Enhanced Feasible-Path Unicast Reverse Path Forwarding
RFC 8704, “Enhanced Feasible-Path Unicast Reverse Path Forwarding”, is a Best Current Practice document published in February 2020 by K. Sriram, D. Montgomery, J. Haas. It updates RFC 3704. The canonical text is published by the RFC Editor.
Abstract
This document identifies a need for and proposes improvement of the unicast Reverse Path Forwarding (uRPF) techniques (see RFC 3704) for detection and mitigation of source address spoofing (see BCP 38). Strict uRPF is inflexible about directionality, the loose uRPF is oblivious to directionality, and the current feasible-path uRPF attempts to strike a balance between the two (see RFC 3704). However, as shown in this document, the existing feasible-path uRPF still has shortcomings. This document describes enhanced feasible-path uRPF (EFP-uRPF) techniques that are more flexible (in a meaningful way) about directionality than the feasible-path uRPF (RFC 3704). The proposed EFP-uRPF methods aim to significantly reduce false positives regarding invalid detection in source address validation (SAV). Hence, they can potentially alleviate ISPs' concerns about the possibility of disrupting service for their customers and encourage greater deployment of uRPF techniques. This document updates RFC 3704.
What “Best Current Practice” means
Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.
The canonical text of RFC 8704 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8705 OAuth 2.0 Mutual-TLS Client Authentication and Certificate-Bound Access Tokens
- RFC 8703 Dynamic Link Exchange Protocol Link Identifier Extension
- RFC 8706 Restart Signaling for IS-IS
- RFC 8702 Use of the SHAKE One-Way Hash Functions in the Cryptographic Message Syntax
- RFC 8707 Resource Indicators for OAuth 2.0
- RFC 8701 Applying Generate Random Extensions And Sustain Extensibility to TLS Extensibility
- RFC 8708 Use of the HSS/LMS Hash-Based Signature Algorithm in the Cryptographic Message Syntax
- RFC 8709 Ed25519 and Ed448 Public Key Algorithms for the Secure Shell Protocol