Configuring Ip Directed Broadcast (Cli Procedure) - Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual

For ex series ethernet switches
Table of Contents

Advertisement

Disabling Unicast RPF (CLI Procedure)
Related
Documentation

Configuring IP Directed Broadcast (CLI Procedure)

Copyright © 2010, Juniper Networks, Inc.
Unicast reverse-path forwarding (RPF) can help protect your LAN from denial-of-service
(DoS) and distributed denial-of-service (DDoS) attacks on untrusted interfaces. Unicast
RPF filters traffic with source addresses that do not use the incoming interface as the
best return path back to the source. If the network configuration changes so that an
interface that has unicast RPF enabled becomes a trusted interface or becomes
asymmetrically routed (the interface that receives a packet is not the best return path
to the packet's source), disable unicast RPF.
To disable unicast RPF on an EX3200 or EX4200 switch, you must delete it from every
interface on which you explicitly configured it. If you do not disable unicast RPF on every
interface on which you explicitly enabled it, it remains implicitly enabled on all interfaces.
If you attempt to delete unicast RPF from an interface on which it was not explicitly
enabled, the message
warning: statement not found
RPF on every interface on which you explicitly enabled it, unicast RPF remains implicitly
enabled on all interfaces of the EX3200 or EX4200 switch.
On EX8200 switches, the switch does not apply unicast RPF to an interface unless you
explicitly enable that interface for unicast RPF.
To disable unicast RPF, delete its configuration from the interface:
[edit interfaces]
user@switch# delete ge-1/0/10 unit 0 family inet rpf-check
NOTE: On EX3200 and EX4200 switches, if you do not disable unicast RPF
on every interface on which you explicitly enabled it, unicast RPF remains
implicitly enabled on all interfaces.
Example: Configuring Unicast RPF on an EX Series Switch on page 1274
Verifying Unicast RPF Status on page 1349
Configuring Unicast RPF (CLI Procedure) on page 1339
Understanding Unicast RPF for EX Series Switches on page 1249
You can use IP directed broadcast on an EX Series switch to facilitate remote network
management by sending broadcast packets to hosts on a specified subnet without
broadcasting to the entire network. IP directed broadcast packets are broadcast on only
the target subnet. The rest of the network treats IP directed broadcast packets as unicast
packets and forwards them accordingly.
Before you begin to configure IP directed broadcast:
Chapter 58: Configuring Interfaces
displays. If you do not disable unicast
1341

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents