Cisco CCNP Security Core (SCOR) 350-701Network SecurityHard

A network security administrator is configuring a Cisco router to protect against spoofed IP addresses originating from within the internal network. The administrator wants to ensure that only IP addresses assigned to specific interfaces can be used for outbound traffic, preventing an attacker from sending packets with a forged source IP. Which feature should be enabled to achieve this ingress filtering?

  1. AUnicast Reverse Path Forwarding (uRPF)
  2. BAccess Control Lists (ACLs)
  3. CPort Security
  4. DDynamic Host Configuration Protocol (DHCP) Snooping
Show answer & explanation

Correct answer: A. Unicast Reverse Path Forwarding (uRPF)

Unicast Reverse Path Forwarding (uRPF) is a security feature that helps mitigate IP spoofing by verifying that the source IP address of an incoming packet has a corresponding entry in the routing table that points back to the interface on which the packet arrived. If the reverse path is not valid, the packet is dropped, effectively preventing an attacker from using a forged source IP that doesn't legitimately belong to that network segment.

Why the other options are wrong

  • B. ACLs filter traffic based on defined rules (source/destination IP, port) but do not inherently verify the legitimacy of a source IP's routing path.
  • C. Port Security restricts the number of MAC addresses allowed on a switch port to prevent unauthorized devices, not IP spoofing based on routing paths.
  • D. DHCP Snooping is used to prevent rogue DHCP servers and create a binding table for legitimate MAC-IP pairs, but it doesn't directly perform ingress filtering based on routing paths.

Unicast Reverse Path Forwarding (uRPF)

A security feature that prevents IP spoofing by checking if the source IP address of an incoming packet has a valid reverse path in the routing table.

  • Mitigates IP spoofing attacks
  • Verifies source IP against routing table
  • Drops packets with invalid reverse paths
  • Can operate in strict or loose mode

Memory trick: uRPF: Check the return address.

More Network Security questions