Reference Guide

Table Of Contents
deny icmp
Configures a filter to drop all or specific Internet Control Message Protocol (ICMP) messages.
Syntax
deny icmp [A.B.C.D | A.B.C.D/x | any | host ip-address] [[A.B.C.D |
A.B.C.D/x | any | host ip-address] [capture | dscp value | fragment]
Parameters
A.B.C.D Enter the IP address in hexadecimal format separated by colons.
A.B.C.D/x Enter the number of bits to match to the IP address.
any (Optional) Set all routes subject to the filter.
capture (Optional) Capture packets the filter processes.
dscp value (Optional) Deny a packet based on the DSCP values, from 0 to 63.
fragment (Optional) Use ACLs to control packet fragments.
host ip-address (Optional) Enter the IP address to use a host address only.
Default Not configured
Command Mode IPV4-ACL
Usage
Information
The no version of this command removes the filter.
Example
OS10(config)# ip access-list egress
OS10(conf-ipv4-acl)# deny icmp any any capture session 1
Supported
Releases
10.2.0E or later
deny icmp (IPv6)
Configures a filter to drop all or specific ICMP messages.
Syntax
deny icmp [A::B | A::B/x | any | host ipv6-address] [A::B | A::B/x | any |
host ipv6-address] [capture | dscp value | fragment]
Parameters
A::B Enter the IPv6 address in hexadecimal format separated by colons.
A::B/x Enter the number of bits to match to the IPv6 address.
any (Optional) Set all routes which are subject to the filter:
capture (Optional) Capture packets the filter processes.
dscp value (Optional) Deny a packet based on the DSCP values, from 0 to 63.
fragment (Optional) Use ACLs to control packet fragments.
host ipv6-address (Optional) Enter the IPv6 address to use a host address only.
Default Not configured
Command Mode IPV6-ACL
Usage
Information
The no version of this command removes the filter.
Example
OS10(config)# ipv6 access-list ipv6test
OS10(conf-ipv6-acl)# deny icmp any any capture session 1
Supported
Releases
10.2.0E or later
Access Control Lists 577