cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
998
Views
5
Helpful
4
Replies

Enable Unicast reverse path forwarding (urpf) on Cisco ASA ?

kaus2005007
Level 1
Level 1

Hello,
I want to enable reverse-path (URPF) on Cisco ASA where all my firewalls are in Active-standby mode.

We have default route configured towards outside interface.

I would like to know where do i need to enable URPF ? Inside or outside or both interfaces ?

Also, Will it cause any issues after implementaion under above mentioned scenario ?

4 Replies 4

kaus2005007
Level 1
Level 1

Also in my scenario we have 2 edged upstream routers, So if there is any asymmetric routing on edge will it impact on prod environment ? as my firewalls are in Active-standby mode but on downstream of routers.

downstream Router have static router? if yes then they ALWAYS point to active ASA.
if you want to use both ASA use context this make ASA Active/Active.

General rule of thumb: You can enable it on every interface where you never will see a source address that doesn't match the routing table. When you only have one ISP connected, you can enable it typically on all interfaces. If you have two (or more) ISPs connected, you can enable it on all non-outside-interfaces.