Fortinet black logo

CLI Reference

firewall ipv6-eh-filter

firewall ipv6-eh-filter

Introduction.

config firewall ipv6-eh-filter
    set hop-opt {enable | disable}   Enable/disable blocking packets with the Hop-by-Hop Options header (default = disable).
    set dest-opt {enable | disable}   Enable/disable blocking packets with Destination Options headers (default = disable).
    set hdopt-type {integer}   Block specific Hop-by-Hop and/or Destination Option types (max. 7 types, each between 0 and 255, default = 0). range[0-255]
    set routing {enable | disable}   Enable/disable blocking packets with Routing headers (default = enable).
    set routing-type {integer}   Block specific Routing header types (max. 7 types, each between 0 and 255, default =  0). range[0-255]
    set fragment {enable | disable}   Enable/disable blocking packets with the Fragment header (default = disable).
    set auth {enable | disable}   Enable/disable blocking packets with the Authentication header (default = disable).
    set no-next {enable | disable}   Enable/disable blocking packets with the No Next header (default = disable)
end

firewall ipv6-eh-filter

Introduction.

config firewall ipv6-eh-filter
    set hop-opt {enable | disable}   Enable/disable blocking packets with the Hop-by-Hop Options header (default = disable).
    set dest-opt {enable | disable}   Enable/disable blocking packets with Destination Options headers (default = disable).
    set hdopt-type {integer}   Block specific Hop-by-Hop and/or Destination Option types (max. 7 types, each between 0 and 255, default = 0). range[0-255]
    set routing {enable | disable}   Enable/disable blocking packets with Routing headers (default = enable).
    set routing-type {integer}   Block specific Routing header types (max. 7 types, each between 0 and 255, default =  0). range[0-255]
    set fragment {enable | disable}   Enable/disable blocking packets with the Fragment header (default = disable).
    set auth {enable | disable}   Enable/disable blocking packets with the Authentication header (default = disable).
    set no-next {enable | disable}   Enable/disable blocking packets with the No Next header (default = disable)
end