Linux Netfilter discussions
 help / color / mirror / Atom feed
* ICMPv6 Type 1 Code 5 and 6 missing in iptables REJECT target and icmpv6 match
@ 2015-08-19 14:51 Andreas Herz
  2015-08-20  8:13 ` Jan Engelhardt
  0 siblings, 1 reply; 2+ messages in thread
From: Andreas Herz @ 2015-08-19 14:51 UTC (permalink / raw)
  To: netfilter-devel, netfilter

Hi,

as i read the RFC 7084 i found the following suggestion:

> L-14:   The IPv6 CE router MUST send an ICMPv6 Destination Unreachable
>         message, code 5 (Source address failed ingress/egress policy)
>         for packets forwarded to it that use an address from a prefix
>         that has been invalidated.

And in RFC 4443 they are defined as:

> 5 - Source address failed ingress/egress policy
> 6 - Reject route to destination

Is there a reason for that?

If i look into the "extensions/libip6t_icmp6.c" i just see the codes 0,1,2,3,4
for type 1. And in "include/linux/netfilter_ipv6/ip6t_REJECT.h" it's
"IP6T_ICMP6_ECHOREPLY" which doesnt' sound like the one in the RFC.

Or is it just missing, so i might add it?

Thanks

-- 
Andreas Herz

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: ICMPv6 Type 1 Code 5 and 6 missing in iptables REJECT target and icmpv6 match
  2015-08-19 14:51 ICMPv6 Type 1 Code 5 and 6 missing in iptables REJECT target and icmpv6 match Andreas Herz
@ 2015-08-20  8:13 ` Jan Engelhardt
  0 siblings, 0 replies; 2+ messages in thread
From: Jan Engelhardt @ 2015-08-20  8:13 UTC (permalink / raw)
  To: Andreas Herz; +Cc: netfilter-devel, netfilter


On Wednesday 2015-08-19 16:51, Andreas Herz wrote:
>And in RFC 4443 they are defined as:
>
>> 5 - Source address failed ingress/egress policy
>> 6 - Reject route to destination
>
>Is there a reason for that?
>
>If i look into the "extensions/libip6t_icmp6.c" i just see the codes 0,1,2,3,4
>for type 1. And in "include/linux/netfilter_ipv6/ip6t_REJECT.h" it's
>"IP6T_ICMP6_ECHOREPLY" which doesnt' sound like the one in the RFC.
>
>Or is it just missing, so i might add it?

It would appear fine to just add it.

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2015-08-20  8:13 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-08-19 14:51 ICMPv6 Type 1 Code 5 and 6 missing in iptables REJECT target and icmpv6 match Andreas Herz
2015-08-20  8:13 ` Jan Engelhardt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox