Controlling the Processing of IP Packets Carrying Route Options

By disabling devices from processing IP packets carrying route options, you can effectively defend networks against attacks by sending these packets.

Context

IP packets can carry the following route options:
  • Route alert option

  • Record route option

  • Source route option

  • Timestamp option

These options are used to diagnose link faults and temporarily transmit special services. These options may also be utilized by network attackers to probe the network structure and launch attacks. Therefore, you need to run this command to enable the system to process or disable the system from processing IP packets with route options.

By default, routers process IP packets carrying route options. To defend networks against attacks by sending IP packets carrying route options, disable the system from processing these IP packets.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run any of the following commands based on the route options:

  3. Run commit

    The configuration is committed.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
Next topic >