![Zte ZXR10 8900 Series Скачать руководство пользователя страница 171](http://html.mh-extra.com/html/zte/zxr10-8900-series/zxr10-8900-series_user-manual_941741171.webp)
Chapter 17 URPF Configuration
Note:
In step 1, the parameters are described below.
�
Strict
means that if egress port found by source IP address is
different from data ingress port, it will be discarded; otherwise
it will be processed in primary way.
�
Loose
means that if source IP address can find route, and
egress port and ingress port of default route are coincident, it
will be processed in the normal way, otherwise it will be dis-
carded.
�
Loose-ingoring-default-route
means that if source IP ad-
dress can find route and the route is not by default, it will be
processed in the normal way. Otherwise it will be discarded.
URPF Configuration
Example
URPF network topology is shown in
Figure 39
.
F
IGURE
39 URPF C
ONFIGURATION
E
XAMPLE
Strict URPF is configured on interface fei_1/2 on S1 so as to pre-
vent the users behind network 192.168.0.0/24 from maliciously
attacking networks behind S1.
Configuration on S1:
ZXR10(config)#interface fei_1/2
ZXR10(config-if)#sw ac vlan 10
ZXR10(config-if)#ip verify strict
ZXR10(config-if)#exit
ZXR10(config)#int vlan 10
ZXR10(config-if)#ip address 192.168.0.1 255.255.255.0
Confidential and Proprietary Information of ZTE CORPORATION
159