Juniper Networks
Log in
|
How to Buy
|
Contact Us
|
United States (Change)
Choose Country
Close

Choose Country

North America

  • United States

Europe

  • Deutschland - Germany
  • España - Spain
  • France
  • Italia - Italy
  • Россия - Russia
  • United Kingdom

Asia Pacific

  • Asean Region (Vietnam, Indonesia, Singapore, Malaysia)
  • Australia
  • 中国 - China
  • India
  • 日本 - Japan
  • 대한민국 - Korea
  • 台灣 - Taiwan
Solutions
Products & Services
Company
Partners
Support
Education
Community
Security Intelligence Center

Technical Documentation

Support
Technical Documentation
Content Explorer New
 
Enterprise MIBs
 
EOL Documentation
 
Feature Explorer Login required New
 
File Format Help
 
Glossary
 
Portable Libraries
 
 
Home > Support > Technical Documentation > JunosE Software > Understanding ICMPv6 Unreachable Messages for Static Routes Sent on Null Interfaces
Print
Rate and give feedback:  Feedback Received. Thank You!
Rate and give feedback: 
Close
This document helped resolve my issue.  Yes No

Additional Comments

800 characters remaining

May we contact you if necessary?

Name:  
E-mail: 
Submitting...
 

Related Documentation

  • Establishing an IPv6 Static Route
  • Enabling or Disabling the Transmission of ICMPv6 Unreachable Messages for Static Routes on Null Interfaces
  • ip unreachables
  • ipv6 route
  • show ipv6 static
 

Understanding ICMPv6 Unreachable Messages for Static Routes Sent on Null Interfaces

You can handle undesired traffic by sending data packets to the null interface. The null interface is automatically created by the router, is always up, cannot be deleted, and acts as a data sink. The null interface cannot forward or receive traffic. However, the command-line interface (CLI) does enable you to access the null interface. You can configure a static route using the ip route command and direct traffic to the null interface by specifying the null 0 keyword with this command, instead of a next-hop or destination address. You can also use access control lists to filter undesired traffic.

When a ping or traceroute packet from a subscriber reaches the null 0 interface configured with a static route, it is discarded in the forwarding plane. You can configure the router to either send or not send Internet Control Message Protocol version 6 (ICMPv6) unreachable messages to the subscriber for such discarded packets. An advantage of this feature is that it enables synchronization of the RADIUS configuration of the client environment with the network topology.

You can use the reject keyword with the ipv6 route command to cause the router to send ICMPv6 unreachable messages to the originator from which ping and traceroute packets are received on the null 0 interface with a static route. The switch route processor (SRP) module drops these ping and traceroute packets destined for null 0 interface without further processing and sends ICMPv6 unreachable messages to the originator.

For ICMPv6 unreachable messages to be sent from the router for packets that are received from clients on the static routes configured on null 0 interfaces, you must configure the router to enable generation of ICMP unreachable messages for IPv6 (ping and traceroute) that the router cannot deliver using the ip unreachables command in Interface Configuration mode.

The option to send ICMPv6 unreachable messages is available for all IPv6 static routes in a virtual router that are configured with null 0 interface as the next-hop. The Denial of Service (DoS) protection feature can be enabled to monitor the ping and traceroute packets that are discarded from flooding the network. A new DoS type is used to apply a rate-control limit on these packets.

By default, generation of ICMP unreachable messages is enabled on an interface. If the capability to generate ICMP unreachable messages is disabled on the interface, you must enable this functionality using the ip unreachables command in Interface Configuration mode to send ICMP unreachables for packets that reached null 0 interfaces with static routes and were discarded. The IPv6 ICMP unreachable message packets are sent with a value of 6 (Reject Route to destination) in the Code field.

If you disable generation of ICMPv6 unreachable messages for null interfaces on the router using the no ip unreachables command, ICMPv6 unreachable messages are not sent for packets that are dropped or not processed by such interfaces, even if you configure static routes for such interfaces to send ICMP unreachables (using the reject keyword with the ipv6 route command).

To enable backward compatibility with versions of JunosE software in which functionality is not available, the default behavior is to discard the IPv6 ping and traceroute packets destined for null 0 interfaces at the forwarding layer without the transmission of ICMP unreachable messages to the originator.

You can use the output of the show ipv6 static command to determine whether the sending of ICMP unreachable messages is enabled on each interface for which static routes are configured. The ICMP Unreach field in the output of these commands specifies whether the reject or discard keyword is configured for each static route on the router interface.

 

Related Documentation

  • Establishing an IPv6 Static Route
  • Enabling or Disabling the Transmission of ICMPv6 Unreachable Messages for Static Routes on Null Interfaces
  • ip unreachables
  • ipv6 route
  • show ipv6 static
 

Published: 2012-06-20

 
  • About Juniper
  • Investor Relations
  • Press Releases
  • Newsletters
  • Juniper Offices
  • Green Networking
  • Resources
  • How to Buy
  • Partner Locator
  • Image Library
  • Visio Templates
  • Security Center
  • Community
  • Forums
  • Blogs
  • Junos Central
  • Social Media
  • Developers
  • Support
  • Technical Documentation
  • Knowledge Base (KB)
  • Software Downloads
  • Product Licensing
  • Contact Support
Site Map / RSS Feeds / Careers / Accessibility / Feedback / Privacy & Policy / Legal Notices
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out