Configuring ACE IP fragmentation

Configure ACE IP fragmentation entries to have the filter look for packets with the fragmentation flag.

Before you begin

  • The ACL exists.

  • The ACE exists.

Procedure

  1. In the navigation tree, expand the following folders: Configuration > Security > Data Path.
  2. Click Advanced Filters (ACE/ACLs).
  3. Click the ACL tab.
  4. Select the appropriate ACL.
  5. Click ACE.
  6. Select the appropriate ACE.
  7. Click IP.
  8. Click the Fragmentation tab.
  9. Click Insert.
  10. Specify the operator for IP fragmentation.

    Eq is the only choice.

  11. Specify the fragmentation bits to match from the IP header.
  12. Click Insert.

Fragmentation field descriptions

Use the data in the following table to use the Fragmentation tab.

Name

Description

AclId

Specifies the ACL ID.

AceId

Specifies the ACE ID.

Oper

Specifies the logical operator for the ACE IP options. Any is the only option.

Fragmentation

Specifies the IP fragmentation bits to match from the IP header:

  • noFragment

  • anyFragment

The default is noFragment.