Configuration Considerations for uRPF

The following configuration considerations apply to unicast Reverse Path Forwarding (uRPF) on supported RUCKUS devices.

The following are general considerations for uRPF:

  • uRPF works on the Layer 3 interface level (Layer 3 physical interface or Layer 3 VE interface).
  • uRPF is VRF-aware.
  • If a VLAN has multiple ports, the uRPF check will not identify packets coming in from different ports within the same VLAN, because a VLAN is considered as having a single Layer 3 interface.
  • uRPF can be configured along with PBR, ACLs, routing protocol configurations, and multicast configurations.
  • uRPF is not supported on tunnel interfaces.
  • Tunnel keep-alive packets will be dropped in the hardware if uRPF is configured.
  • uRPF must not be configured on devices where group-VE, tunnel keep-alive packets, or OpenFlow is configured.
  • Counters or logging information is unavailable for uRPF hits.
  • After enabling reverse path check, you must reload the device for uRPF to be programmed.
  • Tunnel over user VRF should not be configured on a device on which uRPF is enabled.

ICX 7850, ICX 7750, ICX 7650, ICX 7550, ICX 7450, and ICX 7250 considerations

  • Per-interface level configuration is available on VE interfaces and physical ports only.
  • IPv4 and IPv6 unicast routed packets are subjected to uRPF check on ICX 7850, ICX 7750, and ICX 7650 devices.
  • Scaling numbers are reduced by half for the following system values when uRPF is enabled: ip-route, ip6-route, ip-route-default-vrf, ip6-route-default-vrf, ip-route-vrf, ip6-route-vrf.
  • uRPF and MCT should not be configured together.
  • If the number of ECMP paths for a route is more than 8, the hardware automatically chooses to use loose mode check, despite the configuration on the incoming interface.
  • If the interface is not uRPF-enabled, the traffic is not subjected to uRPF check.
  • If the interface is uRPF-enabled, both IPv4 and IPv6 traffic is subjected to uRPF check.