URPF Flashcards

1
Q

How do you configure urpf to consider feasible-paths aswell as active?

A

done globally.

routing-options forwarding table unicast-reverse-path feasible-paths

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

where should RPF be used?

A

at the untrusted edges

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

WWhat does RPF do is a packet fails?

A

by default, discard.

But, you can define a fail filter…

This is a normal firewall policy and can do normal policy things.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what does config look like?

A

define your fail filter policy under edit firewall

within the address family on an interface specify rpf-check

you can apply loose mode here with “mode loose”

if you want a fail-filter use “fail-filter <filter>"</filter>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

how do you verify uRPF is applied?

A

show interface <interface> extensive</interface>

Should be a URPF flag.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly