Cisco Systems OL-4580-01 Switch User Manual


 
6-7
Cisco Content Services Switch Routing and Bridging Configuration Guide
OL-4580-01
Chapter 6 Configuring the Internet Protocol
Configuring an IP Source Route
Configuring an IP Source Route
To enable the CSS to process frames with information that overrides the default
routing, use the ip source-route command. For example:
(config)# ip source-route
Caution Enabling the ip source-route command may pose a major security risk to your
network. The IP source route specifies information that overrides the default
routing a packet would normally take. The packet could then bypass a firewall. If
this poses a problem, avoid using the ip source-route command.
The CSS does not load balance TCP or UDP packets with IP options that are
destined to a VIP address. These packet types are dropped and the CSS returns an
ICMP destination/port unreachable error. This behavior exists regardless of the
state (enabled or disabled) of the ip source-route and ip record-route
commands.
The CSS, however, does respond to ICMP packets that are destined to a VIP
address. The CSS also responds to TCP or UDP packets that include IP options
that are destined to a local circuit address, or require that a routing decision be
made.
To disable the processing of frames with the IP source-route option (the default
behavior), enter:
(config)# no ip source-route
Configuring the IP Record Route
To enable the CSS to process frames with the IP address of each router along a
path, use the ip record-route command. For example:
(config)# ip record-route
Caution Enabling the ip record-route command could pose security risks to your network.
The ip record-route command inserts the IP address of each router along a path
into the IP header.