RFC 2827 · BEST CURRENT PRACTICE · 2000

Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing

Overview

RFC 2827, “Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address Spoofing”, is a Best Current Practice document published in May 2000 by P. Ferguson, D. Senie. It obsoletes RFC 2267. It has since been updated by RFC 3704. The canonical text is published by the RFC Editor.

Abstract

This paper discusses a simple, effective, and straightforward method for using ingress traffic filtering to prohibit DoS (Denial of Service) attacks which use forged IP addresses to be propagated from 'behind' an Internet Service Provider's (ISP) aggregation point. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.

Abstract as published in the RFC, via rfc-editor.org.

What “Best Current Practice” means

Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.

Read this RFC

The canonical text of RFC 2827 is hosted at rfc-editor.org. Available in TXT,HTML.

Relationships to other RFCs
This RFC obsoletes
RFC 2267
Updated by
RFC 3704
Other RFCs from 2000

Who Is Online

In total there are 41 users online: 0 registered, 35 guests and 6 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Baiduspider Bingbot Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372