Network Application - HP VSR1000 Security Configuration Manual

Virtual services router
Table of Contents

Advertisement

If yes, the output interface of the matching route is an InLoop interface. IPv6 uRPF checks
whether the receiving interface of the packet is an InLoop interface. If yes, permits the packet.
If no, proceeds to step 6. If the source address is a link-local address and is the receiving
interface address, also proceeds to step 6.
If no, proceeds to step 4.
4.
IPv6 uRPF checks whether the receiving interface matches the output interface of the matching FIB
entry:
If yes, proceeds to step 5.
If no, IPv6 uRPF checks whether the check mode is loose. If yes, proceeds to step 5. If no,
proceeds to step 6.
5.
IPv6 uRPF checks whether the matching route is a default route:
If yes, IPv6 uRPF checks whether the allow-default-route keyword is configured to allow using
the default route. If yes, the packet is forwarded. If no, proceeds to step 6.
If no, the packet is forwarded.
6.
IPv6 uRPF checks whether the packet is permitted by the IPv6 ACL:
If yes, the packet is forwarded (such a packet is displayed in the uRPF information as a
"suppressed drop").
If no, the packet is discarded.

Network application

Figure 100 Network diagram
Configure strict IPv6 uRPF check between an ISP network and a customer network, and loose IPv6
uRPF check between ISPs.
ISP A
ISP B
IPv6 uRPF (loose)
IPv6 uRPF (strict)
User
332
ISP C

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents