nanog mailing list archives

Re: netscan.org update


From: Roland Dobbins <rdobbins () netmore net>
Date: Mon, 25 Sep 2000 10:05:21 -0700


Now =this= I'm familiar with.  ip verivy unicast reverse-path causes
massive problems when you're multihomed.

By 'recent', I assume you mean 12.x?

Bradley Dunn wrote:

On Mon, Sep 25, 2000 at 03:31:53AM -0400, John Fraizer wrote:
In a BB situation and in some simple multihomed situations, it is possible
for someone to have a route into your network via an interface that for
administrative/technical reasons, you're not accepting routes to them via.
In such instances, CEF will break an otherwise valid, though be it
asymetric stream.

You are confusing CEF, a switching path, with 'ip verify unicast reverse-path',
an interface configuration command which requires CEF.

In any case, recent flavours of IOS support using an ACL to specify exceptions
to the reverse-path check.

Bradley

-- 
------------------------------------------------------------
 Roland Dobbins <rdobbins () netmore net> // 818.535.5024 voice



Current thread: