37-11
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 37 Configuring Unicast Reverse Path Forwarding
Monitoring and Maintaining Unicast RPF
Monitoring and Maintaining Unicast RPF
To monitor and maintain Unicast RFP, perform this task:
Unicast RPF counts the number of packets dropped or suppressed because of malformed or forged source
addresses. Unicast RPF counts dropped or forwarded packets that include the following global and
per-interface information:
•
Global Unicast RPF drops
•
Per-interface Unicast RPF drops
•
Per-interface Unicast RPF suppressed drops
The
show ip traffic
command shows the total number (global count) of dropped or suppressed packets
as dropped by software; it does not include those dropped by hardware. The Unicast RPF drop count is
included in the IP statistics section.
Switch#
show ip traffic
IP statistics:
Rcvd: 1471590 total, 887368 local destination
0 format errors, 0 checksum errors, 301274 bad hop count
0 unknown protocol, 0 not a gateway
0 security failures, 0 bad options, 0 with options
Opts: 0 end, 0 nop, 0 basic security, 0 loose source route
0 timestamp, 0 extended security, 0 record route
0 stream ID, 0 strict source route, 0 alert, 0 other
Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble
0 fragmented, 0 couldn't fragment
Bcast: 205233 received, 0 sent
Mcast: 463292 received, 462118 sent
Sent: 990158 generated, 282938 forwarded
! The second line below (“0 unicast RPF”) displays Unicast RPF packet dropping
information.
Drop: 3 encapsulation failed, 0 unresolved, 0 no adjacency
0 no route, 0 unicast RPF, 0 forced drop
A nonzero value for the count of dropped or suppressed packets can mean one of two things:
•
Unicast RPF is dropping or suppressing packets that have a bad source address (normal operation).
•
Unicast RPF is dropping or suppressing legitimate packets because the route is misconfigured to use
Unicast RPF in environments where asymmetric routing exists; that is, where multiple paths can
exist as the best return path for a source address.
The
show ip interface
command shows the total of dropped or suppressed packets at a specific interface.
If Unicast RPF is configured to use a specific ACL, that ACL information is displayed along with the
drop statistics.
Switch>
show ip interface fast 2/1
Unicast RPF ACL 197
1 unicast RPF drop
1 unicast RPF suppressed drop
Command
Purpose
Switch#
show ip traffic
Displays global switch statistics about Unicast RPF drops
and suppressed drops.
Switch(config-if)#
no ip verify unicast
Disables Unicast RPF at the interface.
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...