Cisco Systems 7600 SERIES Configuring Unicast Reverse Path Forwarding, Configuring Unicast RPF

Page 19

Chapter 23 Configuring Network Security

Configuring Unicast Reverse Path Forwarding

Configuring Unicast Reverse Path Forwarding

These sections describe configuring Cisco IOS Unicast Reverse Path Forwarding (Unicast RPF):

Understanding Unicast RPF Support, page 23-19

Configuring Unicast RPF, page 23-19

Enabling Self-Pinging, page 23-19

Configuring the Unicast RPF Checking Mode, page 23-20

Understanding Unicast RPF Support

The PFC2 supports Unicast RPF with hardware processing for packets that have a single return path. The MSFC2 processes traffic in software that has multiple return paths (for example, load sharing).

With a PFC2, if you configure Unicast RPF to filter with an ACL, the PFC2 determines whether or not traffic matches the ACL. The PFC2 sends the traffic denied by the RPF ACL to the MSFC2 for the Unicast RPF check.

Note

Because the packets in a denial-of-service attack typically match the deny ACE and are sent to the

 

 

MSFC2 for the unicast RPF check, they can overload the MSFC2.

 

The PFC2 provides hardware support for traffic that does not match the Unicast RPF ACL, but that

 

 

does match an input security ACL.

 

 

 

With Supervisor Engine 1 and PFC, the MSFC or MSFC 2 supports Unicast RPF in software.

Configuring Unicast RPF

For configuration procedures, refer to the Cisco IOS Security Configuration Guide, Release 12.1, “Other Security Features,” “Configuring Unicast Reverse Path Forwarding” at this URL:

http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_c/scprt5/scdrpf.htm

Enabling Self-Pinging

With Unicast RPF enabled, the router cannot ping itself. To enable self-pinging, perform this task:

 

Command

Purpose

Step 1

 

 

Router(config)# interface {{vlan vlan_ID}

Selects the interface to configure.

 

{type1 slot/port} {port-channelnumber}}

 

Step 2

 

 

Router(config-if)#ip verify unicast source

Enables the router to ping itself or a secondary address.

 

reachable-via any allow-self-ping

 

 

Router(config-if)#no ip verify unicast source

Disables self-pinging.

 

reachable-via any allow-self-ping

 

Step 3

 

 

Router(config-if)# exit

Exits interface configuration mode.

 

 

 

1.type = ethernet, fastethernet, gigabitethernet, or tengigabitethernet

 

 

Cisco 7600 Series Router Cisco IOS Software Configuration Guide—12.1E

 

 

 

 

 

 

78-14064-04

 

 

23-19

 

 

 

 

 

Image 19
Contents This chapter consists of these sections ACL Configuration Guidelines23-1 23-2 Hardware and Software ACL Support23-3 Determining Layer 4 Operation Usage23-4 Configuring the Cisco IOS Firewall Feature SetDetermining Logical Operation Unit Usage More detailed example follows23-5 Cisco IOS Firewall Feature Set Support OverviewGuidelines Firewall Configuration Guidelines and RestrictionsConfiguring Cbac on Cisco 7600 Series Routers Restrictions23-7 Configuring MAC Address-Based Traffic Blocking23-8 Configuring Vlan ACLsUnderstanding VACLs Vacl OverviewIgmp packets are not checked against VACLs VACLs and Cbac cannot be configured on the same interfaceBridged Packets Same interface23-10 Routed Packets23-11 Configuring VACLsThese sections describe configuring VACLs Multicast Packets23-12 Vacl Configuration OverviewDefining a Vlan Access Map To define a Vlan access map, perform this task23-13 Configuring a Match Clause in a Vlan Access Map SequenceConfigures the match clause in a Vlan access map sequence Deletes the match clause in a Vlan access map sequenceApplying a Vlan Access Map Configuring an Action Clause in a Vlan Access Map Sequence23-14 Vlan Access Map Configuration and Verification Examples Verifying Vlan Access Map Configuration23-15 23-16 Configuring a Capture Port23-17 Configuring Vacl Logging23-18 Configuring TCP InterceptEnabling Self-Pinging Configuring Unicast Reverse Path ForwardingConfiguring Unicast RPF Understanding Unicast RPF Support23-20 Configuring the Unicast RPF Checking ModeThis example shows how to verify the configuration Configuring Unicast Flood Protection23-21 23-22 Configuring MAC Move Notification23-23 23-24
Related manuals
Manual 74 pages 38.06 Kb