Chapter 13 Unicast Reverse Path Forwarding - Cisco 10000-2P2-2DC Software Configuration Manual

10000 series
Table of Contents

Advertisement

Unicast Reverse Path Forwarding
Cisco integrated security systems incorporate a comprehensive selection of feature-rich security
services, offering commercial, enterprise and service provider customers the ability to deploy trusted and
protected business applications and services.
Threat defense is a critical aspect of an integrated security approach and involves the implementation of
proactive measures. One valuable threat defense tool is unicast Reverse Path Forwarding (uRPF).
The key function of uRPF is to verify that the path of an incoming packet is consistent with the local
packet forwarding information. This is achieved by performing a reverse path look-up (hence the
feature's name) using the source IP address of an incoming packet to determine the current path
(adjacency) to that IP address. The validity of this path determines whether uRPF passes or drops the
packet.
The specific uRPF path validation criteria that is used to determine path consistency is dependent upon
the particular uRPF mode enabled on an interface.
supported by Cisco 10000 series routers.
Table 13-1
uRPF Mode
Strict
Loose
If the path is:
Valid—the packet will be passed.
Invalid—the packet is silently discarded.
uRPF uses the Cisco Express Forwarding (CEF) Forwarding Information Base (FIB) to perform reverse
path look-up on the source IP address of an incoming packet. The CEF FIB is a database of network layer
routing information and associated forwarding/adjacency information used in the CEF switching of
packets. The CEF FIB is populated with the path for all known IP prefixes and their associated
adjacencies. It is thus a key element of uRPF reverse path validation. After enabled on an interface, uRPF
checks all IP packets on the input path of that interface.
OL-2226-23
Three uRPF Modes
Path Resolution
Table
CEF FIB
CEF FIB
C H A P T E R
Table 13-1
shows two uRPF modes which are
uRPF Path Selection Criteria
Path to the source IP address must be
through the SAME interface as that on
which the packet arrived
Path to the source IP address is through
any interface on the device
Cisco 10000 Series Router Software Configuration Guide
13
13-11

Advertisement

Table of Contents
loading

This manual is also suitable for:

1000510008

Table of Contents