06-23-2020 12:40 PM
We need to implement uRPF in our network. I was hoping someone from the Community could provide their insights from their experience.
- Is there a significant impact on the CPU from turning on uRPF?
- Due to the potential CPU impact should it be configured on each SVI on a core switch or just the link from the external router going to the core switch?
- Is it better/preferable to implement via an ACL or "ip verify unicast source reachable-via rx"?
I appreciate your thoughts on this,
Chuck McFadden
06-24-2020 12:12 AM
Hi,
Here, you are missing key information such as the Device model and firmware version. I remember that I was reading a document on the same topic a year ago. I want to share the same with you to understand the impact of uRPF.
https://xrdocs.io/ncs5500/tutorials/ncs5500-urpf/
I think uRPF is more scalable if there are multiple interfaces and routes.
06-24-2020 02:44 AM
Thank you for the reply. Here is the information that you requested:
Core switch: Nexus 7706 NXOS 8.4(2)
External Boundary Router: ASR 1001-HX IOS XE 16.12.1s
TIA,
Chuck
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide