Manual Chapter :
Create a packet filter policy
Applies To:
Show VersionsBIG-IP AFM
- 17.1.2, 17.1.1, 17.1.0, 17.0.0, 16.1.5, 16.1.4, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.10, 15.1.9, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0
Create a packet filter policy
You can create an IPv6 Packet Filter policy that contains one or more firewall rules. Once created, the policy can be applied to either the global or route domain contexts.
- On the Main tab, click.
- To the right of the page, clickAdd Policy.
- Type aNameand optionalDescriptionfor the policy.
- To the right of the page, clickAdd Rule.
- Type aNamefor the rule.
- From theStatelist, select eitherEnabledorDisabled.
- From theHeader Typelist, select the appropriate IPv6 header to match. Info: Only one Extension Header can be configured per rule.
- In theValuestext box, type a single EH option ID and click Add. Repeat this step for each option ID. Info: For a range of IDs, use a dash character separator. For example, 0-5.
- From theActionlist, select eitherAcceptorDrop.
- From theLoglist, select eitherYesorNo. Important: The Packet Filter logging option must also be enabled in the Event Log logging profile.
- ClickDone Editing.
- ClickCommit Changes to System.
The packet filter policy can now be applied to the route domain or global context.