skip to content

An edge router forwards IPv4 directed broadcasts that arrive from the internet; why is that dangerous, and what does RFC 2644 require of routers?

level: seniorimportance: should knowfreq 24%

answer

  1. looks like unicast until the end
  2. one forged request, many replies
  3. a 1999 change of default
  4. the setting lives on the last hop

basics

~20 s

Forwarding outside directed broadcasts makes the network an amplifier: one forged echo request to its broadcast address draws replies from every answering host, all aimed at the victim. RFC 2644 updates RFC 1812 so routers block them by default.

solid answer

~40 s

A directed broadcast, such as `203.0.113.255` for network `203.0.113.0` with mask `255.255.255.0`, looks like unicast to every router except the **last hop**, which turns it into a link-layer broadcast. If that router accepts them from the internet, an attacker sends ICMP Echo Requests to the broadcast address with the **victim's forged source address**, and every responding host replies to the victim: the classic **Smurf** amplification. RFC 1812 (1995) required forwarding by default with an option to disable it; **RFC 2644** (1999, BCP 34) reversed that, so options to receive and forward network-prefix-directed broadcasts must default to blocking. Enable it only where a named need exists, and keep ingress filtering of forged sources, which RFC 2644 calls the better defence.

go deeper

for a junior

Recall that a directed broadcast is a network's all-ones host address and that routers now refuse to forward it by default.

for a middle

Explain why only the last-hop router can recognise a directed broadcast and how RFC 2644 changed RFC 1812's default from forward to block.

for a senior

Walk through the amplification: a forged source, one request to a broadcast address, many replies to the victim. Then show how you would audit edge interfaces and allow narrow exceptions.

for a principal

Weigh legitimate remote-subnet needs against amplification risk, and argue for defaults that fail closed plus source validation as the layered defence.

## What a directed broadcast is A **directed broadcast** is an IPv4 address formed from a network's prefix with the **host part set to all ones**. For network `203.0.113.0` with mask `255.255.255.0` it is `203.0.113.255`. It means "every host on that network", and unlike limited broadcast (`255.255.255.255`, which never leaves the sender's link) it can be sent from anywhere. ## Only the last-hop router can recognise it RFC 1812 explains a property that shapes the whole problem: 1. A router far from the target network sees `203.0.113.255` as an ordinary destination. It does not know that network's mask, and under classless addressing an all-ones last octet can be a normal host: in `198.51.100.0` with mask `255.255.254.0`, the address `198.51.100.255` is an ordinary host. 2. So every transit router forwards it like unicast, by longest-prefix match. 3. The router **attached** to `203.0.113.0` knows the mask, recognises the all-ones host part, and delivers the datagram as a **link-layer broadcast** to every host there. RFC 1812 says the forwarding decision is "by definition only possible in the last hop router". That is also why the control has to live on that router. ## How the default changed | Specification | Rule for network-prefix-directed broadcasts | |---|---| | RFC 1812 (1995), router requirements | Given a route and no overriding policy, a router MUST forward them; it MUST have an option to disable forwarding, and that option MUST default to permit | | RFC 2644 (1999), BCP 34 | Updates RFC 1812: a router MAY have options to enable receiving and forwarding them, and those options MUST default to **blocking** both | RFC 2644 does not forbid the feature outright. It makes it off unless an operator deliberately turns it on for a specific interface. ## Why forwarding them from outside is dangerous RFC 2644 names the reason: **Smurf attacks**, which target networks that permit directed broadcasts from outside and turn them into "Smurf amplifiers". The mechanism: 1. The attacker sends ICMP Echo Requests (the messages ping uses) to the directed broadcast address of a large remote network. 2. Each request carries a **forged source address**: the victim's. 3. The last-hop router converts each request into a link-layer broadcast, so every host on the network receives it. 4. Every host that answers sends an Echo Reply to the forged source, the victim. One small packet from the attacker becomes as many replies as there are responding hosts. The amplifier's own network suffers too, because each attack packet becomes a broadcast on its link. ## What to check and change on the edge router - **Confirm the setting on every interface facing hosts**, since only the router attached to a network can forward its directed broadcasts. An edge router doing it is exactly what RFC 2644 says must not be the default. - **Turn it off unless there is a named need.** Where one exists, such as waking or discovering every machine on a remote subnet, enable it only on the interface toward that subnet and only from known sources, or use a relay that re-sends a request as unicasts. - **Keep host-side defences.** RFC 1122 lets a host silently discard an Echo Request sent to a broadcast or multicast address, which removes it from the amplifier even if a router leaks the broadcast. - **Do not treat this as the whole fix.** RFC 2644 says ingress filtering of forged source addresses remains the best way to limit these attacks; source validation and absorbing the resulting traffic are separate defences. ## Related rules worth naming - **Limited broadcast** is never forwarded by any router, regardless of configuration (RFC 1812). - A directed broadcast must never be used as a **source** address (RFC 1122, RFC 1812). - **Subnet-directed** and network-directed broadcasts are the same thing under classless addressing; RFC 1812 treats both as network-prefix-directed broadcasts, since a router cannot tell a subnet from a network without the mask. - The old **all-subnets** broadcast, aimed at every subnet of a classful network, is deprecated: RFC 1812 calls it meaningless under classless addressing. ## What interviewers listen for - That transit routers cannot recognise a directed broadcast, so the control sits on the last hop. - The amplification arithmetic: one forged request, many replies to the victim. - The history: RFC 1812's forward-by-default reversed by RFC 2644's block-by-default.

  • Why can't a transit IPv4 router simply drop every datagram whose last octet is 255?
    It does not know the remote network's mask, and under classless addressing an all-ones last octet can be an ordinary host. In network `198.51.100.0` with mask `255.255.254.0`, `198.51.100.255` is a normal host address. RFC 1812 precludes inspecting the host part of remote prefixes, so only the router attached to the network can decide.
  • When is enabling directed-broadcast forwarding justified, and how would you limit it?
    When something genuinely must reach every host on a remote subnet, such as waking or discovering all machines there. Enable it only on the interface toward that subnet, accept it only from known management sources, and prefer a relay that converts one request into unicasts, so the default stays blocking everywhere else.

A letter addressed to 'every resident of 12 Elm Street' looks like any other letter to the sorting offices it passes through; only the final delivery office knows the building has forty flats and makes forty copies. If anyone can post such letters with a forged return address, one letter becomes forty replies to an innocent stranger.

saying these in an interview costs you the question

  • Routers never forward any broadcast, so directed broadcasts are harmless.
  • Any IPv4 address ending in .255 is a broadcast address.
  • RFC 1812 still applies: routers forward directed broadcasts by default.
  • Blocking directed broadcasts makes ingress filtering unnecessary.
  • Every router on the path can spot and drop a directed broadcast.