On Wed, 16 Jul 2008, Ole Troan wrote:
that is incorrect. you do not need a global address to verify the SA. we could go into details on "RPF checking", but before that, why do you even want RPF checking on a CPE router, that belongs on the provider edge.
On the WAN side to prevent spoofed packets from entering the customer's network. On the LAN side to prevent a customer's network that's been overrun from sending spoofed packets to the service provider's network. Doing it at the CPE prevents those packets from overwhelming the WAN link.
Antonio Querubin whois: AQ7-ARIN