cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1030
Views
10
Helpful
6
Replies

ip verify unicast reverse-path

cisco_lite
Level 1
Level 1

On a router and ASA firewall, should RPF be enabled on all the given interfaces.

2 Accepted Solutions

Accepted Solutions

Jon Marshall
Hall of Fame
Hall of Fame

You should generally apply it at the exit point to your network because within your network you may well have asymmetrical paths. Have a look at this doc which goes into where Unicast RPF should be used -

http://www.cisco.com/en/US/docs/ios/11_1/feature/guide/uni_rpf.html#wp1042716

Jon

View solution in original post

This is my understanding as well.

View solution in original post

6 Replies 6

mikegrous
Level 3
Level 3

typically youd only apply it on your WAN interface as you should be trusting your LAN routes

Jon Marshall
Hall of Fame
Hall of Fame

You should generally apply it at the exit point to your network because within your network you may well have asymmetrical paths. Have a look at this doc which goes into where Unicast RPF should be used -

http://www.cisco.com/en/US/docs/ios/11_1/feature/guide/uni_rpf.html#wp1042716

Jon

What is difference between

ip verify unicast reverse-path

and

ip verify unicast source reachable-via any

What is the default Unicast RPF mode; loose or strict.

Regards.

In reguard to the first question:

R8(config-if)#ip verify unicast ?

reverse-path Reverse path validation of source address (old command format)

source Validation of source address

From this I understand that both of the above commands have the same effect, where in reverse-path is an old command.

Please confirm.

This is my understanding as well.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card