Configuring Urpf - Huawei AR1200-S Configuration Manual

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
The AR1200-S supports the following types of URPF check modes:
l
l

8.3 Configuring URPF

This section describes how to configure URPF.
Applicable Environment
Users on an enterprise network are often attacked by unauthorized users on other network
segments when they use applications demanding IP address-based authentication. An attacker
sends bogus packets with the IP address of an authorized user to a server to access the server.
As a result, the authorized user cannot access the server or the authorized user information is
intercepted. To prevent such an attack, configure URPF on the AR1200-S.
As shown in
RouterA. URPF strict check is configured on GE1/0/0 and GE2/0/0.
PC A on Network 1 sends a bogus packet with the source IP address 2.2.2.2 to the server on
Network 3. After RouterA receives this packet, it checks the inbound interface. Packets with the
source address 2.2.2.2 must reach Network 3 through GE2/0/0 but not GE1/0/0. Therefore,
RouterA considers the packet as a bogus packet and discards it. This protects PC B on Network
2 against IP address spoofing attacks initiated from PC A.
Packets sent from Network 2 to the server pass the URPF check and are forward normally.
Packets sent from VLAN 10 to the server pass the URPF check and are forward normally.
Figure 8-2 URPF application
Issue 02 (2012-03-30)
Strict check: Packets can pass the check only when the FIB table of the AR1200-S has a
corresponding routing entry with the destination address being the source address of the
packet and the inbound interface of the packets matches the outbound interface in the
routing entry. Unmatched packets are discarded.
Loose check: A packet can pass the check as long as the FIB table of the AR1200-S has a
routing entry with the destination address being the source address of the packet.
Figure
8-2, Network 1 and Network 2 are connected to GE1/0/0 and GE2/0/0 of
Network1
PC A
1.1.1.1/24
URPF
enabled
Network2
PC B
2.2.2.2/24
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Eth1/0/0
RouterB
Eth2/0/0
RouterA
8 IP Address Anti-spoofing Configuration
Network3
Server
3.3.3.3/24
164

Advertisement

Table of Contents
loading

Table of Contents