Port Routing Control; Reverse Path Checking - Avaya 8800 Configuration Manual

Ethernet routing switch
Table of Contents

Advertisement

Routing fundamentals

Port routing control

You can enable or disable routing capabilities on specified switch ports, even if the port is part
of a routed VLAN. For example, when you disable IP routing on a specific port, the IP traffic
that enters that port is not routed to any other interface on the switch.
You can use this feature as a security measure to prevent untrusted VLAN ports from injecting
IP traffic that is destined to be routed by the switch.

Reverse path checking

Reverse path checking prevents packet forwarding for incoming IP packets that have incorrect
or forged (spoofed) IP addresses. Reverse path checking (RPC) guarantees that traffic
received on one interface was sent by a station from this interface (which prevents address
spoofing). With this mode enabled, the Avaya Ethernet Routing Switch 8800/8600 performs a
reverse path check to determine if the packet source IP address is verifiable. If it is not
verifiable, the packet is discarded.
Configure RPC as required for each IP interface. When enabled, the Ethernet Routing Switch
8800/8600 checks all routing packets that enter the interface. RPC ensures that the source
address and source interface appear in the routing table and that the address matches the
interface on which the packet was received.
You can use one of two modes for RPC:
• Exist-only mode: RPC checks whether the source IP address for the incoming packet
exists in the routing table. If the source IP entry is found, the packet is forwarded as usual;
otherwise, the packet is discarded.
• Strict mode: RPC checks that the source IP address exists in the routing table, and is
reachable through the incoming IP interface (and not through any other interface). If these
conditions are not met, the packet is discarded.
For more information about configuring RPC, see Avaya Ethernet Routing Switch 8800/8600
Security, NN46205-601.
RPC operational example
The following example illustrates how strict mode works.
26
Configuration — OSPF and RIP
June 2011

Advertisement

Table of Contents
loading

This manual is also suitable for:

8600

Table of Contents