Configuring Gtsm For Ipv6 Bgp - HPE FlexNetwork HSR6800 Configuration Manual

Layer 3-ip routing configuration guide
Hide thumbs Also See for FlexNetwork HSR6800:
Table of Contents

Advertisement

Configuration prerequisites
Before applying an IPsec policy to a peer or peer group, complete the following tasks:
Create an IPsec proposal.
Create an IPsec policy.
For more information about IPsec policy configuration, see Security Configuration Guide.
Configuration procedure
An IPsec policy used for IPv6 BGP can be only in manual mode. For more information, see Security
Configuration Guide.
To apply an IPsec policy to a peer or peer group
Step
Enter system view.
1.
Enter BGP view.
2.
Enter IPv6 address
3.
family view.
Apply an IPsec policy
4.
to a peer or peer group.

Configuring GTSM for IPv6 BGP

If an attacker continuously sends forged IPv6 BGP packets or TCP packets (used to acknowledge
the sending and receiving of IPv6 BGP packets) to a device, the device directly delivers these
packets to the CPU without checking their validity. As a result, the CPU utilization is very high. You
can configure the Generalized TTL Security Mechanism (GTSM) to avoid such CPU-utilization
based attacks.
The GTSM feature allows you to configure a hop-count value to get a valid hop limit range
[255-hop-count+1, 255]. Upon receiving a packet from the specified peer, the device checks whether
the Hop Limit in the IP header falls into the specified range. If yes, the packet is delivered to the CPU;
otherwise, the packet is discarded.
In addition, with GTSM configured, the device will send packets with hop limit 255. Therefore, GTSM
provides the best protection for directly connected EBGP peers because the TTL of packets
exchanged between non-direct EBGP peers or IBGP peers can be modified by other devices.
To configure GTSM for IPv6 BGP:
Step
Enter system view.
1.
Enter BGP view.
2.
Enter IPv6 address
3.
family view.
Configure GTSM to
4.
check IPv6 packets
from the specified IPv6
BGP peer or peer
group.
Command
system-view
bgp as-number
ipv6-family
peer { group-name | ip-address }
ipsec-policy policy-name
Command
system-view
bgp as-number
ipv6-family
peer { group-name | ipv6-address }
ttl-security hops hop-count
367
Remarks
N/A
N/A
N/A
Not configured by default.
Remarks
N/A
N/A
N/A
Not configured by default.

Advertisement

Table of Contents
loading

Table of Contents