[c-nsp] uRPF on Cat4500?

Thomas Kernen thomas at ip-man.net
Tue Mar 29 02:48:52 EST 2005


Brian,

If you are connecting customers to the 4500 the work around is the use 
the "IP Source Guard" feature that allows you to build dynamic ACLs 
based on source MAC/IP address. This doesn't work in all network designs 
but depending on your topology can fit your needs.

Thomas

----- Original Message ----- 
From: "Brian Feeny" <signal at shreve.net>
To: <cisco-nsp at puck.nether.net>
Sent: Monday, March 28, 2005 10:32 PM
Subject: [c-nsp] uRPF on Cat4500?


>
> Does anyone know if the Catalyst 4500 (Sup IV) has a feature like "ip
> verify unicast reverse-path"?  I did not see this command in its IOS
> under the VLAN interfaces, and then tried to search cisco.com for
> anything similar and turned up blank.  It would be surprising to me
> that they did not support this functionality.
>
> Brian
>
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/ 



More information about the cisco-nsp mailing list