RE: Best practice ACLs for a internet facing border router?

ftp://ftp-eng.cisco.com/cons/isp/security/Ingress-Prefix-Filter-Template
s/

Florian

ftp://ftp-eng.cisco.com/cons/isp/security/Ingress-Prefix-Filter-Template
s/

Florian

The original question didn't specify whether the interest was prefixes or packet filters.

For packet filtering, the above URL is not going to help, but a read of BCP38 would be in order.

Edge sites with no downstreams can very easily filter the source addresses leaving their network and ensure no bogus-sourced packets leave, be they RFC1918, or spoofs.