Optional) Disabling Urpf For The Specified Traffic; Checking The Configuration - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

5 Source IP Attack Defense Configuration
----End

5.5.4 (Optional) Disabling URPF for the Specified Traffic

Context
After the URPF function is enabled on an interface, the S9300 performs the URPF check on all
traffic passing through the interface. To prevent the packets of a certain type from being
discarded, you can disable the URPF check for these packets. For example, if the S9300 is
configured to trust all the packets from a certain server, the S9300 does not check these packets.
To disable the URPF function, you need to run commands in the traffic behavior view and
associate the traffic behavior and a traffic classifier with a traffic policy.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
traffic behavior behavior-name
A traffic behavior is created and the traffic behavior view is displayed.
Step 3 Run:
ip urpf disable
The URPF function is disabled.
By default, the RUPF function is enabled in a traffic behavior.
After the URPF function is enabled on an interface, the S9300 performs the URPF check on all
traffic passing through the interface. If you need to disable the URPF function, you can run
commands in the traffic behavior view and associate the traffic behavior and a traffic classifier
with a traffic policy. When the traffic policy is applied globally or applied to a board, an interface,
or a VLAN, the S9300 does not perform URPF check on the traffic that match the traffic classifier
rules.
For the configuration procedures of traffic classifier and traffic policy, see Class-based QoS
Configuration in the Quidway S9300 Terabit Routing Switch Configuration Guide - QoS.
----End

5.5.5 Checking the Configuration

5-12
Packets pass URPF check and are forwarded in URPF loose check mode regardless of
whether the outgoing interface of a default route is the same as the incoming interface of
the packets.
NOTE
Only the S9300 installed with an EA/EC/ED LPU supports this function.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents