WANGUARD 5.2 User Manual & Administrator's Guide
neighbor 192.168.1.100 description Filter appliance
neighbor 192.168.1.100 soft-reconfiguration inbound
neighbor 192.168.1.100 distribute-list routesToWANGUARDFilter out
neighbor 192.168.1.100 route-map WANGUARD-Filter-in
no synchronization
!
ip bgp community new-format
ip community-list expanded WANGUARD-Filter permit 1000:64000 no-export no-advertise
!
route-map WANGUARD-Filter-in permit 10
match community WANGUARD-Filter exact match
ip access-list standard routesToWANGUARDFilter
deny any
... ... ... ...
Understanding Traffic Forwarding Methods
This secton provides details on trafc forwarding methods. Trafc forwarding methods are used to forward
the cleaned trafc from the Filter system to a downstream router.
The following terminology is used in this secton:
●
Divert-from router – Router from which the bgpd diverts the atacked destnatons trafc.
●
Inject-to router – Router where bgpd forwards the cleaned trafc towards atacked destnatons.
●
Next-hop router – Router that is the next-hop to the destnatons according to the routng table on the
divert-from router before trafc diversion is actvated.
Static Routing – Layer 2 Forwarding Method
In a Layer 2 topology, the Filter system, divert-from router, and next-hop router are on the same network or
VLAN. In a Layer 2 topology, a divert-from router and an inject-to router are two diferent devices. The next-hop
router and the inject-to router are the same device.
GRE / IP over IP Tunneling – Layer 3 Forwarding Method
In a Layer 3 topology, the divert-from and inject-to routers are the same router (referred to as the router in
this chapter). Filter sends a BGP announcement that modifes the router’s routng table to divert the zone trafc to
the Filter system. Filter cleans the trafc and returns the cleaned trafc to the same router. The divert-from router
then sends the trafc to the router that appears as the best path to the zone. This process may result in a malicious
routng loop. In this case you may have to use a tunnel that is confgured between the Filter system and the next-hop
router to forward clean trafc. The inject-to router does not perform routng decisions according to the zone address
and forwards the packets to the next-hop router.
Configuring Static Routing – Layer 2 Forwarding Method
- 71 -
Summary of Contents for Wanguard 5.2
Page 1: ......