Hiding Transit-Only Networks in OSPF
RFC 6860, “Hiding Transit-Only Networks in OSPF”, is a Proposed Standard document published in January 2013 by Y. Yang, A. Retana, A. Roy. It updates RFC 2328, RFC 5340. The canonical text is published by the RFC Editor.
Abstract
A transit-only network is defined as a network connecting routers only. In OSPF, transit-only networks are usually configured with routable IP addresses, which are advertised in Link State Advertisements (LSAs) but are not needed for data traffic. In addition, remote attacks can be launched against routers by sending packets to these transit-only networks. This document presents a mechanism to hide transit-only networks to speed up network convergence and reduce vulnerability to remote attacks.
In the context of this document, 'hiding' implies that the prefixes are not installed in the routing tables on OSPF routers. In some cases, IP addresses may still be visible when using OSPFv2.
This document updates RFCs 2328 and 5340. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 6860 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 6859 Update to RFC 3777 to Clarify Nominating Committee Eligibility of IETF Leadership
- RFC 6861 The "create-form" and "edit-form" Link Relations
- RFC 6858 Simplified POP and IMAP Downgrading for Internationalized Email
- RFC 6862 Keying and Authentication for Routing Protocols Overview, Threats, and Requirements
- RFC 6857 Post-Delivery Message Downgrading for Internationalized Email Messages
- RFC 6863 Analysis of OSPF Security According to the Keying and Authentication for Routing Protocols Design Guide
- RFC 6856 Post Office Protocol Version 3 Support for UTF-8
- RFC 6864 Updated Specification of the IPv4 ID Field