D3 · Architecture

What is ingress filtering?

Ingress filtering blocks inbound traffic with spoofed source IP addresses — preventing IP spoofing attacks. BCP38 is the best practice for ISPs to implement it.
Ingress filtering + uRPF (Unicast Reverse Path Forwarding) at ISP level would eliminate most DDoS amplification attacks. Most organizations also need egress filtering to detect compromised internal hosts.
← Back to Glossary Practice Questions →