10-15
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 10 Configuring Network Access
Configuring Virtual Context VLAN Interfaces
IPv6 Peer Link-Local
Address
In a redundant configuration, you can configure an IPv6 peer link local
address for the standby ACE. You can configure only one peer link local
address on an interface.
To configure the peer link local address, enter a complete IPv6 address
with an FE80::/10 prefix in this field.
Note The IPv6 peer link local address must be unique across multiple
contexts on a shared VLAN.
More Settings
Enable ICMP Guard Check the IPv4, IPv6 or both check boxes to indicate that ICMP Guard
is to be enabled on the ACE appliance. Clear the check boxes to indicate
that ICMP Guard is not to be enabled on ACE appliance.
Caution Disabling ICMP security checks may expose your ACE
appliance and network to potential security risks. When you
disable ICMP Guard, the ACE appliance no longer performs
NAT translations on the ICMP header and payload in error
packets, which can potentially reveal real host IP addresses to
attackers.
Enable DHCP Relay Check the IPv4, IPv6 or both check boxes to indicate that the ACE
appliance is to accept DHCP requests from clients on this interface and
to enable the DHCP relay agent.
Clear the check boxes to indicate that the ACE appliance is not to accept
DHCP requests or enable the DHCP relay agent.
Reverse Path Forwarding
(RPF)
Check the IPv4, IPv6 or both check boxes to indicate that the ACE
appliance is to discard IP packets if no reverse route is found or if the
route does not match the interface on which the packets arrived.
Clear the check boxes to indicate that the ACE appliance is not to filter
or discard packets based on the ability to verify the source IP address.
Reassembly Timeout
(Seconds)
Enter the number of seconds that the ACE appliance is to wait before it
abandons the fragment reassembly process if it doesn’t receive any
outstanding fragments for the current fragment chain (that is, fragments
belonging to the same packet).
• For IPv4, valid entries are 1 to 30 seconds. The default is 5.
• For IPv6, valid entries are 1 to 60 seconds. The default is 60.
Max. Fragment Chains
Allowed
Enter the maximum number of fragments belonging to the same packet
that the ACE appliance is to accept for reassembly.
For IPv4 and IPv6, valid entries are 1 to 256. The default is 24.
Table 10-3 VLAN Interface Attributes (continued)
Field Description
Comments to this Manuals