[spoofing-tf] More spoofing filtering references and experiences


You should also put RFC 3704 in the references. As a co-author, I'm a bit biased, but IMHO it's a much more useful and up-to-date take on the ingress filtering than RFC 2827.

For experiences in strict uRPF (we've deployed it in all the customer (regardless of size) links for years), and some other types of ingress filtering for peers and upstreams check out:


It will be revised within a couple of weeks, so comments are welcome.

Pekka Savola                 "You each name yourselves king, yet the
Netcore Oy                    kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings