Ingress Filtering for Multihomed Networks

Ingress Filtering for Multihomed Networks
复制标题

DOI:
10.17487/rfc3704
复制
发表时间:
2004-03
期刊:
RFC
影响因子:
--
通讯作者:
F. Baker;P. Savola
F. Baker;P. Savola
中科院分区:
其他
文献类型:
--
作者:
F. Baker;P. Savola

文献摘要

被引文献

相似文献

BCP 38(RFC 2827)旨在通过拒绝具有欺骗地址的流量访问网络来限制分布式拒绝服务攻击的影响,并帮助确保流量可追溯到其正确的源网络。作为保护互联网免受此类攻击的副作用,实施该解决方案的网络还可以保护自己免受这种攻击和其他攻击,例如对网络设备的欺骗性管理访问。在某些情况下,这可能会产生问题,例如,多宿主本文描述了当前的入口过滤操作机制,研究了与入口过滤相关的一般问题,并特别深入研究了对多宿主的影响。本备忘录更新RFC 2827。
BCP 38, RFC 2827, is designed to limit the impact of distributed denial of service attacks, by denying traffic with spoofed addresses access to the network, and to help ensure that traffic is traceable to its correct source network. As a side effect of protecting the Internet against such attacks, the network implementing the solution also protects itself from this and other attacks, such as spoofed management access to networking equipment. There are cases when this may create problems, e.g., with multihoming. This document describes the current ingress filtering operational mechanisms, examines generic issues related to ingress filtering, and delves into the effects on multihoming in particular. This memo updates RFC 2827.