< Home

Overview of URPF

Definition

Unicast Reverse Path Forwarding (URPF) prevents network attacks based on source IP address spoofing.

Purpose

A Denial of Service (DoS) attack disables users from connecting to a server. DoS attacks aim to occupy many resources by sending a large number of connection requests to a specified server. The attacked server cannot respond to authorized users.

URPF searches for the route to the source IP address in the routing table based on the source IP address of the packet, and checks whether the inbound interface of the packet is the same as the outbound interface of the route. If no route to the source IP address of the packet exists in the routing table, or the inbound interface of the packet is different from the outbound interface of the route, the packet is discarded. This prevents IP spoofing attacks, especially DoS attacks with bogus source IP address.

Benefits

  • URPF prevents source IP address spoofing attacks and reduces maintenance costs.

  • URPF improves network security and stability and defends against malicious attacks.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
Next topic >