Ingress Filtering for Multihomed Networks
RFC 3704, “Ingress Filtering for Multihomed Networks”, is a Best Current Practice document published in March 2004 by F. Baker, P. Savola. It updates RFC 2827. It has since been updated by RFC 8704. The canonical text is published by the RFC Editor.
Abstract
BCP 38, RFC 2827, is designed to limit the impact of distributed denial of service attacks, by denying traffic with spoofed addresses access to the network, and to help ensure that traffic is traceable to its correct source network. As a side effect of protecting the Internet against such attacks, the network implementing the solution also protects itself from this and other attacks, such as spoofed management access to networking equipment. There are cases when this may create problems, e.g., with multihoming. This document describes the current ingress filtering operational mechanisms, examines generic issues related to ingress filtering, and delves into the effects on multihoming in particular. This memo updates RFC 2827. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.
What “Best Current Practice” means
Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.
The canonical text of RFC 3704 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 3703 Policy Core Lightweight Directory Access Protocol Schema
- RFC 3705 High Capacity Textual Conventions for MIB Modules Using Performance History Based on 15 Minute Intervals
- RFC 3702 Authentication, Authorization, and Accounting Requirements for the Session Initiation Protocol
- RFC 3706 A Traffic-Based Method of Detecting Dead Internet Key Exchange Peers
- RFC 3701 6bone Phaseout
- RFC 3707 Cross Registry Internet Service Protocol Requirements
- RFC 3700 Internet Official Protocol Standards
- RFC 3708 Using TCP Duplicate Selective Acknowledgement and Stream Control Transmission Protocol Duplicate Transmission Sequence Numbers to Detect Spurious Retransmissions