R3721-F3210-F3171-HP High-End Firewalls VPN Command Reference-6PW101
32
Description
Use tunnel discard ipv4-compatible-packet to enable dropping of IPv6 packets using IPv4-compatible
IPv6 addresses.
Use undo tunnel discard ipv4-compatible-packet to restore the default.
By default, IPv6 packets using IPv4-compatible IPv6 addresses are not dropped.
The tunnel discard ipv4-compatible-packet command enables the firewall to check the source and
destination IPv6 addresses of the de-encapsulated IPv6 packets from the tunnel and discard packets that
use a source or destination IPv4-compatible IPv6 address.
Examples
# Enable dropping of IPv6 packets using IPv4-compatible IPv6 addresses.
<Sysname> system-view
[Sysname] tunnel discard ipv4-compatible-packet
tunnel-protocol
Syntax
tunnel-protocol { gre [ ipv6 | p2mp ] | ipsec ipv4 | ipv4-ipv4 | ipv4-ipv6 [ dslite-aftr | dslite-cpe ] |
ipv6-ipv4 [ 6to4 | isatap ] | ipv6-ipv6 }
undo tunnel-protocol
View
Tunnel interface view
Default level
2: System level
Parameters
gre: Specifies the GRE over IPv4 tunnel mode.
gre ipv6: Specifies the GRE over IPv6 tunnel mode.
gre p2mp: Specifies the point-to-multipoint GRE tunnel mode.
ipsec ipv4: Specifies the IPsec over IPv4 tunnel mode.
ipv4-ipv4: Specifies the IPv4 over IPv4 tunnel mode.
ipv4-ipv6: Specifies the IPv4 over IPv6 manual tunnel mode.
ipv4-ipv6 dslite-aftr: Specifies the IPv4 over IPv6 DS-lite tunnel mode on the AFTR.
ipv4-ipv6 dslite-cpe: Specifies the IPv4 over IPv6 DS-lite tunnel mode on the CPE.
ipv6-ipv4: Specifies the IPv6 over IPv4 manual tunnel mode.
ipv6-ipv4 6to4: Specifies the IPv6 over IPv4 6to4 tunnel mode..
ipv6-ipv4 isatap: Specifies the IPv6 over IPv4 ISATAP tunnel mode.
ipv6-ipv6: Specifies the IPv6 over IPv6 tunnel mode.
Description
Use tunnel-protocol to specify the tunnel mode for the tunnel interface.
Use undo tunnel-protocol to restore the default.