• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Filtering ICMPv6 Messages (RFC 4890)

Scheduled Pinned Locked Moved Firewalling
3 Posts 2 Posters 773 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    metebalci
    last edited by Jul 13, 2021, 8:32 AM

    I wonder if this RFC is also practically used to configure IPv6. So basically it lists traffic that must not be dropped for transit traffic and for local traffic. In short it says for transit traffic:

    • Destination Unreachable (Type 1) - All codes
    • Packet Too Big (Type 2)
    • Time Exceeded (Type 3) - Code 0 only
    • Parameter Problem (Type 4) - Codes 1 and 2 only
    • Echo Request (Type 128)
    • Echo Response (Type 129)

    must not be dropped. In addition to these, for local traffic, there is another (a bit longer) list related to being a router e.g. router and neighbor solicitation and advertisement.

    Related question: is it possible to specific the code of an ICMPv6 type in a rule ?

    J 1 Reply Last reply Jul 13, 2021, 10:50 AM Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator @metebalci
      last edited by johnpoz Jul 13, 2021, 10:52 AM Jul 13, 2021, 10:50 AM

      @metebalci said in Filtering ICMPv6 Messages (RFC 4890):

      is it possible to specific the code of an ICMPv6 type in a rule ?

      Yes

      type.png

      you can always look to the full rules to see what is allowed/blocked etc.. that might not be shown in the gui

      https://docs.netgate.com/pfsense/en/latest/firewall/pf-ruleset.html

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      M 1 Reply Last reply Jul 13, 2021, 10:59 AM Reply Quote 0
      • M
        metebalci @johnpoz
        last edited by Jul 13, 2021, 10:59 AM

        @johnpoz said in Filtering ICMPv6 Messages (RFC 4890):

        @metebalci said in Filtering ICMPv6 Messages (RFC 4890):

        is it possible to specific the code of an ICMPv6 type in a rule ?

        Yes

        type.png

        This is type and it is how I do it, I wonder if it is possible to filter by code also.

        @johnpoz said in Filtering ICMPv6 Messages (RFC 4890):

        you can always look to the full rules to see what is allowed/blocked etc.. that might not be shown in the gui

        https://docs.netgate.com/pfsense/en/latest/firewall/pf-ruleset.html

        Thanks, I didnt know this, I will check.

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received