Hi,
IP spoofing is a packet that uses an incorrect source IP address to obscure its true source.
The command ip verify reverse-path interface interface_name ensurres that all packets have a source IP address that matches the correct source interface according to the routing table.
http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i3_72.html
See below a configuration guide
http://www.cisco.com/web/about/security/intelligence/unicast-rpf.html
See below an example of it's use. If you think that attacks can come from both your internal and external networks then enable it on both interfaces.
http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00809763ea.shtml
Please remember to rate all posts that are helpful.