Timeto Live TTL Security Check

TTL Security Check is a security feature implemented in BGP. It helps protect BGP peers from multihop attacks. This feature is based on the Generalized TTL Security Mechanism (GTSM) defined in RFC 3682 and applies only to external BGP (eBGP).

NOTE Several organizations are working to implement this feature for other routing protocols, such as OSPF and EIGRP.

You can configure a minimum acceptable TTL value for the packets exchanged between two eBGP peers when you use the TTL Security Check feature in Cisco IOS. After you enable TTL Security Check, both BGP peers send all their updates with a TTL of 255. In addition, routers establish a peering session only if the other eBGP peer sends packets with a TTL equal to or greater than the TTL value configured for the peering session. By default, eBGP uses a TTL value of 1; the only exception is when eBGP multihop is used.

NOTE If a router receives a packet with TTL values less than the calculated value, it silently discards it.

You can enable the TTL security check by using the neighbor <ip address> ttl-security command as shown in the following example:

Router(config)# router bgp 123

Router(config-router)# neighbor 209.165.200.226 ttl-security hops 3

In this example, TTL security check is enabled for the 209.165.200.226 eBGP neighbor which is three hops away. This router then accepts only BGP packets with a TTL value of 252 or greater.

NOTE For more information about TTL security check, go to http://www.cisco.com/en/US/ products/ps6350/products_configuration_guide_chapter09186a0080455621.html.

Continue reading here: Resource Thresholding Notification

Was this article helpful?

0 0