The ipv6 security permit incomplete-first-fragment command enables the function not to check the packets with an incomplete first fragment header.
The undo ipv6 security permit incomplete-first-fragment command disables the function not to check the packets with an incomplete first fragment header.
By default, the function not to check the packets with an incomplete first fragment header is disabled.
100ge sub-interface view, 100GE interface view, 10GE sub-interface view, 10GE interface view, 200GE sub-interface view, 25GE sub-interface view, 25GE interface view, 400GE sub-interface view, 400GE interface view, 40GE sub-interface view, 40GE interface view, 50GE sub-interface view, 50GE interface view, Eth-Trunk sub-interface view, Eth-Trunk interface view, FlexE interface view, GE optical interface view, GE sub-interface view, GE interface view, GE electrical interface view, Global VE sub-interface view, Loopback interface view, PW-VE sub-interface view, PW-VE interface view, Tunnel interface view, VBDIF interface view, VE sub-interface view, VLANIF interface view, Management interface view
Usage Scenario
If a router needs to process IPv6 packets with an incomplete first fragment header, the capability of receiving such packets must be reserved. To enable the function not to check the packets with an incomplete first fragment header, run the ipv6 security permit incomplete-first-fragment command.
<HUAWEI> system-view [~HUAWEI] interface Eth-Trunk1 [~HUAWEI-Eth-Trunk1] undo portswitch [*HUAWEI-Eth-Trunk1] ipv6 enable [*HUAWEI-Eth-Trunk1] ipv6 security permit incomplete-first-fragment