Here are filters every network should implement.
Inbound filters:
- Reject private prefixes (, , )
- Reject your own prefixes (advertising your addresses is attack or misconfiguration)
- Reject default route unless wanted
- Reject prefixes longer than
Outbound filters:
- Only advertise your own and customer prefixes
- Don't advertise peer routes to other peers
- Don't advertise private ASNs
Bogon filtering: Block reserved or unallocated IP space.