Attackers often forge (spoof) the source address of packets, for example in denial-of-service floods, to hide their origin or to make replies hit a victim. Unicast reverse path forwarding (uRPF) is a simple defense. Normally a router looks only at a packet's destination address. With uRPF enabled on an interface, the router also looks up the packet's source address in its forwarding table and asks whether that source is plausible. Packets that fail the check are dropped. This supports the widely recommended practice of filtering spoofed traffic at the network edge.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.