cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2987
Views
5
Helpful
2
Replies

ICMPv6 and firewall clarification

mocah
Level 1
Level 1

Hello all,

I was just reading that some ICMPv6 types must be permitted over firewall rules in both directions. Does this mean that even if current rules on firewall  allows only access from LAN to Internet (all traffic from Internet to LAN is blocked) firewall rules should allow some ICMPv6 types from Internet to LAN?

If so which icmpv6 types must be allowed from internet to LAN (Fragmentation, packet-to-big)?

Thank you and kind regards,

Marko

2 Replies 2

Marcin Latosiewicz
Cisco Employee
Cisco Employee

Marko,

ND, DAD, PMTUD will depend on ICMPv6 being allowed through.

Any traffic filtering should allow those.

if you're looking for brief overview, NIST guys have compiled it:

http://csrc.nist.gov/publications/nistpubs/800-119/sp800-119.pdf

Section 3.5 to be specific.

Marcin

Dear Marcin,

thank you

Kind regards,

Marko