Hiding Transit-only Networks in OSPF

Document Type Expired Internet-Draft (individual)
Last updated 2011-05-23
Stream (None)
Intended RFC status (None)
Expired & archived
pdf htmlized (tools) htmlized bibtex
Stream Stream state (No stream defined)
Consensus Boilerplate Unknown
RFC Editor Note (None)
IESG IESG state Expired
Telechat date
Responsible AD (None)
Send notices to (None)

This Internet-Draft is no longer active. A copy of the expired Internet-Draft can be found at


A transit-only network is defined as a network connecting routers only. In OSPF, transit-only networks are usually configured with routable IP addresses, which are advertised in LSAs but not needed for data traffic. In addition, remote attacks can be launched against routers by sending packets to these transit-only networks. This document presents a mechanism to hide transit-only networks to speed up network convergence and minimize remote attack vulnerability.


Yi Yang (yiya@cisco.com)
Alvaro Retana (alvaro.retana@hp.com)
Abhay Roy (akr@cisco.com)

(Note: The e-mail addresses provided for the authors of this Internet-Draft may no longer be valid.)