URPF support

  • 0
  • 1
  • Question
  • Updated 1 year ago
  • Answered
Hi Experts, 

Does our extreme switches support URPF feature? i was not able to find it in latest 22.1 UG?
Photo of adnan khan

adnan khan

  • 100 Points 100 badge 2x thumb

Posted 1 year ago

  • 0
  • 1
Photo of Bastian Sprotte

Bastian Sprotte, Employee

  • 1,590 Points 1k badge 2x thumb
EXOS today not support unicast reverse-path forwarding (uRPF)
we had some internal discussion about that, might be we add this in the future.

looking into our GTAC Knowledge Base

Photo of Grosjean, Stephane

Grosjean, Stephane, Employee

  • 11,948 Points 10k badge 2x thumb
uRPF is defined in rfc 3704, which lists several methods. Among them, ingress ACL is proposed. That could be done, but I agree this is a stretch and maybe not very feasible in everyday network.
Photo of Erik Auerswald

Erik Auerswald, Embassador

  • 12,606 Points 10k badge 2x thumb

the uRPF feature in other vendor's products has the advantage that it just needs to be turned on and then works automatically, adjusting to routing changes on the fly. It is not realistic to manually implement and maintain ACLs for this on every routed interface.

What is realistic is to implement anti-spoofing ACL(s) on the uplink(s) to the service provider(s) using egress ACL(s). This is equivalent to the service provider using ingress filtering (BCP 38, BCP 84).