Default Settings For Unicast Rpf - Cisco Nexus 9000 Series Configuration Manual

Nx-os security configuration guide, release 9.x
Hide thumbs Also See for Nexus 9000 Series:
Table of Contents

Advertisement

Default Settings for Unicast RPF

• Beginning with Cisco NX-OS Release 9.2(1), for N9K-X9636C-R and N9K-X96136YC-R switches,
• For Cisco Nexus 9300-EX, FX, and FX2 Series switches, the ping to a directly connected peer IP interface
• For Cisco Nexus 9300-EX, FX, and FX2 Series switches, packets from a host on the interface subnet
• The following guidelines and limitations apply only to Cisco Nexus 9500 Series switches with a
Default Settings for Unicast RPF
This table lists the default settings for unicast RPF parameters.
Table 38: Default Unicast RPF Parameter Settings
Parameters
Unicast RPF
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
442
you can configure only one version of the available IPv4 and IPv6 Unicast RPF command on an interface.
However, this will enable Unicast RPF for both IPv4 and IPv6.
will fail when the peer IP interface has strict unicast RPF enabled with the ARP/ND to SRC IP is not
resolved.
will drop due to the unicast RPF failure when the ARP/ND for the host IP is not resolved.
N9K-X9636C-R, N9K-X9636C-RX, or N9K-X9636Q-R line card:
• For strict uRPF to work, you must enable it on both the ingress interface and the interface where
the source IP address is learned.
• The switch hardware does not implement strict uRPF per the configured routing interface.
• Strict uRPF is implemented per learned route on strict uRPF-enabled interfaces.
• If a route is resolved as ECMP, strict uRPF will fall back to loose mode.
• Because of the hardware limitation on the trap resolution, uRPF might not be applied on
supervisor-bound packets via inband.
• For IP traffic, both IPv4 and IPv6 configurations should be enabled simultaneously.
• Due to hardware limitations, the N9K-X9636C-R, N9K-X9636C-RX, and N9K-X9636Q-R line
cards support only the following combinations:
uRPF Configuration
IPv4
IPv6
Disable
Disable
Loose
Loose
Strict
Strict
Default
Disabled
Applied Traffic Check on Source IP Address
IP Unipath
IP ECMP
Allow
Allow
uRPF loose
uRPF loose
uRPF strict
uRPF loose
Configuring Unicast RPF
MPLS
Unipath MPLS
Encap/VPN/ECMP
VPN for
N9K-X9636C-RX
Line Card
Allow
Allow
uRPF loose
uRPF strict
uRPF loose
uRPF strict

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents