本帖最后由 小乔 于 2016-6-20 15:54 编辑
问题描述
NE40E路由器接口GE2/0/0配置URPF(Unicast Reverse Path Forwarding)是单播逆向路径转发检查不生效。
具体配置如下:
<XZIDC_NE40_1>dis curr int gi2/0/0
#
interface GigabitEthernet2/0/0
description TO_FW-1_GigabitEthernet2/0/0
undo shutdown
ip address 111.xxx.xxx.5 255.255.255.252
qppb-policy ip-precedence destination
ospf network-type p2p
ip urpf strict allow-default //配置接口URPF检查
#
测试方法如下:
伪造源地址2.2.2.2从NE40E路由器接口GigabitEthernet2/0/0进入,但是测试数据包被路由正常转发,没有被URPF检查丢弃
关于2.2.2.2的路由表如下:
<XZIDC_NE40_1>dis ip routing-table 2.2.2.2
Route Flags: R - relay, D - download to fib
------------------------------------------------------------------------------
Routing Table : Public
Summary Count : 1
Destination/Mask Proto Pre Cost Flags NextHop Interface
0.0.0.0/0 BGP 20 0 RD 111.11.200.1 GigabitEthernet2/1/0
解决方案
|