Generalized ttl security mechanism support – Brocade BigIron RX Series Configuration Guide User Manual

Page 1009

Advertising
background image

BigIron RX Series Configuration Guide

931

53-1002484-04

Generalized TTL security mechanism support

27

Syntax: show ip bgp neighbor <address>

Generalized TTL security mechanism support

The BigIron RX supports the Generalized TTL Security Mechanism (GTSM) as defined in RFC 3682.
GTSM provides a means of protecting the Brocade device from attacks where invalid BGP control
traffic is sent to the device in order to overload the CPU or hijack the BGP session. GTSM protection
applies to EBGP neighbors only.

When GTSM protection is enabled, BGP control packets sent by the Brocade device to its neighbor
have a Time To Live (TTL) value of 255. In addition, the Brocade device expects the BGP control
packets received from the neighbor to have a TTL value of either 254 or 255. For multihop peers
(where the ebgp-multihop option is configured for the neighbor) the Brocade device expects the TTL
for BGP control packets received from the neighbor to be greater than or equal to 255, minus the
configured number of hops to the neighbor. If the BGP control packets received from the neighbor
do not have the anticipated value, they are dropped by the Brocade device.

For more information on GTSM protection, see RFC 3682.

To enable GTSM protection for neighbor 192.168.9.210, enter the following command.

BigIron RX(config-bgp-router)# neighbor 192.168.9.210 ebgp-btsh

BigIron RX# show ip bgp neighbor 11.11.11.2

1 IP Address: 11.11.11.2, Remote AS: 101 (EBGP), RouterID: 101.101.101.1

Local AS: 200

State: ESTABLISHED, Time: 0h18m15s, KeepAliveTime: 60, HoldTime: 180

KeepAliveTimer Expire in 44 seconds, HoldTimer Expire in 167 seconds

RefreshCapability: Received

GracefulRestartCapability: Received

Restart Time 120 sec, Restart bit 0

afi/safi 1/1, Forwarding bit 0

GracefulRestartCapability: Sent

Restart Time 30 sec, Restart bit 0

afi/safi 1/1, Forwarding bit 0

Messages: Open Update KeepAlive Notification Refresh-Req

Sent : 1 5 15 0 0

Received: 1 1 15 0 0

Last Update Time: NLRI Withdraw NLRI Withdraw

Tx: --- --- Rx: --- ---

Last Connection Reset Reason:Unknown

Notification Sent: Unspecified

Notification Received: Unspecified

Neighbor NLRI Negotiation:

Peer Negotiated IPV4 unicast capability

Peer configured for IPV4 unicast Routes

TCP Connection state: ESTABLISHED

TTL check: 0, value: 0, rcvd: 64

Byte Sent: 628, Received: 363

Local host: 11.11.11.1, Local Port: 8190

Remote host: 11.11.11.2, Remote Port: 179

ISentSeq: 2123652 SendNext: 2124281 TotUnAck: 0

TotSent: 629 ReTrans: 1 UnAckSeq: 2124281

IRcvSeq: 2300094 RcvNext: 2300458 SendWnd: 65000

TotalRcv: 364 DupliRcv: 0 RcvWnd: 65000

SendQue: 0 RcvQue: 0 CngstWnd: 1460

Advertising