hardMultiple SelectObjective-mapped
IPv6 uRPF and ACL Interaction
Which TWO statements about the interaction between IPv6 ACLs and uRPF are correct? (Choose TWO.)
Quick Answer
The answer is that an IPv6 ACL can be used to permit traffic that would otherwise be dropped by uRPF strict mode due to asymmetric routing. This is correct because on a Cisco router, uRPF processes packets before inbound ACLs in the input path; if uRPF drops a packet, the ACL is never evaluated, but if uRPF passes the packet, the ACL then filters it sequentially. For the CCNP ENARSI 300-410 exam, this interaction tests your understanding of packet flow order and the fact that ACLs can override uRPF drops only when explicitly configured to permit the traffic, which is a common trap—many candidates mistakenly think uRPF always overrides ACLs. Remember the memory tip: “uRPF first, ACL second; to save a packet from uRPF, the ACL must be beckoned.”
⚠ Common exam trap
It's easy for candidates to assume ACLs are always processed before uRPF, or that uRPF can be configured to skip ACL checks, but Cisco explicitly tests the order of operations where uRPF is evaluated first on inbound interfaces.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
When both uRPF and an inbound IPv6 ACL are configured on the same interface, uRPF is processed first.
When both uRPF and an inbound IPv6 ACL are configured on the same interface, Cisco IOS processes uRPF first. This is because uRPF is a routing-based security check that verifies the source address against the FIB before any ACL filtering occurs. The inbound ACL is evaluated only after the packet passes the uRPF check, ensuring that spoofed traffic is dropped before ACL processing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
When both uRPF and an inbound IPv6 ACL are configured on the same interface, uRPF is processed first.
Why this is correct
Correct. uRPF checks occur before ACL processing in the input path.
- ✓
An IPv6 ACL can be used to permit traffic that would otherwise be dropped by uRPF strict mode due to asymmetric routing.
Why this is correct
Correct. You can use an ACL to explicitly permit traffic from sources that are not reachable via the incoming interface, bypassing uRPF drops.
- ✗
uRPF can be configured to ignore IPv6 ACLs on the same interface.
Why it's wrong here
Incorrect. uRPF and ACLs are independent; uRPF does not ignore ACLs. They operate sequentially.
- ✗
An outbound IPv6 ACL can be used to filter traffic before uRPF checks.
Why it's wrong here
Incorrect. uRPF checks occur on inbound traffic only; outbound ACLs are processed after routing, not before uRPF.
- ✗
If uRPF drops a packet, the inbound ACL is still evaluated for logging purposes.
Why it's wrong here
Incorrect. If uRPF drops a packet, it is discarded before reaching the ACL, so the ACL is not evaluated.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,966 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 300-410
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Consider the following configuration: ipv6 access-list FILTER permit ipv6 2001:db8:3::/48 any deny ipv6 any any interface GigabitEthernet0/5 ipv6 traffic-filter FILTER in ipv6 verify unicast source reachable-via rx A packet arrives on GigabitEthernet0/5 with source 2001:db8:3::100 and destination 2001:db8:4::1. The route for 2001:db8:3::/48 points out interface GigabitEthernet0/6. What happens?
medium- A.The packet is permitted because the ACL matches and uRPF is not applied.
- ✓ B.The packet is dropped by uRPF because strict mode requires the source to be reachable via the receiving interface.
- C.The packet is dropped by the ACL because the deny statement blocks all traffic.
- D.The packet is permitted because uRPF only checks destination addresses.
Why B: The packet is dropped by uRPF (unicast Reverse Path Forwarding) in strict mode because the `ipv6 verify unicast source reachable-via rx` command checks that the source address 2001:db8:3::100 is reachable via the receiving interface (GigabitEthernet0/5). The route for the source prefix 2001:db8:3::48 points out GigabitEthernet0/6, not the receiving interface, so uRPF fails and drops the packet before the ACL is evaluated.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.