ZXR10ZSRV2CongurationGuide(IPv6)
LooseRPF
InlooseRPFmode,therouteronlycheckswhetherthesourceIPaddressofthepacket
existsintheroutingtable(normalsourceaddressrouteordefaultroute).Itdoesnotcheck
whethertheingressforreceivingpacketsmatcheswiththecontentoftheroutingtable.In
thisway,URPFcaneffectivelypreventnetworkfromattacks,anditcanalsopreventthe
interceptionoflegaluserpackets.
LooseRPFIgnoringDefaultRoute
Ifadefaultrouteisconguredonthedevice,whenURPFcheckssourceaddresses
accordingtotheroutingtable,thenext-hopinformationofallthesourceaddressescanbe
queried.Inthiscase,youcancongurewhethertoallowURPFtointroducedefaultroute
(ifURPFignoringthedefaultrouteiscongured,URPFdoesnotcheckthedefaultroute).
ACLApplicationinURPF
BymeansofACL,URPFprovidesamoreexiblecustomizationsolution.Whenthe
networkadministratortruststhatthepacketswithsomefeaturesarelegalpackets,hecan
congureACLrulestoforwardthesepacketsproperlythatarenotdiscardedevenifthe
packetslackasourceroute(or,thesourcerouteisdefaultroute,butthedefaultrouteis
disabledinURPF).Thatis,whenURPFcheckfails,thepacketsarepermittedordenied
accordingtotheACLrules.
21.2ConguringIPv6URPF
ThisproceduredescribeshowtoconguretheIPv6URPFfunction.
Steps
1.ConguretheIPv6URPFfunctionontheinterface.
StepCommandFunction
1ZXR10(config)#ipv6verifyunicast
sourcereachable-via{rxinterface
<interface-name>[acl-name<acl-name>]|
anyinterface<interface-name>[acl-name
<acl-name>][ignore-default-route]}
EnablesIPv6URPFfunctiononan
interface.
2ZXR10(config)#interface<interface-name>Entersinterfacecongurationmode.
3ZXR10(config-if-interface-name)#ipv6
verifyunicastsourcereachable-via{rx
[acl-name<acl-name>]|any[acl-name
<acl-name>][ignore-default-route]}
EnablesinterfaceIPv6URPF
functiononaninterfaceconguration
mode.
rx:strictmode.
any:loosemode.
21-2
SJ-20140504150128-018|2014-05-10(R1.0)ZTEProprietaryandCondential