October 2020
Intermediate to advanced
481 pages
17h 35m
English
Ingress and egress filtering are common filtering practices to eliminate spoofing. A source address that comes from the opposite side of the firewall than where it is assigned is obviously a spoofed address. For example, this happens when an internal LAN address appears as a source address in a packet on its way into a network from outside. This form of spoof filtering can be part of ingress filtering.
Likewise, the same process can filter for packets leaving a network. If a packet with a source address from the outside, such as an Internet address, is received by a firewall from an interface inside the private LAN, this is also a spoofed address. This form of spoof filtering can be part of egress filtering.
Read now
Unlock full access