
WANGUARD 5.2 User Manual & Administrator's Guide
Appendix 3 – Configuring Traffic Diversion
This appendix describes how to confgure trafc diversion for Filter. Informaton provided here regarding
router confguratons is for informatonal purposes only. Please refer to the appropriate router user guides for
detailed informaton.
Understanding the BGP Diversion Method
Following standard Border Gateway Protocol (BGP) routng defnitons, routers select the routng path with
the longest matching prefx (also known as the “most specifc”). Afer establishing a BGP session with the router,
Filter sends a routng update where the Filter system is listed as the best path for the atacked destnatons.
The network prefx that Filter announces is longer than the one already listed in the router’s routng table,
overriding the router's routng table defniton.
To confgure trafc diversion in Layer 2 or Layer 3 network topologies, perform the following:
1. Confgure trafc diversion using BGP
2. Confgure the appropriate trafc forwarding method
The fgure above provides an example of trafc diversion from Ingress Router 1,2,3 towards a Linux server
running the Filter sofware.
- 67 -
Содержание Wanguard 5.2
Страница 1: ......