O'Reilly logo

Implementing Cisco Networking Solutions by Harpreet Singh

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

IP options and source routing

IP source routing is enabled by default within Cisco IOS. When IP source routing is enabled, IOS is able to process IP packets with the source-routing headers option.

Allowing the router to use source routing is a potential risk as this can be used to punt packets to the CPU from the normal hardware forwarding plane and even dictate the routers that would process these packets by defining the addresses in the source routing list of the IP packet options.

It is a security best practice to disable IP source routing. This can be done by using the IOS command no ip source-route in the global configuration mode.

All IP packets with the IP options present can be dropped by the router using the IOS ip options drop

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required