Got it

URPF Design

Latest reply: Dec 27, 2018 12:31:42 983 5 10 0 0

URPF prevents network attacks based on source address spoofing and can be performed in strict or loose mode.

Unicast Reverse Path Forwarding (URPF) is a technology used to defend against network attacks based on source address spoofing.

Generally, upon receiving a packet, a router first obtains the destination IP address of the packet and then searches the forwarding table for a route to the destination address. If the router finds such a route, it forwards the packet; otherwise, it discards the packet. A URPF-enabled router, however, obtains the source IP address of a received packet and searches for a route to the source address. If the router fails to find the route, it considers that the source address is a forged one and discards the packet. In this manner, URPF can effectively protect against malicious attacks that are launched by changing the source addresses of packets.

URPF works by enabling a device to verify the reachability of the source address in a received packet. If the source IP address is unreachable, the packet is discarded.

In a complex network environment, URPF cannot work normally in the case of asymmetrical routes.

To counteract the problem, the NE9000 supports two URPF modes:

l   Strict mode

l   Loose mode

Strict mode

In strict URPF mode, a data packet can pass the URPF check only when the forwarding table contains a matching entry and the outbound interface of the entry matches the inbound interface of the packet.

Loose mode

In loose URPF mode, a packet can pass the URPF check as long as there is a route with the destination address that is the source address of the packet, regardless of whether the outbound interface of the route and the inbound interface of the packet match.

For this project, we can configure the loose mode on the link which is connect between the CE and PE, PE and P, because there one routing maybe have multi-link.

For the interface which connect the end user, if there only have single link, we can enable the strict mode.

The configuration example is as below:

Table 1-1 URPF Configuration

#

interface interface-type interface-number

ip urpf{ loose | strict } [ allow-default] [ statistics enable ]

commit

#


  • x
  • convention:

xiaomumu
Created Dec 22, 2018 08:35:05

niceURPF Design-2827701-1
View more
  • x
  • convention:

YOO
Created Dec 22, 2018 08:36:01

It is very helpful for the learner in the first stage.can you add more picture?
View more
  • x
  • convention:

JoneSnow
Created Dec 22, 2018 08:38:10

any other devices support URPF modes ?
View more
  • x
  • convention:

Yolanda_617
Created Dec 22, 2018 09:39:24


It is very helpful
View more
  • x
  • convention:

user_2915719
Created Dec 27, 2018 12:31:42

Is this function only supported by high level range routers, or it's supported by entry level routers like some AR series?
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.
Information Protection Guide
Thanks for using Huawei Enterprise Support Community! We will help you learn how we collect, use, store and share your personal information and the rights you have in accordance with Privacy Policy and User Agreement.