Checking The Configuration - Huawei S6700 Series Configuration Manual

Ip routing
Hide thumbs Also See for S6700 Series:
Table of Contents

Advertisement

S6700 Series Ethernet Switches
Configuration Guide - IP Routing
l
----End

8.13.4 Checking the Configuration

After BGP4+ network security is configured, you can check authentication information of BGP4
+ peers.
Prerequisites
The configurations for BGP4+ security are complete.
Procedure
l
l
l
Issue 01 (2012-03-15)
The range of TTL values of packets is [ 255-hops+1, 255 ]. By default, the value of
hops is 255. That is, the valid TTL range is [ 1, 255 ]. For example, for the direct
EBGP route, the value of hops is 1. That is, the valid TTL value is 255.
After the BGP4+ GTSM policy is configured, an interface board checks the TTL
values of all BGP4+ packets. According to the actual networking requirements, you
can configure GTSM to discard or process the packets that do not match the GTSM
policy. If you configure GTSM to discard the packets that do not match the GTSM
policy by default, you can configure the range of finite TTL values according to the
network topology; therefore, the interface board directly discards the packets with the
TTL value not in the configured range. Thus, the attackers cannot simulate valid BGP4
+ packets to occupy CPU resources.
Performing the Default GTSM Action
Do as follows on the switch configured with GTSM:
1.
Run:
system-view
The system view is displayed.
2.
Run:
gtsm default-action { drop | pass }
The default action is configured for the packets that do not match the GTSM policy.
By default, the packets that do not match the GTSM policy can pass the filtering.
NOTE
If only the default action is configured and the GTSM policy is not configured, GTSM does
not take effect.
Run the display gtsm statistics all command to check the statistics of GTSM.
Run the display gtsm statisticsall command. You can view GTSM statistics on each board,
including the total number of BGP4+ packets, the total number of OSPF packets, the
number of packets that match the GTSM policy, and the number of discarded packets.
Run the display bgp ipv6 peer ipv6-address verbose command to check information about
BGP4+ GTSM.
Run the display bgp group [ group-name ] command to check GTSM of a BGP4+ peer
group.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
8 BGP4+ Configuration
540

Advertisement

Table of Contents
loading

Table of Contents