[c-nsp] URPF MAC check

Saku Ytti saku at ytti.fi
Fri Nov 23 06:58:48 EST 2012


On (2012-11-23 11:45 +0000), Dobbins, Roland wrote:

> It may well be that multiple interfaces would ARP for that source (also, this implies a lot of layer-2 chatter which would be prohibitive, IMHO).
> 
> What's the ultimate problem we're trying to solve?  Traffic dumping?

If 10.10.20.0 attacks/dosses you, you know which peer sent it.

-- 
  ++ytti


More information about the cisco-nsp mailing list