Actions
Feature #6539
openICMPv6 filtering requires multiple rules - no range support
Status:
New
Priority:
Normal
Assignee:
-
Category:
Rules / NAT
Target version:
-
Start date:
06/27/2016
Due date:
% Done:
0%
Estimated time:
Plus Target Version:
Release Notes:
Description
(This may also be a shortcoming in PF itself).
Currently there is no way to specify an ICMPv6 type range in the GUI. This leads to multiple rules being required to implement basic filtering e.g. RA-Guard as in RFCs 6105 & 7113. This is cumbersome and difficult to read & maintain, especially for novice users.
(although this normally requires L2 assistance from a switch, also.)
Actions