< Home

Configuring Attack Defense Against IP Packets with the Route Record Option

Generally, an IP route record option is to diagnose faults on network paths, but may also be utilized by malicious attackers to probe the network structure.

Context

The IP routing technology provides the route record option, which records the route that an IP packet takes from the source IP address to the destination IP address. The route record option is a list of routers that process the IP packet. The route record option is generally used for fault diagnosis of network paths, but may also be used by malicious attackers to probe the network structure.

After the attack defense against IP packets with the route record option is configured, the device checks whether packets entering the router contain the route record option. If yes, the packets are discarded.

Procedure

  1. In the user view, access the system view.

    system-view

  2. Enable attack defense against IP packets with route record option.

    firewall defend route-record enable

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >