397
Network application
Figure 128
Network diagram
Configure strict URPF between each ISP and its connected users, and loose URPF between ISPs.
Configuring URPF
To configure URPF globally:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable URPF check globally.
ip urpf
{
loose
|
strict
}
Disabled by default
NOTE:
•
The routing table size decreases by half when URPF is enabled on the HP 5500 HI switches.
•
To prevent loss of routes and packets, URPF cannot be enabled if the number of route entries the switch
maintains exceeds half the routing table size.
URPF configuration example
Network requirements
As shown in
, a client (Switch A) directly connects to the ISP switch (Switch B). Enable URPF
check on Switch A and Switch B to prevent source address spoofing attacks.