<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unicast Reverse Path on Cisco ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unicast-reverse-path-on-cisco-asa/m-p/2895143#M157095</link>
    <description>&lt;P&gt;When we have enabled Unicast RPF on Cisco ASA, The RPF drops on the outside interface keeps on increasing and we are getting many alerts. I understand that it's an expected behavior, So how we can find the logs filtered for this particular drops or any solution to bring the drops down. Kindly let me know. Thanks in advance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;
&lt;P&gt;Soosai Silvester&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:59:37 GMT</pubDate>
    <dc:creator>ssilvest</dc:creator>
    <dc:date>2019-03-12T07:59:37Z</dc:date>
    <item>
      <title>Unicast Reverse Path on Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/unicast-reverse-path-on-cisco-asa/m-p/2895143#M157095</link>
      <description>&lt;P&gt;When we have enabled Unicast RPF on Cisco ASA, The RPF drops on the outside interface keeps on increasing and we are getting many alerts. I understand that it's an expected behavior, So how we can find the logs filtered for this particular drops or any solution to bring the drops down. Kindly let me know. Thanks in advance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;
&lt;P&gt;Soosai Silvester&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:59:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unicast-reverse-path-on-cisco-asa/m-p/2895143#M157095</guid>
      <dc:creator>ssilvest</dc:creator>
      <dc:date>2019-03-12T07:59:37Z</dc:date>
    </item>
    <item>
      <title>Assuming that you have your</title>
      <link>https://community.cisco.com/t5/network-security/unicast-reverse-path-on-cisco-asa/m-p/2895144#M157096</link>
      <description>&lt;P&gt;Assuming that you have your routing table correct you'll only be able to bring the drops down by asking attackers to stop spoofing your IP addresses.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 05:09:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unicast-reverse-path-on-cisco-asa/m-p/2895144#M157096</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-07-06T05:09:41Z</dc:date>
    </item>
    <item>
      <title>Hi Soosai,</title>
      <link>https://community.cisco.com/t5/network-security/unicast-reverse-path-on-cisco-asa/m-p/2895145#M157097</link>
      <description>&lt;P&gt;Hi Soosai,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can use the command sh asp drop for checking the logs.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_100 gr-alert gr_gramm gr_run_anim Punctuation multiReplace" id="100" data-gr-id="100"&gt;Also&lt;/G&gt;&amp;nbsp;check this command:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The &lt;STRONG&gt;show &lt;G class="gr_ gr_75 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="75" data-gr-id="75"&gt;ip&lt;/G&gt; verify statistics&lt;/STRONG&gt; command can provide information about Unicast RPF statistics on a PIX/ASA/FWSM firewall. The following example shows 21 drops by Unicast RPF on the outside interface and 2738 packets dropped by Unicast RPF on the inside interface. Dropped packets should be investigated to determine their source and administrators should consider whether the packets indicate attempts to circumvent network security.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;PRE class="prettyprint"&gt;R4-ASA5520a# &lt;STRONG&gt;show ip verify statistics&lt;/STRONG&gt;
interface outside: &lt;STRONG&gt;21 unicast rpf drops&lt;/STRONG&gt;
interface inside: &lt;STRONG&gt;2738 unicast rpf drops&lt;/STRONG&gt;
interface vpn: 0 unicast rpf drops
R4-ASA5520a#&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;More info:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/about/security-center/unicast-reverse-path-forwarding.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;To bring these errors down please check the source routing for the packets.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2016 05:18:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unicast-reverse-path-on-cisco-asa/m-p/2895145#M157097</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-07-06T05:18:49Z</dc:date>
    </item>
  </channel>
</rss>

