ip verify unicast vrf

Unanswered Question
Oct 28th, 2007

Unicast Reverse Path Forwarding

Unicast Reverse Path Forwarding (Unicast RPF) can be optionally configured. Unicast RPF is used to verify that the source address is in the Forwarding Information Base (FIB). The ip verify unicast vrf command is configured in interface configuration mode and is enabled for each VRF. This command has permit and deny keywords that are used to determine if the traffic is forwarded or dropped.


1. enable

2. configure terminal

3. interface type number [name-tag]

4. ip policy route-map map-tag

5. ip verify unicast vrf vrf-name deny | permit

6. end

How different is this command from :

ip verify unicast source reachable-via any allow-self-ping ( Can this command be used on VRF interfaces)

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
atif-siddiqui Sun, 10/28/2007 - 08:44


1. What is the difference between these two:

IP verify source reachable-via ANY, allow self-ping

145 verification drops

1350294 suppressed verification drops

2. Are there any known issues with NAT and RPF check.


This Discussion