RFC 2267 · INFORMATIONAL · 1998

Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing

Overview

RFC 2267, “Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing”, is an Informational document published in January 1998 by P. Ferguson, D. Senie. It has been obsoleted by RFC 2827 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.

Abstract

This paper discusses a simple, effective, and straightforward method for using ingress traffic filtering to prohibit DoS attacks which use forged IP addresses to be propagated from 'behind' an Internet Service Provider's (ISP) aggregation point. This memo provides information for the Internet community. It does not specify an Internet standard of any kind.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 2267 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
Obsoleted by
RFC 2827
Other RFCs from 1998

Who Is Online

In total there are 79 users online: 0 registered, 75 guests and 4 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354