Универсальные интеллектуальные ИТ-решения

dw@donewin.com.hk |

WhatisUnicastReversePathForwarding(uRPF)?Canadefaultroute0.0.0.0/0beusedtoperformauRPFcheck?

Часто задаваемые вопросы о маршрутизаторах CiscoЧасто задаваемые вопросы

Что такое одноадресная переадресация по обратному пути (uRPF)? Может ли маршрут по умолчанию 0.0.0.0/0 использоваться для выполнения проверки uRPF?

Unicast Reverse Path Forwarding, used for preventing source address spoofing, is alook backwardability which allows the router to check and see if any IP packet received at a router interface arrives on the best return path (return route) to the source address of the packet. If the packet was received from one of the best reverse path routes, the packet is forwarded as normal. If there is no reverse path route on the same interface from which the packet was received, the packet is dropped or forwarded, depending on whether an access control list (список управления доступом) is specified in the ip verify unicast reverse-path list interfaceconfiguration command. For more information, refer to the Configuring Unicast Reverse Path Forwardingchapter of the Cisco IOS Security Configuration Guide, Release 12.2.

Default route 0.0.0.0/0 can not be used to perform a uRPF check. Например, if a packet with source address 10.10.10.1 comes on Serial 0 interface and the only route matching 10.10.10.1 is the default route 0.0.0.0/0 pointing out Serial 0 on the router, the uRPF check fails and it drops that packet.

Пред.:

Следующий:

оставьте ответ

Живой чат
Оставить сообщение

    − 1 "=" 4