Chapter21IPv6URPFConguration
interface<interface-name>:nameoftheinterfacewheretheIPv6URPFfunctionis
congured.
ignore-default-route:Itisonlyavailableforloosemode.
2.Verifythecongurations.
CommandFunction
ZXR10#showrunning-configurpf[all]DisplaysalltheURPFcongurations.
ZXR10#showrunning-config-interface
<interface-name>[all]
DisplaysURPFcongurationofa
speciedinterface.
–EndofSteps–
21.3IPv6URPFCongurationInstances
21.3.1Example:ConfiguringIPv6URPF(Strict)
CongurationDescription
AsshowninFigure21-1,strictURPFisconguredfortheinterfacegei-2/1onR1,which
preventsthenetworkuserscomingfromthenetworksegmentbefore1:1::ad:ea/64from
attackingthenetworkconnectingtoR1,andpermitsthedataowfromthenetwork
segment1:11::ad:ea/64topassthroughURPFinspection.
Figure21-1TopologyofIPv6URPFCongurationExample(Strict)
CongurationFlow
1.CongureIPv6addressfortheinterface.
2.CreateACL,addtheACLmatchingrequirements.Forexample,permitthetrafc
comingfrom1:11::ad:ea/64topass.
3.BindstrictIPv6URPFwithACLlisttotheinterface.
CongurationCommands
ThecongurationofR1isasfollows:
R1(config)#interfacegei-2/1
R1(config-if-gei-2/1)#noshutdown
R1(config-if-gei-2/1)#ipv6enable
R1(config-if-gei-2/1)#ipv6address1:1::ad:ea/64
21-3
SJ-20140504150128-018|2014-05-10(R1.0)ZTEProprietaryandCondential