RFC 3704: Ingress Filtering for Multihomed Networks
In plain English — editorial summary, not part of the RFC
BCP 38, RFC 2827, is designed to limit the impact of distributed denial of service attacks, by denying traffic with spoofed addresses access to the network, and to help ensure that traffic is traceable to its correct source network. As a side effect of protecting the Internet against such attacks, the network implementing the solution also protects itself from this and other attacks, such as spoofed management access to networking equipment. There are cases when this may create problems, e.g., with multihoming. This document describes the current ingress filtering operational mechanisms, examines generic issues related to ingress filtering, and delves into the effects on multihoming in particular. This memo updates RFC 2827. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.
Document record
- Document ID
- RFC3704
- Published
- March 2004
- Authors
- F. Baker; P. Savola
- Status
- BEST CURRENT PRACTICE
- Stream
- IETF
- Area
- —
- Pages
- 16
- Also known as
- BCP84
Topics
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 3750Unmanaged Networks IPv6 Transition ScenariosCurrent
April 2004
- RFC 4029Scenarios and Analysis for Introducing IPv6 into ISP NetworksCurrent
March 2005
- RFC 5358Preventing Use of Recursive Nameservers in Reflector AttacksCurrent
October 2008
- RFC 5632Comcast's ISP Experiences in a Proactive Network Provider Participation for P2P (P4P) Technical TrialCurrent
September 2009
- RFC 6057Comcast's Protocol-Agnostic Congestion Management SystemCurrent
December 2010
- RFC 6561Recommendations for the Remediation of Bots in ISP NetworksCurrent
March 2012
- RFC 7141Byte and Packet Congestion NotificationCurrent
February 2014
- RFC 7646Definition and Use of DNSSEC Negative Trust AnchorsCurrent
September 2015
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?