misc_parameters);
        void *misc_v = MLX5_ADDR_OF(fte_match_param, spec->match_value,
                                    misc_parameters);
+       void *misc_c_3 = MLX5_ADDR_OF(fte_match_param, spec->match_criteria,
+                                   misc_parameters_3);
+       void *misc_v_3 = MLX5_ADDR_OF(fte_match_param, spec->match_value,
+                                   misc_parameters_3);
        struct flow_rule *rule = flow_cls_offload_flow_rule(f);
        struct flow_dissector *dissector = rule->match.dissector;
        u16 addr_type = 0;
              BIT(FLOW_DISSECTOR_KEY_CT) |
              BIT(FLOW_DISSECTOR_KEY_ENC_IP) |
              BIT(FLOW_DISSECTOR_KEY_ENC_OPTS) |
+             BIT(FLOW_DISSECTOR_KEY_ICMP) |
              BIT(FLOW_DISSECTOR_KEY_MPLS))) {
                NL_SET_ERR_MSG_MOD(extack, "Unsupported key");
                netdev_dbg(priv->netdev, "Unsupported key used: 0x%x\n",
                if (match.mask->flags)
                        *match_level = MLX5_MATCH_L4;
        }
+       if (flow_rule_match_key(rule, FLOW_DISSECTOR_KEY_ICMP)) {
+               struct flow_match_icmp match;
 
+               flow_rule_match_icmp(rule, &match);
+               switch (ip_proto) {
+               case IPPROTO_ICMP:
+                       if (!(MLX5_CAP_GEN(priv->mdev, flex_parser_protocols) &
+                             MLX5_FLEX_PROTO_ICMP))
+                               return -EOPNOTSUPP;
+                       MLX5_SET(fte_match_set_misc3, misc_c_3, icmp_type,
+                                match.mask->type);
+                       MLX5_SET(fte_match_set_misc3, misc_v_3, icmp_type,
+                                match.key->type);
+                       MLX5_SET(fte_match_set_misc3, misc_c_3, icmp_code,
+                                match.mask->code);
+                       MLX5_SET(fte_match_set_misc3, misc_v_3, icmp_code,
+                                match.key->code);
+                       break;
+               case IPPROTO_ICMPV6:
+                       if (!(MLX5_CAP_GEN(priv->mdev, flex_parser_protocols) &
+                             MLX5_FLEX_PROTO_ICMPV6))
+                               return -EOPNOTSUPP;
+                       MLX5_SET(fte_match_set_misc3, misc_c_3, icmpv6_type,
+                                match.mask->type);
+                       MLX5_SET(fte_match_set_misc3, misc_v_3, icmpv6_type,
+                                match.key->type);
+                       MLX5_SET(fte_match_set_misc3, misc_c_3, icmpv6_code,
+                                match.mask->code);
+                       MLX5_SET(fte_match_set_misc3, misc_v_3, icmpv6_code,
+                                match.key->code);
+                       break;
+               default:
+                       NL_SET_ERR_MSG_MOD(extack,
+                                          "Code and type matching only with ICMP and ICMPv6");
+                       netdev_err(priv->netdev,
+                                  "Code and type matching only with ICMP and ICMPv6\n");
+                       return -EINVAL;
+               }
+               if (match.mask->code || match.mask->type) {
+                       *match_level = MLX5_MATCH_L4;
+                       spec->match_criteria_enable |= MLX5_MATCH_MISC_PARAMETERS_3;
+               }
+       }
        return 0;
 }