Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Filtering ICMPv6 Messages (RFC 4890)

    Firewalling
    2
    3
    758
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      metebalci
      last edited by

      I wonder if this RFC is also practically used to configure IPv6. So basically it lists traffic that must not be dropped for transit traffic and for local traffic. In short it says for transit traffic:

      • Destination Unreachable (Type 1) - All codes
      • Packet Too Big (Type 2)
      • Time Exceeded (Type 3) - Code 0 only
      • Parameter Problem (Type 4) - Codes 1 and 2 only
      • Echo Request (Type 128)
      • Echo Response (Type 129)

      must not be dropped. In addition to these, for local traffic, there is another (a bit longer) list related to being a router e.g. router and neighbor solicitation and advertisement.

      Related question: is it possible to specific the code of an ICMPv6 type in a rule ?

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @metebalci
        last edited by johnpoz

        @metebalci said in Filtering ICMPv6 Messages (RFC 4890):

        is it possible to specific the code of an ICMPv6 type in a rule ?

        Yes

        type.png

        you can always look to the full rules to see what is allowed/blocked etc.. that might not be shown in the gui

        https://docs.netgate.com/pfsense/en/latest/firewall/pf-ruleset.html

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        M 1 Reply Last reply Reply Quote 0
        • M
          metebalci @johnpoz
          last edited by

          @johnpoz said in Filtering ICMPv6 Messages (RFC 4890):

          @metebalci said in Filtering ICMPv6 Messages (RFC 4890):

          is it possible to specific the code of an ICMPv6 type in a rule ?

          Yes

          type.png

          This is type and it is how I do it, I wonder if it is possible to filter by code also.

          @johnpoz said in Filtering ICMPv6 Messages (RFC 4890):

          you can always look to the full rules to see what is allowed/blocked etc.. that might not be shown in the gui

          https://docs.netgate.com/pfsense/en/latest/firewall/pf-ruleset.html

          Thanks, I didnt know this, I will check.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.