[c-nsp] benefit of uRFP with ACL over ACL on interface

LIM Fung limfung at cisco.com
Wed Sep 8 05:34:26 EDT 2004


It all depends on what you want to achieve. uRPF when used in loose mode 
allows for remotely triggered drops/filters in a short timeframe, which 
is difficult to achieve with ACL.

However, uRPF doesn't allow for filtering granularity (matching 
protocol/ports) like what xACL allows.

Sven Huster wrote:

> Hi there,
> 
> I was wondering what the benefit of uRPF with an ACL is over applying 
> the ACL straight in the interface.
> Can anyone, please, provide some info?
> 
> Thanks
> Cheers
> Sven
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/


More information about the cisco-nsp mailing list