[c-nsp] uRPF Black hole routing with asymmetric traffic

f287cd76 at opayq.com f287cd76 at opayq.com
Tue Oct 13 13:30:12 EDT 2015


Hi
Looking for help on how to configure uRPF on Cisco IOS-XE 3.13 in an
asymmetric multiple ISP Edge scenario

We currently have a edge/customer router that receives a list of 'known bad'
routes via BGP.
These are re-routed to 192.0.2.1/NULL0 with a route-map.

Today.. this router has only one ISP and all traffic is symmetric.  uRPF
works fine with this syntax
-> " ip verify unicast source reachable-via any 2699"

I'm moving to a router with multiple  ISP and IX connections and some of our
traffic is now asymmetric.
The above uRPF config didn't work and was removed.

But I still need to drop traffic sourced from any of the above 'bad'
networks.
In other words .. I'm looking for a configuration that only drops traffic
from routes with a next-hop of Null0, and ignores the rest.

Suggestions on how to configure for this now?

thanks in advance
(appologies if this posted twice )

WS



More information about the cisco-nsp mailing list