Configure IPv6 ACL Extensions for Hop by Hop Filtering

I have IPv6 ACL questions and concerns.  The following code is an example:
ipv6  access-list inbound-to-enclave
     remark block IPv6 DO Invalid Options
      deny 60 any any dest-option-type 5
     deny 60 any any dest-option-type 194
     deny 60 any any dest-option-type 195
I see that dest-option-type became available in IOS release 12.4(2)T.  I can't tell if this option was added to later releases of 12.2.  Also, is it available in all releases of 15.x.
I am guessing that if a version of the IOS that is used is prior to 12.4(2)T that the default action will be to pass this traffic, correct?  Thank you for any assistance that you can provide.

Hi Forrest,
This is correct. By default, this traffic would be allowed.
Regards

Similar Messages

  • Configure localost and extension for test site

    Hi, I'm on my first attempt at setting up a site and using an
    extension. I dl'd the login extension from Adobe but seem to have a
    problem with the URL it is passing. My site is set up for "
    http://localhost:8500/test".
    A successful login calls "index.cfm". What is apparently getting
    passed is "
    http://localhost:8500/test//test/login.cfm".
    Somewhere in configuring things I put in too much, but I can't seem
    to track it down. Help is appreciated as this will affect all my
    testing as you might guess. Thanks.

    Hi, I'm on my first attempt at setting up a site and using an
    extension. I dl'd the login extension from Adobe but seem to have a
    problem with the URL it is passing. My site is set up for "
    http://localhost:8500/test".
    A successful login calls "index.cfm". What is apparently getting
    passed is "
    http://localhost:8500/test//test/login.cfm".
    Somewhere in configuring things I put in too much, but I can't seem
    to track it down. Help is appreciated as this will affect all my
    testing as you might guess. Thanks.

  • IPv6 ACL host limitation also for private network?

    Hello,
    I'm using a cisco WS-C3750G-24TS-1U 12.2(44)SE5. I know the IPv6 ACL limitations for this hardware
    However, I think that private network(fc00::/7) should not be the case. In my case, I'm using EUI addresses.
    switchcore(config-ipv6-acl)#permit tcp any host 2001:0:0:0:222:64ff:fec2:1f5a eq www sequence 20
    switchcore(config-ipv6-acl)#permit tcp any host 3FFF:0:0:0:222:64ff:fec2:1f5a eq www sequence 20  
    switchcore(config-ipv6-acl)#permit tcp any host fdc8:0:0:0:222:64ff:fec2:1f5a eq www sequence 20
    % Host address FDC8::222:64FF:FEC2:1F5A can not be supported
    % ACE can not be added
    % Failed to modify access list
    switchcore(config-ipv6-acl)#permit tcp any host fc00:0:0:0:222:64ff:fec2:1f5a eq www sequence 20
    % Host address FC00::222:64FF:FEC2:1F5A can not be supported
    % ACE can not be added
    % Failed to add access list
    Is IOS right?

    Hum... yes, you are right. I missed this point. Thanks.
    Anyway, "Private Network" would fit very well in this list
    –aggregatable global unicast addresses
    –link local addresses

  • Extensions for Elements?

    Don't know if this is the right place to post, but I am looking for resources to help build extensions (plugins) for Photoshop Elements. Searched the web, but came up with nothing.
    I have used Configurator to build extensions for Photoshop CS6 & CC, but can find anything on Elements.
    Thanks in advance for your help - Sam

    Hi Sam,
    Thanks for getting in touch. I'm afraid this isn't the right place to ask, either - this forum is for Adobe Exchange, which doesn't currently support Photoshop Elements specifically.
    I'd suggest asking your questions in the Photoshop Elements forum (http://forums.adobe.com/community/photoshop_elements), the Photoshop Scripting forum (http://forums.adobe.com/community/photoshop/photoshop_scripting) or contacting technical support.
    Best wishes,
    Fraser

  • Spring Console extension for weblogic 10.0

    Hi,
    I am trying to configure spring console extension for weblogic version 10.0 . As mentioned in some documents, I am unable to find the required jars in the server lib folder, and googled to download it, but yet no success. If any one is aware of where can I get the required jars and steps to configure spring console for version10.0, let me know.
    Thanks

    Hi
    To my surprise, When i asked my Server team to get me weblogic support, I got a response from them stating that weblogic will not support spring framework 2.5 and they sent me the link
    http://download.oracle.com/docs/cd/E13196_01/platform/suppconfigs/configs100/100_over/overview.html#1131715
    And asked me to downgrade my project to the supported version.
    But I think it is not correct, I don't have information if really my local team contacted weblogic support, or they are just sending me this link based on the document they have.
    But I don't understand why it is so hard to get this thing working. Is there many people facing this issue ?
    Or every one using apache Axis2 or CFX for web service and spring webservice is not advised ?
    Some time I don't know whom should be blamed.
    Thanks

  • IPv6 ACL doesn't accept /128 prefix?

    When I was configuring IPv6 ACL with "permit ipv6 any host ff05::1000" (muticast group), there was error message saying ""%Error: Group prefix must be less than 128, skipping FF05::1000/128". The ACL showed in the running-config as "permit ipv6 any host FF05::1000", but the ACL entry had no hits at all (not functioning).
    It was a 2800 router running 12.4(24)T2. Does this mean /128 prefix or host can't be configured in IPv6 ACL?
    Thanks

    I've checked on 15.2(3)T. There's no problem.
    GH2_R2(config)#ipv6 access-listGH2_R2(config)#ipv6 access-list TESTGH2_R2(config-ipv6-acl)#permit ipv6 any hoGH2_R2(config-ipv6-acl)#permit ipv6 any host ff05::1000GH2_R2(config-ipv6-acl)#do sh hist  ipv6 access-list TEST  permit ipv6 any host ff05::1000  do sh histGH2_R2(config-ipv6-acl)#  
    Do you have that list applied anywhere? (PIM or such?)
    M.

  • IPv6 ACLs for ZBFW with changing IPv6 prefix?

    Hi all
    Is there a trick to keep IPv6 ACLs for ZBFW working when the IPv6 prefix will change ?
    Background:
    6RD based residential internet access.
    Provider has a /28 6RD-Prefix, and will append the whole 32bits of the DHCP assigned public IPv4 address, leaving a /60 to use at home. Inside should be subnet 0, DMZ should be subnet 1 from that /60.
    A few of my DMZ IPv6 hosts should be reachable from the outside world on specific udp/tcp ports, without having to open the whole DMZ subnet towards the IPv6 internet.
    No big deal, one would think...
    zone security Z-INTERNET
     description * the outside world *
    zone security Z-DMZ
    zone security Z-OUTSIDE
    zone-pair security ZP-OUTSIDE-TO-DMZ source Z-OUTSIDE destination Z-DMZ
     service-policy type inspect PMAP-INBOUND-TRAFFIC
    policy-map type inspect PMAP-INBOUND-TRAFFIC
     class type inspect CMAP-IN-TRACE-TRAFFIC
      pass
     class type inspect CMAP-IN-INSPECT-TRAFFIC
      inspect 
     class class-default
      drop log
    class-map type inspect match-any CMAP-IN-TRACE-TRAFFIC
     match access-group name ACLv6-ICMP-UNREACH   <-- some ICMP listed in this ACL, irrelevant here
    class-map type inspect match-any CMAP-IN-INSPECT-TRAFFIC
     match access-group name ACLv6-INBOUND-TRAFFIC 
    Now.. what would I put into ACLv6-INBOUND-TRAFFIC? Manually setting...
    ipv6 access-list ACLv6-INBOUND-TRAFFIC
     sequence 10 permit tcp any host <MYcurrent6RDPREFIX>1::<$MYHOSTID> eq http
    ... works well, until MY6currentRDPREFIX becomes MYnew6RDPREFIX. It does so seldomly, but it does, especially after outages.
    For adressing (and re-adressing) the DMZ interface, "ipv6 general prefix MY6RDPREFIX 6rd tunnel6" helps a lot and it works pretty well.
    However, one cannot seem to make use of "ipv6 general prefix" in an ipv6 ACL, neither as source nor destination (and neither when defining a stateful DHCPv6 server, for that matter).
    router6rd(config-ipv6-acl)#permit ip any ?
      X:X:X:X::X/<0-128>  IPv6 destination prefix x:x::y/<z>
      any                 Any destination prefix
      host                A single destination host
    router6rd(config-ipv6-acl)#
    D'oh. What now?
    I do know that scanning the whole /64 would take aeons to complete, but I would like to use predetermined addresses with SLAAC and stateless DHCPv6 (with the help of http://man7.org/linux/man-pages/man8/ip-token.8.html).
    Opening the entire subnet makes me cringe, even more since these hosts are bound to be in some public DNS as well. For that matter, it becomes largely irrelevant if the Host-ID comes from ip-token, EUI-64, RFC7217 or privacy extensions (allright, the latter wouldn't quite apply here, I know.)
    Am I caught in the "IPv6 is like IPv4 but with longer addresses" trap? Should I just do away with my wish to have only the given DMZ servers reachable, and open up the entire subnet? 
    Or: Is there a completely different way of doing ZBFW things in IPv6 that I didn't think of?
    thanks for your thoughts and ideas.
    Marc

    Hi all
    Is there a trick to keep IPv6 ACLs for ZBFW working when the IPv6 prefix will change ?
    Background:
    6RD based residential internet access.
    Provider has a /28 6RD-Prefix, and will append the whole 32bits of the DHCP assigned public IPv4 address, leaving a /60 to use at home. Inside should be subnet 0, DMZ should be subnet 1 from that /60.
    A few of my DMZ IPv6 hosts should be reachable from the outside world on specific udp/tcp ports, without having to open the whole DMZ subnet towards the IPv6 internet.
    No big deal, one would think...
    zone security Z-INTERNET
     description * the outside world *
    zone security Z-DMZ
    zone security Z-OUTSIDE
    zone-pair security ZP-OUTSIDE-TO-DMZ source Z-OUTSIDE destination Z-DMZ
     service-policy type inspect PMAP-INBOUND-TRAFFIC
    policy-map type inspect PMAP-INBOUND-TRAFFIC
     class type inspect CMAP-IN-TRACE-TRAFFIC
      pass
     class type inspect CMAP-IN-INSPECT-TRAFFIC
      inspect 
     class class-default
      drop log
    class-map type inspect match-any CMAP-IN-TRACE-TRAFFIC
     match access-group name ACLv6-ICMP-UNREACH   <-- some ICMP listed in this ACL, irrelevant here
    class-map type inspect match-any CMAP-IN-INSPECT-TRAFFIC
     match access-group name ACLv6-INBOUND-TRAFFIC 
    Now.. what would I put into ACLv6-INBOUND-TRAFFIC? Manually setting...
    ipv6 access-list ACLv6-INBOUND-TRAFFIC
     sequence 10 permit tcp any host <MYcurrent6RDPREFIX>1::<$MYHOSTID> eq http
    ... works well, until MY6currentRDPREFIX becomes MYnew6RDPREFIX. It does so seldomly, but it does, especially after outages.
    For adressing (and re-adressing) the DMZ interface, "ipv6 general prefix MY6RDPREFIX 6rd tunnel6" helps a lot and it works pretty well.
    However, one cannot seem to make use of "ipv6 general prefix" in an ipv6 ACL, neither as source nor destination (and neither when defining a stateful DHCPv6 server, for that matter).
    router6rd(config-ipv6-acl)#permit ip any ?
      X:X:X:X::X/<0-128>  IPv6 destination prefix x:x::y/<z>
      any                 Any destination prefix
      host                A single destination host
    router6rd(config-ipv6-acl)#
    D'oh. What now?
    I do know that scanning the whole /64 would take aeons to complete, but I would like to use predetermined addresses with SLAAC and stateless DHCPv6 (with the help of http://man7.org/linux/man-pages/man8/ip-token.8.html).
    Opening the entire subnet makes me cringe, even more since these hosts are bound to be in some public DNS as well. For that matter, it becomes largely irrelevant if the Host-ID comes from ip-token, EUI-64, RFC7217 or privacy extensions (allright, the latter wouldn't quite apply here, I know.)
    Am I caught in the "IPv6 is like IPv4 but with longer addresses" trap? Should I just do away with my wish to have only the given DMZ servers reachable, and open up the entire subnet? 
    Or: Is there a completely different way of doing ZBFW things in IPv6 that I didn't think of?
    thanks for your thoughts and ideas.
    Marc

  • Best practice for IPv6 ACL on 6500

    Hi,
    I am trying to implement IPv6 ACL on Cisco 6500.
    Any suggestion for the example of the good IPv6 ACL for 6500 would be appreciated.
    Thank you
    Salja

    Salja,
    Example of config can be found here:
    http://www.cisco.com/c/en/us/td/docs/security/fwsm/fwsm31/configuration/guide/fwsm_cfg/exampl_f.html#wpxref44215
    Configuring IPv6 Access Lists
    Configuring an IPv6 access list is similar configuring an IPv4 access, but with IPv6 addresses.
    To configure an IPv6 access list, perform the following steps:
    Step 1 Create an access entry. To create an access list, use the ipv6 access-list command to create entries for the access list. There are two main forms of this command to choose from, one for creating access list entries specifically for ICMP traffic, and one to create access list entries for all other types of IP traffic.
    •To create an IPv6 access list entry specifically for ICMP traffic, enter the following command:
    hostname(config)# ipv6 access-list id [line num] {permit | deny} icmp source
    destination [icmp_type]
    •To create an IPv6 access list entry, enter the following command:
    hostname(config)# ipv6 access-list id [line num] {permit | deny} protocol source
    [src_port] destination [dst_port]
    The following describes the arguments for the ipv6 access-list command:
    •id—The name of the access list. Use the same id in each command when you are entering multiple entries for an access list.
    •line num—When adding an entry to an access list, you can specify the line number in the list where the entry should appear.
    •permit | deny—Determines whether the specified traffic is blocked or allowed to pass.
    •icmp—Indicates that the access list entry applies to ICMP traffic.
    •protocol—Specifies the traffic being controlled by the access list entry. This can be the name (ip, tcp, or udp) or number (1-254) of an IP protocol. Alternatively, you can specify a protocol object group using object-group grp_id.
    •source and destination—Specifies the source or destination of the traffic. The source or destination can be an IPv6 prefix, in the format prefix/length, to indicate a range of addresses, the keyword any, to specify any address, or a specific host designated by host host_ipv6_addr.
    •src_port and dst_port—The source and destination port (or service) argument. Enter an operator (lt for less than, gt for greater than, eq for equal to,neq for not equal to, or range for an inclusive range) followed by a space and a port number (or two port numbers separated by a space for the rangekeyword).
    •icmp_type—Specifies the ICMP message type being filtered by the access rule. The value can be a valid ICMP type number (from 0 to 155) or one of the ICMP type literals as shown in "Addresses, Protocols, and Ports". Alternatively, you can specify an ICMP object group using object-group id.
    Step 2 To apply the access list to an interface, enter the following command:
    hostname(config)# access-group access_list_name {in | out} interface if_name
    HTH
    Regards
    Inayath

  • Cisco Catalyst 6500 version 12.2(33)SXI13 configured as DHCP server for a VLAN responds to Windows 7 client with status code NOA

    Can anyone help figure out why the Catalyst 6509 is not able to assign an IPv6 address? Thank you.
    Cisco Catalyst 6500 version 12.2(33)SXI13 configured as DHCP server for a VLAN responds to Windows 7 client with status code NOADDRS-AVAIL(2). My configuration on the 6500 for the DHCPv6 server is:
    ipv6 dhcp database disk0://DHCPV6-DB
    ipv6 dhcp pool VLAN206IPV6
     prefix-delegation pool VLAN206IPV6-POOL
     dns-server 2620:B700:0:1001::53
     domain-name global.bio.com
    ipv6 local pool VLAN206IPV6-POOL 2620:B700:0:12C7::/65 65
    interface Vlan206
     description *** IPv6 Subnet ***  
     ip address 10.2.104.2 255.255.255.0
     ipv6 address 2620:B700:0:12C7::2/64
     ipv6 nd prefix 2620:B700:0:12C7::/64 14400 14400 no-autoconfig
     ipv6 nd managed-config-flag
     ipv6 dhcp server VLAN206IPV6
     standby version 2
     standby 0 ip 10.2.104.1
     standby 0 preempt
     standby 6 ipv6 2620:B700:0:12C7::1/64
     standby 6 preempt
    I'm getting a result from my debug as follows:
    Apr 10 16:28:02.873 PDT: %LINK-3-UPDOWN: Interface GigabitEthernet2/2, changed state to up
    Apr 10 16:28:02.873 PDT: %LINK-SP-3-UPDOWN: Interface GigabitEthernet2/2, changed state to up
    Apr 10 16:28:02.877 PDT: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet2/2, changed state to up
    Apr 10 16:28:03.861 PDT: IPv6 DHCP: Received SOLICIT from FE80::5D5E:7EBD:CDBF:2519 on Vlan206
    Apr 10 16:28:03.861 PDT: IPv6 DHCP: detailed packet contents
    Apr 10 16:28:03.861 PDT:   src FE80::5D5E:7EBD:CDBF:2519 (Vlan206)
    Apr 10 16:28:03.861 PDT:   dst FF02::1:2
    Apr 10 16:28:03.861 PDT:   type SOLICIT(1), xid 8277025
    Apr 10 16:28:03.861 PDT:   option ELAPSED-TIME(8), len 2
    Apr 10 16:28:03.861 PDT:     elapsed-time 101
    Apr 10 16:28:03.861 PDT:   option CLIENTID(1), len 14
    Apr 10 16:28:03.861 PDT:     00010001195FD895F01FAF10689E
    Apr 10 16:28:03.861 PDT:   option IA-NA(3), len 12
    Apr 10 16:28:03.861 PDT:     IAID 0x0FF01FAF, T1 0, T2 0
    Apr 10 16:28:03.861 PDT:   option UNKNOWN(39), len 32
    Apr 10 16:28:03.861 PDT:   option VENDOR-CLASS(16), len 14
    Apr 10 16:28:03.861 PDT:   option ORO(6), len 8
    Apr 10 16:28:03.861 PDT:     DOMAIN-LIST,DNS-SERVERS,VENDOR-OPTS,UNKNOWN
    Apr 10 16:28:03.861 PDT: IPv6 DHCP: Option IA-NA(3) is not supported yet
    Apr 10 16:28:03.861 PDT: IPv6 DHCP: Sending ADVERTISE to FE80::5D5E:7EBD:CDBF:2519 on Vlan206
    Apr 10 16:28:03.861 PDT: IPv6 DHCP: detailed packet contents
    Apr 10 16:28:03.861 PDT:   src FE80::21D:E6FF:FEE4:4400
    Apr 10 16:28:03.861 PDT:   dst FE80::5D5E:7EBD:CDBF:2519 (Vlan206)
    Apr 10 16:28:03.861 PDT:   type ADVERTISE(2), xid 8277025
    Apr 10 16:28:03.861 PDT:   option SERVERID(2), len 10
    Apr 10 16:28:03.865 PDT:     00030001001DE6E44400
    Apr 10 16:28:03.865 PDT:   option CLIENTID(1), len 14
    Apr 10 16:28:03.865 PDT:     00010001195FD895F01FAF10689E
    Apr 10 16:28:03.865 PDT:   option STATUS-CODE(13), len 15
    Apr 10 16:28:03.865 PDT:     status code NOADDRS-AVAIL(2)
    Apr 10 16:28:03.865 PDT:     status message: NOADDRS-AVAIL

    Hello,
    maybe hitting the following bug.
    Pv6 Address Assignment Support for IPv6 DHCP Server
    CSCse81385
    Hope this helps

  • Extensions for windows intune

    Hi,
    I am trying to config MDM with SCCM + Intune, when i go to "Extensions for Windows Intune" in sccm console there is nothing in the middle pane, says "no items found". Product version is SCCM 2012 R2 and after seeing this applied CU
    2 as well but no luck. Appreciate your help.
    Regards,
    Kanishka.

    Consensus is that it takes about 3 beers for the plugins to show up after configuring the connector.
    I hope that helps,
    Nash
    Nash Pherson, Senior Systems Consultant
    Now Micro -
    My Blog Posts
    If you found a bug or want the product to work differently,
    share your feedback.
    <-- If this post was helpful, please click the up arrow or propose as answer.

  • HTMLB Mobile Extensions for Pocket PC JSP development

    Hi,
    Can you use HTMLB without using an iView (Portal Component)?
    There is an SAP tutorial at http://help.sap.com/saphelp_nw04s/helpdata/en/87/7b583c2439e66fe10000000a114084/content.htm
    which describes HTMLB Mobile Extensions for Java. There is some demo source code which uses a JSP to embed a table control - this table control has a different format depending on the browser (ie Pocket PC, WAP etc).
    The jsp code has the following at the top..
    <%@ page import="com.sapportals.htmlb.,com.sap.mobile.htmlb.rendering., com.sapportals.htmlb.table.TableView,com.sapportals.htmlb.event.*" %>
    <%@ taglib uri="htmlb.tld" prefix="hbj" %>
    But does not explain how the tag library is configured within a web.xml file. There are other examples where HTMLB is used within a Portal Component (iView)and in these cases the portalapp.xml file has the reference to
    <property name="tagLib" value="/SERVICE/htmlb/taglib/htmlb.tld"/>
    .. but what if you're not using an iview? What if you want to use 'straight' J2EE/JSP or something else?
    There seems to be a contradiction here because if you write an application as an iView it can not even be viewed from within a Pocket PC browser! So how do you use HTMLB without using an iView?
    I would just like to know how to use HTMLB controls in an application that can be used on a PDA?
    Thanks
    Adam

    Hi Adam,
    since you're talking about 'straight' J2EE/JSP application, I guess you should opt for the standard way of using tabligs in J2EE web apps. Have a look at <a href="http://help.sap.com/saphelp_nw04/helpdata/en/dd/9a7005444a2d478edcc986ef10dd52/frameset.htm">these</a> pages for more info about how to configure tabligs on the Web AS.
    Hope that helps!

  • IPv6 Multicast support for service providers 6PE / 6VPE

    Hi,
    Can anyone comment on the current state of development for IPv6 Multicast support for Service Providers who are using 6PE or 6VPE in their MPLS core.
    (6PE - SP is running MPLS in its IPv4 core, it uses IPv6-enabled provider edge (PE) routers to transport IPv6 traffic over an IPv4-only enabled core. 6PE does not support VPN,s it just provides a mechanism for tunneling IPv6 packets from ingress PE to egress PE routers)
    (6VPE - refers to a PE router capable of supporting IPv6 VPNs. A 6VPE solution can be used to provide IPv6 based layer 3 VPN services in a similar way to IPv4 based Layer 3 VPN services.)
    My understanding is that 6PE and 6VPE solution are unable to support IPv6 multicast traffic.
    Any further information on configuration, design or development work in the pipeline would be gratefully received,
    kind regards John

    Hi John,
    From our question I understand you are sking about the MVPN support for IPv6 multicast. It is actually supported on the XR platform as of now. Please refer:
    http://www.cisco.com/en/US/docs/routers/xr12000/software/xr12k_r4.0/multicast/configuration/guide/mc40mcst.html#wp2890031
    I hope this helps.
    Regards,
    Ruchir

  • Adobe Air native extension for admob

    Dear Adobe Team,
    We have recently purchased Adobe Air native extension for admob for android & ios
    but every time we upload our app to an ipad or iphone, the app crashes.
    We have carefully followed your instructions, and we're sure we've not made a mistake writing the action script 3 code.
    We need your help in solving this problem urgently, as we are now running behind schedule in uploading our app.
    Thanks very much,
    Amir Steklov and Dorit Leshnick

    Before I was also searched a lot to find good  add network and also Admob.
    Finally we done successfull integration using..  working fine in all IOS devices. not yet released to Apple app store
    http://code.google.com/p/flash-air-admob-ane-for-ios/source/browse/trunk/admobaneiphone/sr c/admobtest.as?r=2
    You can check our add setups using Air ANE's for our android game ExpressTrain.
    https://play.google.com/store/apps/details?id=air.timuzsolutions.expresstrain&feature=sear ch_result#?t=W251bGwsMSwyLDEsImFpci50aW11enNvbHV0aW9ucy5leHByZXNzdHJhaW4iXQ..
    you no need to buyAdobe Air ANE's everything is free but all u need to do is googling,
    hope this will help.
    Bala
    Message was edited by: vamsibalu

  • Configuring double invoice check for vendor invoices posted through FB60

    Dear all
    Can anyone tell me how to configure double invoice check for vendor invoices posted through FB60.
    for miro documents..we can use Tcode OMRDC
    Is there any such tcode which can be used for configuring fi invoices for double checking..
    regards
    Expertia

    Dear Expertia,
    In FI,when checking for duplicated invoices, the system compares the
    following :Vendor, currency, company code, gross amount of the invoice,
    reference document number and Invoice document date.
    SAP Note 305201 clarifies this in a more details; please read it.
    The following fields must be identical for Duplicate invoice check
         Company code                              (BUKRS)
         Vendor number                             (LIFNR)
         Currency                                  (WAERS)
         Reference number                          (XBLNR)
         Amount in document currency               (WRBTR)
         Document date                             (BLDAT)
    If the document is having any one of the above filed different then the
    system does not consider it as a duplicate invoice.
    Also It will check duplicate invoice check in vendor master data and
    in posting key is there check box selected for sales related
    The setting you making in OMRDC i.e Materials management->Logistics
    Invoice Verification->Incoming Invoice ->Set Check for Duplicate
    Invoices is only valid for MM and not  FI invoices posted via FB60/FB65
    You should check the F1 help on field "Chk double inv." (LFB1-REPRF)
    in the relevant vendor master record (transaction FK03).
    Please also check, that message F5 117 has been set correctly in the
    IMG using this path:
    Financial Accounting -> Financial Accounting Global Settings ->
    Document -> Default Values for Document Processing -> Change Message
    Control for Document Control For Document Processing
    Finally & mainly, go to the relevant posting key is defined as sales
    related in transaction OB41. You have to flag this field if the
    duplicate invoice check should work.
    I hope this helps You.
    mauri

  • Configure plain http adapter for receiving message from an external system

    Hi,
    we use Pi/700.
    Now I have an external system and I have to use HTTP (plain) to send messages to XI (via plain http adapter).
    I have no experiences with HTTP!
    In the external system I can only configure "URL, Username, Password" for sending messages - that's all!
    What do I have to configure in XI (communication channel, abap-stack, java-stack,...)?
    I don't know the URL of my XI-system. Is there an transaction code to get this information?
    Why do I need a Username/Pasword?
    For testing I can use a "http-post test tool" I found here in this forum.
    Thank you all for any help!
    Regards
    Wolfgang

    Hi Hummel,
    In Exteranl System u have to use these values
    name="myhost"      value="xiserver"
    name="myport"      value="8000"
    name="mysystem"    value="XY_BSservice"
    name="myinterface" value="Order_out"
    name="mynamespace" value="urn:xi:hcl:powebapp"
    name="myqos"       value="BE"
    name="myclient"    value="300"
    name="myuser"      value="XYZCLNT"
    name="mypass"      value="xiuser"
    Here My system is the Business service created in Integration directory of XI, Interface is the one created in Integration Repository (This is Outbaound from external sys to XI)
    In XI U have to create
    Data Types : 1) Source Structure data type(from extenal sys)
                 2) Target structure (where u want to send from XI)
    Message Types : 2 with above DT's
    Message Interface: 1) Outbound, Async (Order_out)
                       2) Inbound , Async (for the target sys)
    Then Message mapping and Interface mapping as usual..
    And in ID u have to create 2 services one is XY_BSservice for sending system and the other is for receiving system...
    For sending system no communication channel required...
    Hope u will get idea from the above..
    Need any further u r welcome..
    Regards
    Sridhar

Maybe you are looking for

  • Random Shutdown in 2010 for a 2006 Macbook

    Hello- I have a 2006 Macbook 1.83 GHz processor and I never had the whole random shutdown problem previously... it burned through batteries like nothing and I was about to install my third hard drive, but no random shutdown problems. Well, now I have

  • IPhone 3G no longer appears in My Computer...can't get to my pictures!

    I've been searching everywhere for a solution to this problem. No one seems to be sure what to do. I've poured over the Apple Forums, Microsoft Fix It, etc. No good. Hopefully someone else has figured this out and can help me. My iPhone 3G no longer

  • What's Happening Web Part not showing number of discussions on Community Site

    Hello, I have the What's Happening Web Part on the landing page of a community site in SharePoint 2013 Enterprise On-Premises. The What's Happening Web Part shows number of members and discussion replies correctly, but does not show any discussions.

  • Lenovo Miix 2-8 GPS problem no location

    None of the maps can locate me on my new Miix 2. The let windows and apps use my location is turned on?  Any solutions? Solved! Go to Solution.

  • Scaling this beast

    Hi, I want to know if Re: DB file sequential read is really a very peculiar, cazy, brainsick and bizarre server.. I wish to give a few more bits of information about this, those like the number of users connected to it during normal and peak times, t