Boundary Protection SIMPLib uses the kernel's sysctl rp_filter (reverse path) setting to drop spoofed IPv4 packets. References: :ref:`SC-7`