Configure ACE IP Fragmentation

Configure ACE IP fragmentation entries to have the filter look for packets with the fragmentation flag.

Before you begin

  • The ACL exists.

  • The ACE exists.

Procedure

  1. In the navigation pane, expand Configuration > Security > Data Path.
  2. Select Advanced Filters (ACE/ACLs).
  3. Select the ACL tab.
  4. Select the appropriate ACL.
  5. Select ACE.
  6. Select the appropriate ACE.
  7. Select IP.
  8. Select the Fragmentation tab.
  9. Select Insert.
  10. Specify the operator for IP fragmentation.

    Eq is the only choice.

  11. Specify the fragmentation bits to match from the IP header.
  12. Select Insert.

Fragmentation Field Descriptions

Use the data in the following table to use the Fragmentation tab.

Name

Description

AclId

Specifies the ACL ID.

AceId

Specifies the ACE ID.

Oper

Specifies the logical operator for the ACE IP options. Any is the only option.

Fragmentation

Specifies the IP fragmentation bits to match from the IP header:

  • noFragment

  • anyFragment

The default is noFragment.