bk99.de entertain the web since 1997

RFC 2827: Ingress filtering against spoofed source addresses

Summary

RFC 2827 recommends that providers drop packets with implausible source addresses at the point of entry. Abuse protection works best close to the source. Global security depends on many local operational decisions.

Ideas

  • Network edges know the expected source prefixes of their customers.
  • Filters make source address spoofing harder.
  • Less spoofing reduces reflected DDoS attacks.

Facts

  • RFC 2827 replaces RFC 2267.

Remarks

  • RFC 2827 has the status “Best Current Practice”; current errata and successor documents should also be checked.

Recommendations

  • Enable BCP 38 filters at customer and site borders.
  • Consider asymmetric paths when applying strict checks.

References

Read the RFC at the RFC Editor

Search the Web Archive