<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic unicast rpf in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unicast-rpf/m-p/2316447#M344555</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You use the following command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip verify reverse-path interface &lt;INTERFACE name=""&gt;&lt;/INTERFACE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will mean that the in addition to the normal route lookup with regards to the destination IP address, the ASA will also check its routing table for the source IP address. If it doesnt find a route for the source IP address through the interface which the packet entered in, it will drop it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After enabling the above command for some interface you can use the following command to verify the statistics&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show ip verify statistics&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA will also generate log messages from these dropped packets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Aug 2013 11:52:20 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-08-16T11:52:20Z</dc:date>
    <item>
      <title>unicast rpf</title>
      <link>https://community.cisco.com/t5/network-security/unicast-rpf/m-p/2316446#M344552</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if we enable unicast rpf on asa 5585x, does it mean ip spoofing is enabled? How do we verify this?&lt;/P&gt;&lt;P&gt;is there any other anti spoof mechanisms available in this firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unicast-rpf/m-p/2316446#M344552</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2019-03-12T02:26:40Z</dc:date>
    </item>
    <item>
      <title>unicast rpf</title>
      <link>https://community.cisco.com/t5/network-security/unicast-rpf/m-p/2316447#M344555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You use the following command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip verify reverse-path interface &lt;INTERFACE name=""&gt;&lt;/INTERFACE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will mean that the in addition to the normal route lookup with regards to the destination IP address, the ASA will also check its routing table for the source IP address. If it doesnt find a route for the source IP address through the interface which the packet entered in, it will drop it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After enabling the above command for some interface you can use the following command to verify the statistics&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show ip verify statistics&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA will also generate log messages from these dropped packets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 11:52:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unicast-rpf/m-p/2316447#M344555</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-16T11:52:20Z</dc:date>
    </item>
    <item>
      <title>unicast rpf</title>
      <link>https://community.cisco.com/t5/network-security/unicast-rpf/m-p/2316448#M344559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. Do we have any other anti spoof mechansims availabe in asa.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 11:55:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unicast-rpf/m-p/2316448#M344559</guid>
      <dc:creator>suthomas1</dc:creator>
      <dc:date>2013-08-16T11:55:13Z</dc:date>
    </item>
    <item>
      <title>unicast rpf</title>
      <link>https://community.cisco.com/t5/network-security/unicast-rpf/m-p/2316449#M344562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is some document even though a bit older one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00809763ea.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00809763ea.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you could take a look at this discussion (I have not read it through myself but seems to relate to the subject)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2152269"&gt;https://supportforums.cisco.com/thread/2152269&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems the ASA Configuration Guide doesnt provide that much specific information in itself&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/protect_tools.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/protect_tools.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 12:04:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unicast-rpf/m-p/2316449#M344562</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-16T12:04:13Z</dc:date>
    </item>
  </channel>
</rss>

