Home > ccie resources > BGP Updates Based On Nlri

Protocol Filtering and Controlling LAN Floods

Attackers can cause broadcast floods to disrupt communications over the LAN. You saw an example of this in the section "MAC Address Floods and Port Security." Therefore, it is important to control flooding on the switches. There are two main ways to do this: Set up threshold limits for broadcast/multicast traffic on ports Use protocol filtering to limit broadcasts/multicasts for certain protocols Catalyst switches allow thresholds for broadcast traffic to be set up on a pe..

Policy Routing Based on Traffic Source

Consider the example shown in Figure 8-6. Assume that AS1 was assigned network numbers from two different providers. The 10.10.10.0/24 range was taken from AS3, and the 11.11.11.0/24 range was taken from AS4. AS1 wants to have any traffic originated from its 10.10.10.0/24 networks to be directed toward AS3 and traffic from its 11.11.11.0/24 networks to be directed to AS4, irrespective of the traffic's final destination. AS1 could use policy routing to achieve this requirement..

Restricting What Log Messages Are Sent to the Server

Use the logging trap configuration command to limit the severity level of syslog messages: Router#configure terminal Enter configuration commands, one per line.  End with CNTL/Z. Router(config)#logging host 172.25.1.1 Router(config)#logging trap notifications Router(config)#end Router# By default, when you enable remote logging on a router, it will forward only those messages with a severity level informational or higher. This means that the router forwards everything ..

Requirements for PPP over Frame Relay

The Request for Comments (RFC) document number 1661 (known as RFC 1661) outlines PPP as an industry standard protocol that supports router-to-router or host-to-network connections between point-to-point links. As a successor to the Serial Line Internet Protocol (SLIP), PPP was designed to work with several different network layer protocols, such as IP, IPX, and SNA. Unlike PPP, the legacy SLIP only supports IP. PPP has added security features, such as Challenge Handshake Aut..

Rewriting the Network Prefix

Sometimes you need to connect your network to another network that uses an unregistered range, such as 172.16.0.0/16. However, if you already use this range in your network, the easiest thing to do is to simply replace this prefix with another one that doesn't have a conflict, such as 172.17.0.0/16: Router#configure terminal Enter configuration commands, one per line.  End with CNTL/Z. Router(config)#ip nat outside source static network 172.16.0.0 172.17.0.0 /16 no-al..

Contact Us

86-136-2222-6316
CALL ME NOW

© 2011 CathaySchool, an ANDA Technology Group company, All Rights ReservedPrivacy Policy | Refund Policy | Disclaimer | Sitemap | Resources Tags