Urpf Configuration Example - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Table 14 MPUs and LPUs
MPU model
LSU1SUPA
NOTE:
If the number of routes on any preceding card exceeds half the routing table size, the URPF function cannot
be enabled to avoid loss of routes and packets.
For more information about the route extension mode, see Fundamentals Configuration Guide.

URPF configuration example

Network requirements
As shown in
check on Switch A and Switch B to prevent source address spoofing attacks.
Figure 107 Network diagram
Configuration procedure
1.
Enable strict URPF check on Switch A.
<SwitchA> system-view
[SwitchA] ip urpf strict
2.
Enable strict URPF check on Switch B.
<SwitchB> system-view
[SwitchB] ip urpf strict
LPU model
SC LPU (with the last two letters of the LPU
model being SC, such as LSU1TGS16SC)
SE LPU (with the last two letters of the LPU
model being SE, such as LSU1TGS8SE)
EA LPU (with the last two letters of the LPU
model being EA, such as LSU1GP48EA)
EB LPU (with the last two letters of the LPU
model being EB, such as LSU1GP48EB)
SF LPU (with the last two letters of the LPU
model being SF, such as LSU1TGS48SF)
Figure
107, a client (Switch A) directly connects to an ISP switch (Switch B). Enable strict URPF
272
Half reduction of routing table size
occurs on...
SC LPU, SE LPU, SF LPU, and MPU
EA LPU and EB LPU not operating
in the route extension mode

Advertisement

Table of Contents
loading

Table of Contents