RFC 2827: Ingress filtering against spoofed source addresses
Summary
RFC 2827 recommends that providers drop packets with implausible source addresses at the point of entry. Abuse protection works best close to the source. Global security depends on many local operational decisions.
Ideas
- Network edges know the expected source prefixes of their customers.
- Filters make source address spoofing harder.
- Less spoofing reduces reflected DDoS attacks.
Facts
- RFC 2827 replaces RFC 2267.
Remarks
- RFC 2827 has the status “Best Current Practice”; current errata and successor documents should also be checked.
Recommendations
- Enable BCP 38 filters at customer and site borders.
- Consider asymmetric paths when applying strict checks.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.