 0 and 255.
between 0 and 255.
Usage
Define a rule definition to block ICMP packets which can be used for address resolution and possibly be a
security risk.
The IP redirecting allows flexible controls for pairs of individual hosts or groups by IP masking which allows
the redirecting of entire subnets if necessary.
security risk.
The IP redirecting allows flexible controls for pairs of individual hosts or groups by IP masking which allows
the redirecting of entire subnets if necessary.
Important:
A maximum of 16 rule definitions can be configured per ACL. Also note that ―redirect‖ rule
definitions are ignored for ACLs applied to specific subscribers or all subscribers facilitated by a specific context.
Example
The following command defines a rule definition that redirects packets to the charging service named
The following command defines a rule definition that redirects packets to the charging service named
, and
ICMP packets coming from the host with the IP address
.
The following sets the insertion point before the rule definition above.
The following command sets the insertion point after the first rule definition above.
The following deletes the first rule definition above.