Ip Address Anti-Spoofing Overview - Huawei AR1200-S Configuration Manual

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security

8.1 IP Address Anti-spoofing Overview

This function defends against source address spoofing attacks.
Source IP address spoofing attacks often occur on the Internet. An attacker sends a packet
carrying the IP address of an authorized user to a server to access the server. As a result, the
authorized user cannot use network services or the authorized user information is intercepted.
To defend against such an attack, the AR1200-S provides Unicast Reverse Path Forwarding
(URPF).
URPF
When the AR1200-S receives a packet, it searches for the route to the destination address of the
packet. If the route is found, the AR1200-S forwards the packet. Otherwise, the AR1200-S
discards the packet. After URPF is configured, the AR1200-S obtains the source address and
inbound interface of the packet. The AR1200-S takes the source address as the destination
address to retrieve the corresponding outbound interface in the FIB and compares the retrieved
interface with the inbound interface. If they do not match, the AR1200-S considers the source
address as a spoofing address and discards the packet. URPF can effectively protect the AR1200-
S against malicious attacks by blocking packets from bogus source addresses.
As shown in
RouterC to RouterB. RouterB sends response packets to the real source address 2.1.1.1.
RouterB and RouterC are attacked by the bogus packets.
If URPF is enabled on an interface of RouterB, when RouterB receives bogus packets, it detects
that the packets should not come from RouterA's interface and discards these bogus packets.
Figure 8-1 URPF
1.1.1.1/24
RouterA
8.2 IP Source Address-based Attack Defense Features
Supported by the AR1200-S
This section describes the IP source address-based attack defense features supported by the
AR1200-S.
URPF
URPF takes effect only on Layer 3 inbound interfaces of the AR1200-S. If URPF is enabled on
an interface, the URPF check is conducted on packets received by the interface.
Issue 02 (2012-03-30)
Figure
8-1, RouterA sends bogus packets carrying the source address 2.1.1.1 of
2.1.1.1/24
Source address
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
8 IP Address Anti-spoofing Configuration
RouterB
2.1.1.1/24
RouterC
163

Advertisement

Table of Contents
loading

Table of Contents