300-540 · Question #21
An engineer must implement a solution on a Cisco ASR 1000 Series router to protect against DDoS attacks. DDoS traffic must be dropped by transmitting Flowspec attributes to edge routers, instructing…
The correct answer is A. Configure Flowspec for the BGP address-family. Comprehensive and Detailed Explanation BGP Flowspec allows routers to distribute traffic-filtering rules using BGP NLRI. To enable Flowspec, after neighbors are configured, the essential next step is: Activate the Flowspec address-family under BGP router bgp 65000…
Question
An engineer must implement a solution on a Cisco ASR 1000 Series router to protect against DDoS attacks. DDoS traffic must be dropped by transmitting Flowspec attributes to edge routers, instructing them to generate an ACL via class-maps and policy-maps. The engineer already configured BGP neighbors. Which action must be taken next?
Options
- AConfigure Flowspec for the BGP address-family
- BSet the BGP routing process
- CActivate the BGP neighbors
- DConfigure the route reflector
How the community answered
(45 responses)- A80% (36)
- B4% (2)
- C13% (6)
- D2% (1)
Explanation
Comprehensive and Detailed Explanation BGP Flowspec allows routers to distribute traffic-filtering rules using BGP NLRI. To enable Flowspec, after neighbors are configured, the essential next step is: Activate the Flowspec address-family under BGP router bgp 65000 address-family ipv4 flowspec neighbor X.X.X.X activate exit-address-family FlowSpec NLRI exchange Distribution of drop rules (rate-limit, redirect, null route, etc.) Automatic ACL/class-map/policy- map generation on edge routers
Topics
Community Discussion
No community discussion yet for this question.