5.13 Improving Security of an OSPF Network
On a network demanding high security, you can adopt the GTSM mechanism and configure
OSPF authentication to improve the security of the OSPF network.
5.13.1 Before You Start
Before improving the security of an OSPF network, familiarize yourself with the usage scenario,
complete pre-configuration tasks, and obtain the required data. This can help you complete the
configuration task quickly and accurately.
Applicable Environment
In a network demanding high security, you can configure OSPF authentication and adopt the
GTSM mechanism to improve the security of the OSPF network.
The GTSM mechanism defends against attacks by checking the TTL value. If an attacker keeps
sending packets to a router by simulating real OSPF unicast packets, the router finds itself is the
destination of the packets after the interface board receives these packets. The router directly
sends the packets to the control plane for OSPF processing without checking the validity of the
packets. The router busies itself with processing these "valid" packets. As a result, the system
is busy, and the CPU is highly occupied.
The GTSM mechanism protects a router by checking whether the TTL value in the IP packet
header is in a pre-defined range to enhance the system security.
NOTE
l
NE80E/40E supports IPv4 OSPF GTSM.
l
GTSM supports only unicast addresses; therefore, in OSPF, GTSM takes effect on the virtual link and
the sham link.
Pre-configuration Tasks
Before improving the security of an OSPF network, complete the following tasks:
l
Configuring IP addresses for interfaces to make neighboring nodes reachable
l
Configuring Basic OSPF Functions
Data Preparation
To improve the security of an OSPF network, you need the following data.
No.
Data
1
OSPF process ID
2
(Optional) Names of VPN instances of OSPF
3
(Optional) TTL value to be checked
4
ID of an OSPF area that needs to be configured with authentication
HUAWEI NetEngine80E/40E Router
Configuration Guide - IP Routing
5 OSPF Configuration
Issue 02 (2014-09-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
333