Internet Engineering Task Force (IETF) L. Vegoda
Request for Comments: 6441 ICANN
BCP: 171 November 2011
Category: Best Current Practice
ISSN: 2070-1721
Time to Remove Filters for Previously Unallocated IPv4 /8s
Vegoda Best Current Practice [Page 1]
RFC 6441 Remove /8 Filters November 2011
Table of Contents
1. Introduction
It has been common for network administrators to filter IP traffic from and BGP prefixes of unallocated IPv4 address space. Now that there are no longer any unallocated IPv4 /8s, this practise is more complicated, fragile, and expensive. Network administrators are advised to remove filters based on the registration status of the address space.
2. Terminology
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14, RFC 2119 [RFC2119].
Vegoda Best Current Practice [Page 2]
RFC 6441 Remove /8 Filters November 2011 3. Traffic Filtering Options 3.1. No Longer Filtering Based on Address Registration StatusNetwork administrators who implemented filters for unallocated IPv4 /8s did so in the knowledge that those /8s were not a legitimate source of traffic on the Internet and that there was a small number of bogon filters to implement. Now that there are no longer any unallocated unicast IPv4 /8s, there will be legitimate Internet traffic coming from all unicast /8s that are not reserved for special purposes in an RFC.
3.2. Continuing to Filter Traffic from Unallocated IPv4 Space
Some network administrators might want to continue filtering unallocated IPv4 addresses managed by the RIRs. This requires significantly more granular ingress filters and the highly dynamic nature of the RIRs' address pools means that filters need to be updated on a daily basis to avoid blocking legitimate incoming traffic.
4. Prefixes That Should Not be Routed across the Internet
Network operators may deploy filters that block traffic destined for Martian prefixes. Currently, the Martian prefix table is defined by [RFC5735] which reserves each Martian prefix for some specific, special use. If the Martian prefix table ever changes, that change will be documented in an RFC that either updates or obsoletes [RFC5735].
5. Security Considerations
The cessation of filters based on unallocated IPv4 /8 allocations is an evolutionary step towards reasonable security filters. While these filters are no longer necessary, and in fact harmful, this does not obviate the need to continue other security solutions. These other solutions are as necessary today as they ever were.
Vegoda Best Current Practice [Page 3]
RFC 6441 Remove /8 Filters November 2011 6. References 6.1. Normative References[RFC2119] Bradner, S., "Key words for use in RFCs to Indicate
6.2. Informative References
[RFC1208] Jacobsen, O. and D. Lynch, "Glossary of networking terms",
Vegoda Best Current Practice [Page 4]
RFC 6441 Remove /8 Filters November 2011 Appendix A. AcknowledgmentsThanks are owed to Kim Davies, Terry Manderson, Dave Piscitello, and Joe Abley for helpful advice on how to focus this document. Thanks also go to Andy Davidson, Philip Smith, and Rob Thomas for early reviews and suggestions for improvements to the text, and to Carlos Pignataro for his support and comments.