[c-nsp] URPF MAC check

Saku Ytti saku at ytti.fi
Fri Nov 23 07:44:11 EST 2012


On (2012-11-23 12:36 +0000), Dobbins, Roland wrote:

> If all that's desired is to know the source MAC of the relevant frames, a tap/SPAN/FNF/IPFIX w/PSAMP could provide that information.

OP wants to stop them entering the network in the first-place. If IP
uRPF/strict has valid usage scenario, then SMAC uRPF/strict has valid usage
scenario.


-- 
  ++ytti


More information about the cisco-nsp mailing list