Chapter17URPFConguration
Note:
Instep1,theparametersaredescribedbelow.
�StrictmeansthatifegressportfoundbysourceIPaddressis
differentfromdataingressport,itwillbediscarded;otherwise
itwillbeprocessedinprimaryway.
�LoosemeansthatifsourceIPaddresscanndroute,and
egressportandingressportofdefaultroutearecoincident,it
willbeprocessedinthenormalway,otherwiseitwillbedis-
carded.
�Loose-ingoring-default-routemeansthatifsourceIPad-
dresscanndrouteandtherouteisnotbydefault,itwillbe
processedinthenormalway.Otherwiseitwillbediscarded.
URPFConfiguration
Example
URPFnetworktopologyisshowninFigure39.
FIGURE39URPFCONFIGURATIONEXAMPLE
StrictURPFisconguredoninterfacefei_1/2onS1soastopre-
venttheusersbehindnetwork192.168.0.0/24frommaliciously
attackingnetworksbehindS1.
CongurationonS1:
ZXR10(config)#interfacefei_1/2
ZXR10(config-if)#swacvlan10
ZXR10(config-if)#ipverifystrict
ZXR10(config-if)#exit
ZXR10(config)#intvlan10
ZXR10(config-if)#ipaddress192.168.0.1255.255.255.0
CondentialandProprietaryInformationofZTECORPORATION159