Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing
RFC 2827, “Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing”, is a Best Current Practice document published in May 2000 by P. Ferguson, D. Senie. It obsoletes RFC 2267. It has since been updated by RFC 3704. The canonical text is published by the RFC Editor.
Abstract
This paper discusses a simple, effective, and straightforward method for using ingress traffic filtering to prohibit DoS (Denial of Service) attacks which use forged IP addresses to be propagated from 'behind' an Internet Service Provider's (ISP) aggregation point. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.
What “Best Current Practice” means
Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.
The canonical text of RFC 2827 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 2826 IAB Technical Comment on the Unique DNS Root
- RFC 2828 Internet Security Glossary
- RFC 2825 A Tangled Web: Issues of I18N, Domain Names, and the Other Internet protocols
- RFC 2829 Authentication Methods for LDAP
- RFC 2824 Call Processing Language Framework and Requirements
- RFC 2830 Lightweight Directory Access Protocol : Extension for Transport Layer Security
- RFC 2823 PPP over Simple Data Link using SONET/SDH with ATM-like framing
- RFC 2831 Using Digest Authentication as a SASL Mechanism