ZXR10 8900E series Core Switch Product Description
68
© 2013ZTE CORPORATION. All rights reserved.
ZTE Confidential Proprietary
to find out if the interface in forwarding table corresponding to the source address
matches the incoming interface. If not, the source address is considered spoofing, and
the packet will be dropped. In this way, malicious attack launched by modifying the
source address can be stopped.
ZXR10 8900E series swith supports three types of uRPFs, i.e. strict, loose and
loose-ingoring-default-route.
Strict mechanism strictly searches for outgoing port and incoming port as per source
address. If they do not match, the packet will be dropped. If they match, process it
normally.
Loose mechanism enables route search as per the source address. If the default
route egress is the same as the ingress, process the packet normally. Otherwise,
discard it.
Loose-ignoring-default-route ignores default route. If the route can be found by the
source address, and it is not the default route, it will be processed normally.
Otherwise, it will be dropped.
3.8.5.3
ND Security
The introduction of IPv6 can not solve the security issue in original IPv4 network. Some
IPv6 network security problems are also aroused by IPv6 protocol. In IPv6, ND (Neighbor
Discovery) protocol is similar to ARP protocol in IPv4. It resolutes MAC address, and
realizes automatic IP address distribution in non status. ND protocol mainly consists of
RS, RA, NS and NA protocols. RS and RA messages are used to get IP address prefix,
and NS/NA messages are used to get neighbor MAC address. So ND protocol also has
IP address prefix spoofing and MAC address spoofing issues.
ZXR10 8900E supports router trusted port. Trustable router address and restricted ND
learning number can be configured. ND message filtering based upon ND snooping is
supported. It supports the binding relationship between static IP address,l MAC, VLAN
and port. Also, based upon DHCP IPv6 snooping entry, ND message can be inspected.
Only legal messages can be allowed to pass.
3.9
Network Traffic Analysis
3.9.1
Sflow
sFlow service is mainly composed by three parts: sFlow message sampling unit, sFlow
agent unit and sFlow collector(e.g. analyzer). The entire system architecture is as shown
in Figure 3-28.
Summary of Contents for ZXR10 8900E series
Page 1: ...Operator Logo ZXR10 8900E series Core Switch Product Description ...
Page 2: ......
Page 10: ......