< Home

ipv6 destination-unreachable drop

Function

The ipv6 destination-unreachable drop command enables the switch to discard the packets that do not match IPv6 routing entries.

The undo ipv6 destination-unreachable drop command disables the switch from discarding the packets that do not match IPv6 routing entries.

By default, the device discards the packets that do not match IPv6 routing entries.

Format

ipv6 destination-unreachable drop

undo ipv6 destination-unreachable drop

Only the S5720-EI, S5720-HI, S5730-HI, S5731-H, S5731-S, S5731S-H, S5731S-S, S5732-H, S5735-L, S5735S-L, S5735S-L-M, S5735-S, S5735S-S, S5735-S-I, S6720-EI, S6720-HI, S6720S-EI, S6730-H, S6730S-H, S6730-S, and S6730S-S support this command.

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

Usage Scenario

Generally, the device sends the IPv6 packets that do not match routing entries to the CPU for processing. If many IPv6 packets do not match routing entries because of an attack or improper network configurations, the CPU is busy. To prevent this situation, run the ipv6 destination-unreachable drop command to configure the switch to discard these packets.

Precautions

If the ipv6 destination-unreachable drop command is used and a traffic policy with the redirect action is configured, both the drop action and the redirect action take effect. Because the drop action has a higher priority than the redirect action, ICMPv6 Redirect packets are discarded. This leads to a redirection failure. To make the redirect action take effect, run the undo ipv6 destination-unreachable drop command to disable the drop action. However, disabling the drop action will degrade the attack defense performance of the system. You must configure the two actions properly according to network requirements.

After the ipv6 destination-unreachable drop command is used, the switch does not respond to the ICMPv6 Error packets caused when IPv6 packets do not match routing entries until the drop action is disabled.

For the S6720-EI and S6720S-EI, if the resource allocation mode is set to enhanced-ipv4 or ipv4-ipv6 6:1 using the assign resource-mode command, the ipv6 destination-unreachable drop command does not take effect.

Example

# Configure the switch to discard the packets that do not match IPv6 routing entries.

<HUAWEI> system-view
[HUAWEI] undo ipv6 destination-unreachable drop
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >