Reference Guide

Table Of Contents
permit icmp (for IPv6 ACLs)
To allow all or specific internet control message protocol (ICMP) messages, configure a filter.
Syntax
permit icmp {source address mask | any | host ipv6-address} {destination
address | any | host ipv6-address} [type] [message-type] [ttl operator]
[count [byte]] [log [interval minutes] [threshold-in-msgs [count]]
[monitor]
To remove this filter, you have two choices:
Use the no seq sequence-number command if you know the filters sequence number.
Use the no permit icmp {source address mask | any | host ipv6-address}
{destination address | any | host ipv6-address} command.
Parameters
source address
mask
Enter a network mask in /prefix format (/x) or A.B.C.D. The mask, when specified
in A.B.C.D format, may be either contiguous or non-contiguous.
any Enter the keyword any to specify that all routes are subject to the filter.
host
ip-
v6address
Enter the keyword host then the IPv6 address to specify a host IP address.
destination
Enter the IP address of the network or host to which the packets are sent.
type
Enter the ICMP packet type. The following types are available:
For IPv4:
echo count
echo-reply count
host-unreachable count
host-unknown count
network-unknown count
net-unreachable count
packet-too-big count
parameter-problem count
port-unreachable count
source-quench count
time-exceeded count
For IPv6:
echo count
echo-reply count
nd-ns count
nd-na count
packet-too-big count
parameter-problem count
time-exceeded count
port-unreachable count
The ICMP packets cannot be filtered using mirroring ACL.
ttl
Enter the keyword ttl to permit a packet based on the time to live value. The
range is from 1 to 255.
operator
Enter one of the following logical operand:
eq(equal to) matches packets that contain a ttl value that is equal to the
specified ttl value.
neq(not equal to) matches packets that contain a ttl value that is not equal
to the specified ttl value.
gt(greater than) matches packets that contain a ttl value that is greater
than the specified ttl value.
288 Access Control Lists (ACL)