Home » ASA Appliance, CCNP Security, Certification, Cisco, FIREWALL, Security, Technology, VPN

CCNP Security Question of the Week

Author: Dawn Hopper 17 November 2011 399 views No Comments

Which ASA feature can be used to automatically prevent the spoofing of internal source addresses from outside networks?

  1. ACLs
  2. uRPF
  3. AIP-SSM
  4. Shunning

 

The answer is 2.

Specifying Cisco ASA adaptive security appliance per-interface access rules to protect against source-spoofed packets can be a labor-intensive task. As the adaptive security appliance can refer to its routing table to determine which networks are reachable through which interface, it can also use its routing table to validate source addresses of incoming packets. The technique is called Unicast Reverse Path Forwarding (uRPF), and the Cisco ASA adaptive security appliance supports the strict uRPF usage, where packets must arrive over the correct interface in order to be accepted.

Related Courses:
ASAE — ASA Essentials
FIREWALL — Deploying Cisco ASA Firewall Solutions
VPN — Deploying Cisco ASA VPN Solutions
CCNP Security — Cisco Certified Network Professional Security

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

Leave your response!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.