Community Tribal Knowledge Base

ICMP Type and Code Filtering

Question

It appears that IP protocol 1 includes all types. Are there any ACL types that allow specific ICMP type packets to be denied or permitted?

netservice svc-icmp 1 This allows all types of ICMP messages.

Looking for a way to allow and block specific types and codes. Example:

netservice svc-icmp 1 0 = Echo
netservice svc-icmp 1 8 = Echo Reply

Answer

Extended ACLs in ArubaOS can:

ip access-list extended 100
deny icmp any any echo-reply
deny icmp any any echo

Version History
Revision #:
2 of 2
Last update:
‎11-15-2011 08:36 AM
Updated by:
 
Labels (1)
Search Airheads
Showing results for 
Search instead for 
Did you mean: 
Is this a frequent problem?

Request an official Aruba knowledge base article to be written by our experts.