Wanguard 6.2 User Guide
Appendix 4 – Network Integration Guideline for Wanguard Filter
The following terminology is used:
●
Divert-from
router
– The router from which traffic, initially intended for the victim, is diverted towards
Filter
(e.g.
IBR
) – this router has to receive a redirect-prefix via BGP
●
Inject-to router
– The router where
Filter
will forward the cleaned traffic towards the attacked
destinations (IP-Victims)
●
Next-hop router
– The router that is usually the next-hop to the destinations according to the routing-
table on the
Divert-from router
before traffic diversion is activated.
Figure-1.
Logical Diagram for an Enterprise Network – how traffic diversion works
From a configuration point of view the following steps have to be performed:
1. Configure
traffic-diversion
using BGP as the signaling method
2. Configure an appropriate clean
traffic-injection
method to send clean traffic back on the network to be
forwarded towards the victim
BGP Configuration Guideline
This section provides a general guideline for BGP configuration on the
Filter
server and on a
Divert-from
- 113 -
Содержание wanguard 6.2
Страница 1: ......