This (-02) is a slightly updated over the previous (-01) version -- minor
editorial changes and some wording improvements.
Significant changes based on WG adoption call comments/discussion last April
were already included in -01.
Thanks.
Sriram
--------------------------------------------------------------------------------------------
A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Operational Security Capabilities for IP
Network Infrastructure WG of the IETF.
Title : Enhanced Feasible-Path Unicast Reverse Path Filtering
Authors : Kotikalapudi Sriram
Doug Montgomery
Jeffrey Haas
Filename : draft-ietf-opsec-urpf-improvements-02.txt
Pages : 16
Date : 2019-04-04
Abstract:
This document identifies a need for improvement of the unicast
Reverse Path Filtering techniques (uRPF) [BCP84] for source address
validation (SAV) [BCP38]. The strict uRPF is inflexible about
directionality, the loose uRPF is oblivious to directionality, and
the current feasible-path uRPF attempts to strike a balance between
the two [BCP84]. However, as shown in this draft, the existing
feasible-path uRPF still has shortcomings. This document describes
an enhanced feasible-path uRPF technique, which aims to be more
flexible (in a meaningful way) about directionality than the
feasible-path uRPF. It can potentially alleviate ISPs' concerns
about the possibility of disrupting service for their customers, and
encourage greater deployment of uRPF techniques.
The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-opsec-urpf-improvements/
There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-opsec-urpf-improvements-02
https://datatracker.ietf.org/doc/html/draft-ietf-opsec-urpf-improvements-02
A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-opsec-urpf-improvements-02
_______________________________________________
OPSEC mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/opsec