nanog mailing list archives

Re: netscan.org update


From: Bradley Dunn <bradley () dunn org>
Date: Mon, 25 Sep 2000 03:26:40 -0700


On Mon, Sep 25, 2000 at 03:31:53AM -0400, John Fraizer wrote:
In a BB situation and in some simple multihomed situations, it is possible
for someone to have a route into your network via an interface that for
administrative/technical reasons, you're not accepting routes to them via.  
In such instances, CEF will break an otherwise valid, though be it
asymetric stream.

You are confusing CEF, a switching path, with 'ip verify unicast reverse-path',
an interface configuration command which requires CEF.

In any case, recent flavours of IOS support using an ACL to specify exceptions
to the reverse-path check.

Bradley



Current thread: