uPRF strict more

John Kristoff jtk at dataplane.org
Wed Sep 29 12:50:45 UTC 2021


On Tue, 28 Sep 2021 17:47:41 -0700
Randy Bush <randy at psg.com> wrote:

> do folk use uPRF strict mode?

Presumably you mean uRPF.  As of a few months ago, the .edu  I was doing
netops at, Juniper's 'rpf-check' option was set on all the edge
interfaces where there were only end hosts.  This is strict mode. The
Cisco counterpart devices would use ' ip verify unicast source
reachable-via rx'.  Also strict mode.

More complicated inter-router links would not use this, but some had
form ingress filter that performed roughly the equivalent where
necessary.

John


More information about the NANOG mailing list