Cisco 4700M Configuration Manual page 299

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 4
Configuring TCP/IP Normalization and IP Reassembly Parameters
Configuring Interface Normalization Parameters
This feature enables the ACE to filter both ingress and egress packets to verify
addressing and route integrity. It is called RPF because the route lookup is
typically based on the destination address, not the source address.
When you enable this feature, the ACE discards packets if there is no route found
or if the route does not match the interface on which the packet arrived.
If you configure the mac-sticky command on the interface, you cannot configure
Note
the ip verify reverse-path command. For details about the mac-sticky command,
see the Cisco 4700 Series Application Control Engine Appliance Routing and
Bridging Configuration Guide.
To enable this feature, use the ip verify reverse-path command in interface
configuration mode. The syntax of this command is as follows:
ip verify reverse-path
For example, to enable reverse-path forwarding, enter:
host/C1(config-if)# ip verify reverse-path
To disable reverse-path forwarding, enter:
host/C1(config-if)# no ip verify reverse-path
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
4-41
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents