User`s guide

Configuring IP Broadcast Settings
Matrix DFE Series and N-SA User’s Guide 7-15
Enabling or Disabling IP Directed Broadcasts
Directedbroadcastsarenetworkorsubnetbroadcastpacketswhicharesenttoarouterfor
forwarding.TheycanbemisusedtocreateDenialofService(DoS)attacks.Bydefault,theMatrix
DFESeriesorNSAdeviceprotectsagainstthispossibilitybynotforwardingdirectedbroadcasts.
However,dependingonyournetwork
requirements,youmaywanttoenablethisfunction.
Frominterfaceconfigurationmode,usethiscommandtoenable IPdirectedbroadcastsonan
interface:
ip directed-broadcast
Usethis“no”formofthecommandtogloballydisableIPdirectedbroadcasts:
no ip directed-broadcast
Configuring UDP Broadcast Forwarding
Typically ,broadcastpacketsfromoneinterfacearenotforwarded(routed)toanotherinterface.
However,someapplicationsuseUDPbroadcaststodetecttheavailabilityofservices,and
protocols,suchasBOOTP/DHCP,requirebroadcastforwardingtoprovideservicestoclientson
othersubnets.ConfiguringUDPbroadcastforwardingontheMatrixDFESeriesor
NSAdevice
involvesenablingit,enablingDHCP/BootPrelay,andassigninganIP“helperaddress”as
describedinthissection.
Enabling or Disabling UDP Broadcast Forwarding
Fromglobalconfigurationmode,usethiscommandtoenableUDPbroadcastforwardingandto
specifythe protocolsforwhichUDPwillforwardservices:
ip forward-protocol {udp [port | protocol]}
TheportvariablespecifiesadestinationportthatcontrolswhichUDPservicesareforwarded.
Ifnotspecified,theMatrixDFESeriesorNSAdevicewillforwarddefaultservicesusingthe
defaultportslistedinTable 75.Specifyingaprotocolkeywordwillenableonlyitsserviceon
thedefaultport
listed.
Table 7-5 Default UDP Forwarding Services
Protocol Keyword Service Default UDP Port
bootps Bootstrap Protocol Server 67
bootpc Bootstrap Protocol Client 68
domain Domain Name Service 53
nameserver EN-116 Name Service 42
netbios-dgm NetBIOS datagram service 138
netbios-ns NetBIOS name service 137
tacacs Terminal Access Controller Access Control
System
49
tftp Trivial File Transfer Protocol 69
time Time Service 37