Configuring Ip Performance Optimization; Enabling Receiving And Forwarding Of Directed Broadcasts To A Directly Connected Network; Enabling Receiving Of Directed Broadcasts; Enabling Forwarding Of Directed Broadcasts - HP 10500 Series Configuration Manual

Layer 3 - ip services
Hide thumbs Also See for 10500 Series:
Table of Contents

Configuring IP performance optimization

This chapter describes multiple features for IP performance optimization.
The term "interface" in the IP performance optimization features collectively refers to Layer 3 interfaces,
including VLAN interfaces and Layer 3 Ethernet interfaces. You can set an Ethernet port as a Layer 3
interface by using the port link-mode route command (see Layer 2—LAN Switching Configuration
Guide).
Enabling receiving and forwarding of directed
broadcasts to a directly connected network
A directed broadcast packet is destined for all hosts on a specific network. In the destination IP address
of the directed broadcast, the network ID identifies the target network, and the host ID is made up of all
ones.
If a device is allowed to forward directed broadcasts to a directly connected network, hackers can
exploit this vulnerability to attack the target network. However, this feature must be enabled for UDP
Helper, which converts broadcasts to unicasts and forwards them to a specific server.

Enabling receiving of directed broadcasts

If a device is enabled to receive directed broadcasts, the device determines whether to forward them
according to the configuration on the outgoing interface.
To enable the device to receive directed broadcasts:
Step
Enter system view.
1.
2.
Enable the device to receive
directed broadcasts.

Enabling forwarding of directed broadcasts

Follow these guidelines when you enable forwarding of directed broadcasts:
If an ACL is referenced in the ip forward-broadcast command, only packets permitted by the ACL
can be forwarded.
If you execute the ip forward-broadcast command multiple times on an interface, the most recent
configuration takes effect. If the command executed last does not include acl acl-number, the ACL
configured previously is removed.
To enable the device to forward directed broadcasts:
Step
1.
Enter system view.
Command
system-view
ip forward-broadcast
Command
system-view
94
Remarks
N/A
Disabled by default.
Remarks
N/A
Table of Contents
loading

Table of Contents