RFC 5358: BCP 140: Preventing Use of Recursive Nameservers in Reflector Attacks
Best Current Practice
- J. Damas
- F. Neves
- October 2008
- IETF publication
- Operations and Management Area
Abstract
This document describes ways to prevent the use of default configured recursive nameservers as reflectors in Denial of Service (DoS) attacks. It provides recommended configuration as measures to mitigate the attack. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.