Unicast Reverse Path Forwarding (uRPF)

Hello David

If you are using loose mode, then yes, you can spoof the source address to an address that you know is in the routing table of the router, thus allowing the packet to pass the test and be routed. However, you have to remember that such packets, by definition, are allowed. A router will not be able to distinguish between a legitimate packet with an acceptable source IP address and a malicious packet with an acceptable IP source address. But it will prevent the spoofing of all other possible IP addresses, and that is the purpose of this feature.

Remember, uRPF is a feature that helps to limit malicious traffic on an enterprise, not to eliminate it completely. Although uRPF is an effective tool for preventing IP spoofing and mitigating some types of DoS attacks, it is not a comprehensive security solution and should be used as part of a multi-layered security strategy that includes other measures such as firewalls, intrusion detection systems, and regular network monitoring and auditing.

I hope this has been helpful!

Laz