Re: [nsp] 12.0(14)S/new uRPF code

From: Larry Rosenman (ler@lerctr.org)
Date: Sun Jan 07 2001 - 20:24:25 EST


* Basil Kruglov <basil@cifnet.com> [010107 19:20]:
> On Sun, Jan 07, 2001 at 08:08:43PM -0500, Jared Mauch wrote:
> > > Could not find any notes at CCO... is this feature going to work in asymmetric
> > > environment?
> > >
> > > Also, is 12.0.14S+ the only version where this feature available at the
> > > moment?
> >
> > That i'm aware of.
> >
> > The 'ip verify source reachable via any' (or similar) is useful
> > to drop martians.
>
> but is it going to work in asymmetric environment,
> when two or more paths to the src are available, or is it going to drop
> packets the way 'ip verify unicast reverse-path' did? Thanks,
no, the ip verify source reachable via any command only drops if the
IP address isn't in the routing table at all.

See the archives around 12/19/2000 for a pdf file that explains it
nicely.

>
> -Basil

-- 
Larry Rosenman                     http://www.lerctr.org/~ler
Phone: +1 972-414-9812                 E-Mail: ler@lerctr.org
US Mail: 1905 Steamboat Springs Drive, Garland, TX 75044-6749



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:12:24 EDT