Home
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
MENU
Home
PAN-OS
PAN-OS Web Interface Reference
Network
Network > Network Profiles
Network > Network Profiles > Zone Protection
Packet Based Attack Protection
ICMPv6 Drop
Document:
PAN-OS Web Interface Reference
ICMPv6 Drop
Download PDF
Last Updated:
Mar 14, 2022
Current Version:
9.0 (EoL)
Version 10.2
Version 10.1
Version 10.0
Version 9.1
Version 9.0 (EoL)
Version 8.1 (EoL)
Version 8.0 (EoL)
End-of-Life (EoL)
Previous
Next
ICMPv6 Drop
To instruct the firewall what to do with certain ICMPv6 packets it receives in the zone, select the following settings to enable them.
Zone Protection Profile Settings—Packet Based Attack Protection
Configured In
Description
ICMPv6 destination unreachable - require explicit security rule match
Network
Network Profiles
Zone Protection
Packet Based Attack Protection
ICMPv6 Drop
Require an explicit Security policy match for Destination Unreachable ICMPv6 messages, even when the message is associated with an existing session.
ICMPv6 packet too big - require explicit security rule match
Require an explicit Security policy match for Packet Too Big ICMPv6 messages, even when the message is associated with an existing session.
ICMPv6 time exceeded - require explicit security rule match
Require an explicit Security policy match for Time Exceeded ICMPv6 messages, even when the message is associated with an existing session.
ICMPv6 parameter problem - require explicit security rule match
Require an explicit Security policy match for Parameter Problem ICMPv6 messages, even when the message is associated with an existing session.
ICMPv6 redirect - require explicit security rule match
Require an explicit Security policy match for Redirect Message ICMPv6 messages, even when the message is associated with an existing session.
Previous
Next
Recommended For You
Recommended Videos
Recommended videos not found.