How do you prove your edge actually drops forged source addresses, and what does a clean test not prove?
answer
- configuration read-back is not evidence
- you need a receiver on the far side
- a quiet counter proves nothing at all
- one exit path, one moment, one source class
- count the doors, not the diagram
basics
~20 sSend a packet with a source outside your prefixes from inside a segment toward a receiver you control elsewhere, and check both ends: nothing arrives, and the filter's drop counter moved. It proves that one exit path, at that moment, for a source outside your own space.
solid answer
~50 sThe only real evidence is an end-to-end test with an authorised receiver outside your network: originate traffic from inside a representative segment with a source address outside your allocated prefixes, and look for it at a host you control in another network. Two observations together make the claim - nothing arrived at the receiver, AND the drop counter on the filtering interface incremented while you were testing. The counter alone proves nothing, because a counter that never moves is equally consistent with a working filter and with nobody having tried. What a clean result does not prove is coverage: it covers the exit path you tested, at that moment, under that routing state. Every other door - the second transit edge, a branch with local internet breakout, a tunnel egressing through a cloud account, a partner interconnect - needs its own test, because packets take whichever door their route picks. And no source-prefix filter anywhere stops a host forging an address inside your own space.
go deeper
Know that verifying a filter means generating traffic that should be dropped and looking for it on the far side, not reading the configuration back and assuming it behaves as written.
Be able to describe the two correlated observations that make the claim - nothing at an authorised receiver, and a drop counter that moved in the same window - and why either alone is weak.
Show that you scope the claim: one exit path, one moment, one class of forged source. Enumerate the estate's real doors, name the residual for sources inside your own prefixes, and say what invalidates the result.
Be prepared to say what standing assurance is worth funding here, given that the verdict expires whenever routing or the edge changes and the beneficiary of the control is largely other networks.
## Why the question is asked at all Source-address validation is an assertion about behaviour, and assertions about behaviour rot. The prefix list drifts from the address space. A new circuit appears without the filter. A rebuild loses the interface configuration. Somebody adds a route and the derived reverse-path verdict changes. None of these produce a symptom, because a filter that has stopped working is invisible - the traffic it was supposed to drop leaves quietly and lands on somebody else. So *prove it denies* is a real request, and the wrong answers are easy to spot. Reading the configuration back proves the configuration says what you think, not that packets are handled that way. A rising drop counter proves packets are failing the check somewhere, not that YOUR forged packet would. A quiet counter proves nothing whatsoever. ## The shape of a test that actually proves something Three ingredients, and the interviewer is listening for all three. **An originator inside the real segment.** Not the edge router, not a jump host in a management VLAN with a different path out - a host in the segment whose behaviour you are claiming, because the claim is about that segment's exit path. **An authorised receiver outside your network.** Someone must be positioned to observe the negative. A host you control in a different network, with the test agreed in advance and the target address chosen from space you legitimately hold there. Firing packets with sources you do not own at addresses you do not own is not a test, it is the thing you are trying to prevent, and it will be seen that way by whoever receives it. **Correlated evidence at both ends, timestamped.** The receiver saw nothing during the window; the filtering interface's counter moved during that same window. One without the other is not evidence. That correlation is the whole artefact. ## What a clean result covers - and it is narrower than it feels A passing test is a statement about **one exit path, at one moment, for one class of forged source**. Four limits deserve to be named out loud. **Coverage of paths.** Packets leave by whichever exit their route selects. A merged estate typically has more doors than the diagram admits: a second transit edge from the acquired company, branch sites with local internet breakout, a tunnel that egresses through a cloud account, a partner interconnect, an out-of-band management link with its own uplink. Each is an independent claim requiring its own test. The deliverable is not a pass, it is a matrix of exit paths with a date against each one. **Coverage of sources.** The test used a source outside your prefixes, so it exercised the rule the filter implements. A host forging an address INSIDE one of your own prefixes passes every source-prefix filter and every reverse-path mode that points back into your network - and that is enough to redirect replies onto another host in your estate. Your evidence should say so explicitly rather than letting a reader infer a stronger claim. **Coverage in time.** For a written ACL the verdict changes when someone edits the list. For a reverse-path check the verdict is derived from routing, so it changes when a neighbour changes an announcement, a session flaps, or a route is withdrawn - with no change on your side. A dated pass is therefore a claim about a configuration AND a routing state, and it must be retested after edge or routing changes, not annually because a calendar said so. **What the absence of drops means.** Nothing. A counter sitting at zero is consistent with a perfect filter and with a filter that was removed last month, because in a healthy estate almost nothing legitimately attempts to leave with a forged source. Absence of evidence here is genuinely not evidence of the control working, and treating a quiet counter as assurance is the most common way this control is believed to exist when it does not. ## Producing the evidence somebody else will read The useful artefact is small and unglamorous: for each exit path, the date, the originating segment, the forged source class used, whether the receiver saw traffic, the counter delta, and the routing state at the time. It fits on one page. Its value is that when the question is asked again in a year - after two new circuits and a rebuild - it shows exactly which claims are still current and which have expired, instead of a general belief that the edge is filtered.
- Why is a zero drop counter not reassuring?Because in a healthy estate almost nothing legitimately tries to leave with a forged source, so zero is exactly what a working filter and a removed filter both look like. The counter only carries information while you are deliberately generating traffic that should fail. Outside a test, it is a signal about the environment, not about the control.
- You inherit an estate and are asked whether it filters forged sources. Where do you start?By enumerating exit paths rather than reading edge configuration, because the risk lives in the doors nobody drew: the acquired company's transit edge, branch local breakout, tunnels egressing through cloud accounts, partner interconnects, management uplinks. Every path found is an untested claim until it has its own result. Reading the configuration of the two edges you already knew about answers the easy half.
- What should the evidence explicitly say the control does NOT do?That it does not stop a host forging an address inside your own allocated prefixes, since such a packet satisfies both a source-prefix list and a reverse-path check pointing into your network. Stating the residual is what keeps a reader from converting a narrow pass into a broad belief, and it names the follow-up work: validation at the access layer, closer to where the address assignment is actually known.
saying these in an interview costs you the question
- Offers a configuration read-back as proof the filter drops packets
- Treats a zero drop counter as assurance the control works
- Tests one edge and claims the whole estate is filtered
- Sends forged traffic at a third party without an authorised receiver
- Presents a dated pass as a standing property after routing changes