Enabling IPv6 ICMP Redirects and Configuring ICMP Rate-Limiting

You can enable a Layer 3 switch to send an IPv6 ICMP redirect message to a neighboring host to inform it of a better first-hop router on a path to a destination. and you can limit the rate at which IPv6 ICMP error messages are sent out on a network.

By default, the sending of IPv6 ICMP redirect messages by a Layer 3 switch is disabled. For more information about how ICMP redirect messages are implemented for IPv6, refer to IPv6 Neighbor Discovery Configuration.

Note: IPv6 Redirects is supported on Virtual Ethernet (VE) interfaces only.

IPv6 ICMP implements a token bucket algorithm. To illustrate how this algorithm works, imagine a virtual bucket that contains a number of tokens. Each token represents the ability to send one ICMP error message. Tokens are placed in the bucket at a specified interval until the maximum number of tokens allowed in the bucket is reached. For each error message that ICMP sends, a token is removed from the bucket. If ICMP generates a series of error messages, messages can be sent until the bucket is empty. If the bucket is empty of tokens, error messages cannot be sent until a new token is placed in the bucket.

  1. Enter global configuration mode.
    device# configure terminal
  2. To adjust the transmit interval between ICMP error messages to 1000 milliseconds and the maximum number of ICMP error messages that can be sent to 100, use the ipv6 icmp error-interval command.
    device(config)# ipv6 icmp error-interval 1000 100
    ICMP rate limiting is enabled by default. To disable ICMP rate limiting, set the interval to zero.
    Note: If you retain the default interval value or explicitly set the value to 100 milliseconds, output from the show run command does not include the setting of the ipv6 icmp error-interval command because the setting is the default. Also, if you configure the interval value to a number that does not evenly divide into 100000 (100 milliseconds), the system rounds up the value to a next higher value that does divide evenly into 100000. For example, if you specify an interval value of 150, the system rounds up the value to 200.
  3. Enter virtual Ethernet (VE) interface mode for VE 2.
    device(config)# interface ve 2
  4. To enable the sending of IPv6 ICMP redirect messages on virtual Ethernet (VE) interface 2, use the ipv6 redirects command.
    device(config-vif-2)# ipv6 redirects
    To verify that the sending of IPv6 ICMP redirect messages is enabled on a particular interface, use the show ipv6 interface command.

The following example enables IPv6 ICMP redirect messages and configures IPv6 ICMP rate-limiting.

device# configure terminal
device(config)# ipv6 icmp error-interval 1000 100
device(config)# interface ve 2
device(config-vif-2)# ipv6 redirects