Urpf configuration example, Network requirements, Configuring device b – H3C Technologies H3C SecPath F1000-E User Manual

Page 36

Advertising
background image

28

URPF configuration example

In this configuration example, either Device A or Device B is the SecPath firewall.

Network requirements

As shown in

Figure 30

, Device A directly connects to Device B. Enable strict URPF check in zone B of

Device B to allow packets whose source addresses match ACL 2010 to pass. Enable strict URPF check in

zone A of Device A to allow use of the default route for URPF check.

Figure 30 Network diagram

Configuring Device B

# Configure the interface IP addresses and security zones they belong to. (Details not shown.)
# Define ACL 2010 to permit traffic from network 10.1.1.0/24 to pass.

Select Firewall > ACL from the navigation tree, click Add, and then perform the following operations,
as shown in

Figure 31

.

Figure 31 Defining ACL 2010

Enter 2010 in ACL Number.

Select Config for Match Order.

Click Apply.

On the ACL list page, click

corresponding to ACL 2010, click Add, and then perform the

following operations, as shown in

Figure 32

.

Advertising