ICMPv6 filtering requires multiple rules - no range support
Rules / NAT
Plus Target Version:
(This may also be a shortcoming in PF itself).
Currently there is no way to specify an ICMPv6 type range in the GUI. This leads to multiple rules being required to implement basic filtering e.g. RA-Guard as in RFCs 6105 & 7113. This is cumbersome and difficult to read & maintain, especially for novice users.
(although this normally requires L2 assistance from a switch, also.)
Updated by Chris Buechler over 6 years ago
- Tracker changed from Bug to Feature
Updated by Jim Pingle over 3 years ago
- Category set to Rules / NAT