uRPF configuration example for interfaces
Network requirements
As shown in Figure 212, perform the following tasks:
Configure strict uRPF check on GigabitEthernet 1/0/1 of Router B and permit packets from network 10.1.1.0/24.
Configure strict uRPF check on GigabitEthernet 1/0/1 of Router A and allow using the default route for uRPF check.
Figure 207: Network diagram
Configuration procedure
Configure Router B:
# Configure ACL 2010 to permit traffic from network 10.1.1.0/24.
<RouterB> system-view [RouterB] acl basic 2010 [RouterB-acl-ipv4-basic-2010] rule permit source 10.1.1.0 0.0.0.255 [RouterB-acl-ipv4-basic-2010] quit
# Specify an IP address for GigabitEthernet 1/0/1.
[RouterB] interface gigabitethernet 1/0/1 [RouterB-GigabitEthernet1/0/1] ip address 1.1.1.2 255.255.255.0
# Configure strict uRPF check on GigabitEthernet 1/0/1.
[RouterB-GigabitEthernet1/0/1] ip urpf strict acl 2010
Configure Router A:
# Specify an IP address for GigabitEthernet 1/0/1.
<RouterA> system-view [RouterA] interface gigabitethernet 1/0/1 [RouterA-GigabitEthernet1/0/1] ip address 1.1.1.1 255.255.255.0
# Configure strict uRPF check on GigabitEthernet 1/0/1 and allow using the default route for uRPF check.
[RouterA-GigabitEthernet1/0/1] ip urpf strict allow-default-route