08-Security Command Reference

HomeSupportSwitchesH3C S5130 Switch SeriesReference GuidesCommand ReferencesH3C S5130-HI Command References-R1118P02[R1122]-6W10208-Security Command Reference
15-uRPF commands
Title Size Download
15-uRPF commands 31.35 KB

uRPF commands

display ip urpf

Use display ip urpf to display uRPF configuration.

Syntax

display ip urpf [ slot slot-number ]

Views

Any view

Predefined user roles

network-admin

network-operator

Parameters

slot slot-number: Specifies an IRF member device. The slot number argument specifies the ID of the IRF member device.

Examples

# Display uRPF configuration.

<Sysname> display ip urpf

Global uRPF configuration information:

   Check type: strict

   Allow default route

Table 1 Command output

Field

Description

Global uRPF configuration information

Global uRPF configuration.

(failed)

Failed to deliver the uRPF configuration to the forwarding chip because of insufficient chip resources. If this field does not exist, the delivery is successful.

Check type

uRPF check mode: loose or strict.

Allow default route

Allow use of the default route.

 

ip urpf

Use ip urpf to enable uRPF.

Use undo ip urpf to disable uRPF.

Syntax

ip urpf { loose | strict }

undo ip urpf

Default

uRPF is disabled.

Views

System view

Predefined user roles

network-admin

Parameters

loose: Enables loose uRPF check. To pass loose uRPF check, the source address of a packet must match the destination address of a FIB entry.

strict: Enables strict uRPF check. To pass strict uRPF check, the source address and receiving interface of a packet must match the destination address and output interface of a FIB entry.

Usage guidelines

Global uRPF configuration takes effect on both IPv4 and IPv6 routes.

uRPF can be deployed on a PE connected to a CE or another ISP, or on a CE.

Configure strict uRPF check on a PE interface connected to a CE, and configure loose uRPF check on a PE interface connected to another ISP.

For asymmetrical routing where the interface receiving upstream traffic is different from the interface forwarding downstream traffic on a PE device, configure loose uRPF to avoid discarding valid packets. If the two interfaces are the same (symmetrical routing), configure strict uRPF. An ISP usually adopts symmetrical routing on a PE device.

Examples

# Enable strict uRPF check globally.

<Sysname> system-view

[Sysname] ip urpf strict

Related commands

display ip urpf

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Intelligent Storage
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
  • Technical Blogs
All Support
  • Become A Partner
  • Partner Policy & Program
  • Global Learning
  • Partner Sales Resources
  • Partner Business Management
  • Service Business
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网