RFC 2267 · INFORMATIONAL · 1998

Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing

Overview

RFC 2267, “Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing”, is an Informational document published in January 1998 by P. Ferguson, D. Senie. It has been obsoleted by RFC 2827 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.

Abstract

This paper discusses a simple, effective, and straightforward method for using ingress traffic filtering to prohibit DoS attacks which use forged IP addresses to be propagated from 'behind' an Internet Service Provider's (ISP) aggregation point. This memo provides information for the Internet community. It does not specify an Internet standard of any kind.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 2267 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
Obsoleted by
RFC 2827
Other RFCs from 1998

Who Is Online

In total there are 57 users online: 0 registered, 48 guests and 9 bots.

Most users ever online was 9,867 on 30 Jul 2026, 2:30 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot Other Crawler Other Spider PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372