Use the following configuration statements to add ICMP conditions to a classify-traffic condition:
- policies group name list name rule name traffic-condition name icmp-condition
{
- protocol protocol ;
- protocol-operation protocol-operation ;
- ip-flags ip-flags ;
- ip-flags-mask ip-flags-mask ;
- fragment-offset fragment-offset ;
- packet-length packet-length ;
- icmp-type icmp-type ;
- icmp-code icmp-code ;
- }
Because the protocol is already set to ICMP, do not change the protocol or protocol-operation options.
To add ICMP conditions to a classify-traffic condition:
[edit policies group bod list input rule pr traffic-condition ctc icmp-condition] user@host# show protocol icmp; protocol-operation 1; ip-flags ipFlags; ip-flags-mask ipFlagsMask; fragment-offset ipFragOffset; icmp-type icmpType; icmp-code icmpCode;