07-05-2016 08:22 PM - edited 03-12-2019 12:59 AM
When we have enabled Unicast RPF on Cisco ASA, The RPF drops on the outside interface keeps on increasing and we are getting many alerts. I understand that it's an expected behavior, So how we can find the logs filtered for this particular drops or any solution to bring the drops down. Kindly let me know. Thanks in advance.
Thanks & Regards
Soosai Silvester
07-05-2016 10:09 PM
Assuming that you have your routing table correct you'll only be able to bring the drops down by asking attackers to stop spoofing your IP addresses.
07-05-2016 10:18 PM
Hi Soosai,
You can use the command sh asp drop for checking the logs.
The show
R4-ASA5520a# show ip verify statistics interface outside: 21 unicast rpf drops interface inside: 2738 unicast rpf drops interface vpn: 0 unicast rpf drops R4-ASA5520a#
More info:
http://www.cisco.com/c/en/us/about/security-center/unicast-reverse-path-forwarding.html
To bring these errors down please check the source routing for the packets.
Regards,
Aditya
Please rate helpful posts and mark correct answers.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide