<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Reverse Path Check in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/reverse-path-check/m-p/2039591#M438197</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Shivaji,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Yes, the route-lookup goes first than the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is on the internal network, what other device? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any other question..Sure..Just remember to rate all of my answers.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Oct 2012 17:23:19 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-10-15T17:23:19Z</dc:date>
    <item>
      <title>Reverse Path Check</title>
      <link>https://community.cisco.com/t5/network-security/reverse-path-check/m-p/2039590#M438196</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am getting following maessage on my ASA %ASA-1-106021: Deny UDP reverse path check from 192.168.1.220 to 10.192.0.249 on interface inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.1.220 is not there in my network and I have enabled the RPF on ASA so it is obious that it is getting blocked..&lt;/P&gt;&lt;P&gt;My challenge is to find out the actual souce device for 192.168.1.220 and to block these logs from reflecting. I tried following but could not succeed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Applied ACL on interface interface in line 1 denying all traffic from 192.168.1.220 to 10.192.0.249 (Outside), but still RPF message continues with no hits on this ACL. I am wondering if ACL comes first or RPF&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Connected sniffer in the vlan of Inside interface but could not get any logs for these two IPs.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:09:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-path-check/m-p/2039590#M438196</guid>
      <dc:creator>central_bank</dc:creator>
      <dc:date>2019-03-12T00:09:01Z</dc:date>
    </item>
    <item>
      <title>Reverse Path Check</title>
      <link>https://community.cisco.com/t5/network-security/reverse-path-check/m-p/2039591#M438197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Shivaji,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Yes, the route-lookup goes first than the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is on the internal network, what other device? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any other question..Sure..Just remember to rate all of my answers.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2012 17:23:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-path-check/m-p/2039591#M438197</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-15T17:23:19Z</dc:date>
    </item>
    <item>
      <title>Reverse Path Check</title>
      <link>https://community.cisco.com/t5/network-security/reverse-path-check/m-p/2039592#M438198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; But how do I find out the actual source. 192.168.x.x is not used in my network.&lt;/P&gt;&lt;P&gt;I tried using Sniffer but that did not show up anything with this IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shivaji&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 07:34:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-path-check/m-p/2039592#M438198</guid>
      <dc:creator>central_bank</dc:creator>
      <dc:date>2012-10-16T07:34:32Z</dc:date>
    </item>
    <item>
      <title>Reverse Path Check</title>
      <link>https://community.cisco.com/t5/network-security/reverse-path-check/m-p/2039593#M438199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Shivaji,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know what you mean but if the ASA reports it. that means it is happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Someone is using that Ip on your internal network.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide me the captures you applied on your ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="background-color: #f7fafb; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Any other question..Sure..Just remember to rate all of my answers.&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 12:13:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reverse-path-check/m-p/2039593#M438199</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-16T12:13:13Z</dc:date>
    </item>
  </channel>
</rss>

