Bogon filtering

From Wikipedia, the free encyclopedia
Jump to navigation Jump to search

Bogon filtering is the practice of filtering bogons, which are bogus (fake) IP addresses of a computer network. Bogons include IP packets on the public Internet that contain addresses that are not in any range allocated or delegated by the Internet Assigned Numbers Authority (IANA) or a delegated regional Internet registry (RIR) and allowed for public Internet use. The areas of unallocated address space are called the bogon space.

Bogons also include address ranges reserved for private networks[1], loopback interfaces, and link-local addresses, such as those in,,,, and These are sometimes also known as Martian packets.

Many ISPs and end-user firewalls filter and block bogons, because they have no legitimate use, and usually are the result of accidental misconfiguration or malicious intent. Bogons can be filtered by using router access-control lists (ACLs), or by BGP blackholing.

IP addresses that are currently in the bogon space may not be bogons at a later date because IANA and other registries frequently assign new address space to ISPs. Announcements of new assignments are often published on network operators' mailing lists (such as NANOG) to ensure that operators have a chance to remove bogon filtering for addresses that have become legitimate. For example, addresses in were not allocated prior to August 2010, but are now used by APNIC.[2] As time goes on, the IPv4 address exhaustion will mean there are fewer and fewer IPv4 bogons. IANA maintains a list of allocated and reserved IPv4 netblocks.[2]

As of November 2011, the IETF recommends that since there are no longer any unallocated IPv4 /8s, bogon filters based on registration status should be removed.[3] However, bogon filters still need to check for Martian packets.


The term bogon stems from hacker jargon, with the earliest appearance in the Jargon File in version 1.5.0 (dated 1983).[4] It is defined as the quantum of bogosity, or the property of being bogus. A bogon packet is frequently bogus both in the conventional sense of being forged for illegitimate purposes, and in the hackish sense of being incorrect, absurd, and useless.[citation needed]

These unused IP addresses are collectively known as a bogon, a contraction of "bogus logon", or a logon from a place you know no one can actually logon.[5]

See also[edit]


  1. ^ Y. Rekhter; B. Moskowitz; D. Karrenberg; G. J. de Groot; E. Lear (February 1996). Address Allocation for Private Internets. Network Working Group. doi:10.17487/RFC1918. BCP 5. RFC 1918. Obsoletes RFC 1627 and 1597. Updated by RFC 6761.
  2. ^ a b "IANA IPv4 Address Space Registry". IANA. 2010-02-22. Archived from the original on 2010-04-30. Retrieved 2010-03-18.
  3. ^ L. Vegoda (November 2011). Time to Remove Filters for Previously Unallocated IPv4 /8s. IETF. doi:10.17487/RFC6441. ISSN 2070-1721. BCP 171. RFC 6441.
  4. ^ Guy L. Steele Jr.; Donald R. Woods; Raphael A. Finkel; Mark R. Crispin; Richard M. Stallman; Geoffrey S. Goodfellow (1983). "The Hacker's Dictionary: A Guide to the World of Computer Wizards". Jargon File Text Archive : A large collection of historical versions of the Jargon File. Archived from the original on Nov 8, 2016. Retrieved 28 May 2021.
  5. ^ "Ian McAnerin and Mike Churchill - 2005". McAnerin Networks Inc. Archived from the original on 2007-04-14. Retrieved 16 May 2020.

External links[edit]