Connected: An Internet Encyclopedia
5.3.13.4 Source Route Options

Up: Connected: An Internet Encyclopedia
Up: Requests For Comments
Up: RFC 1812
Up: 5. INTERNET LAYER - FORWARDING
Up: 5.3 SPECIFIC ISSUES
Up: 5.3.13 IP Options
Prev: 5.3.13.3 Stream Identifier Option
Next: 5.3.13.5 Record Route Option

5.3.13.4 Source Route Options

5.3.13.4 Source Route Options

A router MUST implement support for source route options in forwarded packets. A router MAY implement a configuration option that, when enabled, causes all source-routed packets to be discarded. However, such an option MUST NOT be enabled by default.

DISCUSSION

The ability to source route datagrams through the Internet is important to various network diagnostic tools. However, source routing may be used to bypass administrative and security controls within a network. Specifically, those cases where manipulation of routing tables is used to provide administrative separation in lieu of other methods such as packet filtering may be vulnerable through source routed packets.

EDITORS+COMMENTS

Packet filtering can be defeated by source routing as well, if it is applied in any router except one on the final leg of the source routed path. Neither route nor packet filters constitute a complete solution for security.


Next: 5.3.13.5 Record Route Option

Connected: An Internet Encyclopedia
5.3.13.4 Source Route Options