[rbak-nsp] IPv6 Filtering

Brandon Daly brand.daly at googlemail.com
Tue Jun 21 09:15:41 EDT 2011


Hi,



I’m in the process of planning IPv6 deployment for some Ethernet services on
a Smart Edge running SEOS 6.4.1.3



I’m having some trouble with the filter necessary to block RHO.  It
initially only appears to be possible to block all Routing Header (next
header type 43) .  I have attempted the following command, which would
appear to be the correct format to block all RH packets;



ipv6 access-list subscriber_filter seq 5 deny 43 any any



But this is producing the error;



% Next Header cannot be IPv6 Extension Header type.



Suggesting it is not possible to filter on extension headers.  Is anyone
able to  advise the recommended method to block RHO packets?



I’m also looking at rate limiting ICMPv6 messages to the Control Plane, can
you advise on any resources which detail how to achieve this?



Many thanks,

Brandon.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://puck.nether.net/pipermail/redback-nsp/attachments/20110621/be769f29/attachment.html>


More information about the redback-nsp mailing list