Reverse Path Forwarding (RPF) is a networking technique routers use to verify the source of an incoming packet by checking if the packet arrived on the exact interface the router would use to send traffic back to that source.
RPF check is inly carried out on the first packet in a session, not on a reply.
Main Uses of RPF
- Multicast Routing: In multicast networks (like IPTV or video streaming), RPF prevents infinite routing loops. It ensures that a router only accepts and forwards a multicast stream if it arrives via the optimal, loop-free path from the source.
- Unicast Security (uRPF): For standard unicast traffic, RPF acts as a security filter to stop IP address spoofing. If an attacker tries to send traffic with a fake source IP address, the router drops the packet because the source doesn’t map to the correct incoming interface.
Common Operating Modes
- Strict Mode: The packet must arrive on the single best path back to the source. This provides maximum security or strict loop prevention, but it fails if asymmetric routing is used.
- Feasible Path (formerly loose mode): The source address only needs to be reachable through any valid interface on the router, regardless of whether it’s the absolute best path.