RFC 5358: Preventing Use of Recursive Nameservers in Reflector Attacks
In plain English — editorial summary, not part of the RFC
This document describes ways to prevent the use of default configured recursive nameservers as reflectors in Denial of Service (DoS) attacks. It provides recommended configuration as measures to mitigate the attack. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.
Document record
- Document ID
- RFC5358
- Published
- October 2008
- Authors
- J. Damas; F. Neves
- Status
- BEST CURRENT PRACTICE
- Stream
- IETF
- Area
- ops
- Pages
- 7
- Also known as
- BCP140
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9288Recommendations on the Filtering of IPv6 Packets Containing IPv6 Extension Headers at Transit RoutersCurrent
August 2022
- RFC 3704Ingress Filtering for Multihomed NetworksUpdated
March 2004
- RFC 7141Byte and Packet Congestion NotificationCurrent
February 2014
- RFC 2827Network Ingress Filtering: Defeating Denial of Service Attacks which employ IP Source Address SpoofingUpdated
May 2000
- RFC 6274Security Assessment of the Internet Protocol Version 4Current
July 2011
- RFC 3631Security Mechanisms for the InternetCurrent
December 2003
- RFC 7873Domain Name System (DNS) CookiesUpdated
May 2016
- RFC 5575Dissemination of Flow Specification RulesObsoleted
August 2009
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?