Project

General

Profile

Actions

Feature #6539

open

ICMPv6 filtering requires multiple rules - no range support

Added by Bruce Simpson almost 8 years ago. Updated over 4 years ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Rules / NAT
Target version:
-
Start date:
06/27/2016
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:

Description

(This may also be a shortcoming in PF itself).

Currently there is no way to specify an ICMPv6 type range in the GUI. This leads to multiple rules being required to implement basic filtering e.g. RA-Guard as in RFCs 6105 & 7113. This is cumbersome and difficult to read & maintain, especially for novice users.

(although this normally requires L2 assistance from a switch, also.)

Actions

Also available in: Atom PDF