[c-nsp] NXOS BFD sends packets sourced and destined for it's own IP address to the remote host.

Gert Doering gert at greenie.muc.de
Mon Jan 18 16:26:04 EST 2021


Hi,

On Mon, Jan 18, 2021 at 08:15:02PM +0000, Drew Weaver wrote:
> I can really easily resolve this by just adding another line to the ACL but I would much rather understand how this traffic is ending up on the wire in the first place.

By being sent out, to be returned by the other end "if its IP forwarding
engine is working" - BFD echo mode

  https://netcraftsmen.com/clarifying-bfd-and-bfd-echo/

gert
-- 
"If was one thing all people took for granted, was conviction that if you 
 feed honest figures into a computer, honest figures come out. Never doubted 
 it myself till I met a computer with a sense of humor."
                             Robert A. Heinlein, The Moon is a Harsh Mistress

Gert Doering - Munich, Germany                             gert at greenie.muc.de
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 630 bytes
Desc: not available
URL: <https://puck.nether.net/pipermail/cisco-nsp/attachments/20210118/5c9ccc88/attachment.sig>


More information about the cisco-nsp mailing list