SNR S2989G-24TX-POE — настройка IP-сервисов и маршрутизации в сетевых устройствах [176/553]

Превью страниц Страница 176 / 553
SNR S2989G-24TX-POE [176/553] Ip route aggregation configuration task
S2989G-24TX Operation Manual
Chapter 3 IP services Configuration
3-14
enabling/disabling optimization to adjust generation of network route entry in the switch
chip and view statistics for IP forwarding and hardware forwarding chip status.
3.3.2
IP Route Aggregation Configuration Task
IP route aggregation configuration task:
1. Set whether IP route aggregation algorithm with/without optimization should be used
1. Set whether IP route aggregation algorithm with/without optimization should be
used
3.4
URPF
3.4.1
Introduction to URPF
URPF (Unicast Reverse Path Forwarding) introduces the RPF technology applied in
multicast to unicast, so to protect the network from the attacks which is based on source
address cheat.
When switch receives the packet, it will search the route in the route table using the
source address as the destination address which is acquired from the packet. If the found
router exit interface does not match the entrance interface acquired from this packet, the
switch will consider this packet a fake packet and discard it.
In Source Address Spoofing attacks, attackers will construct a series of messages
with fake source addresses. For applications based on IP address verification, such
attacks may allow unauthorized users to access the system as some authorized ones, or
even the administrator. Even if the response messages can’t reach the attackers, they will
also damage the targets.
Command
Explanation
Global Mode
ip fib optimize
no ip fib optimize
Enables the switch to use optimized IP
route aggregation algorithm; the no ip fib
optimize disables the optimized IP route
aggregation algorithm.

Содержание

666

Изучите, как настраивать IP-сервисы, оптимизацию маршрутов и защиту от атак с подменой адреса. Полное руководство по конфигурации и управлению сетевыми устройствами.