Re: [bess] About draft-brissette-bess-evpn-l2gw-proto-03

"Rabadan, Jorge (Nokia - US/Mountain View)" <jorge.rabadan@nokia.com> Tue, 06 November 2018 01:50 UTC

Return-Path: <jorge.rabadan@nokia.com>
X-Original-To: bess@ietfa.amsl.com
Delivered-To: bess@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F386F130DD1; Mon, 5 Nov 2018 17:50:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.37
X-Spam-Level:
X-Spam-Status: No, score=-2.37 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.47, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nokia.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H7hVT2C4S8QF; Mon, 5 Nov 2018 17:49:58 -0800 (PST)
Received: from EUR01-VE1-obe.outbound.protection.outlook.com (mail-ve1eur01on0136.outbound.protection.outlook.com [104.47.1.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5A61C1294D0; Mon, 5 Nov 2018 17:49:58 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nokia.onmicrosoft.com; s=selector1-nokia-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=DEuusxj7Z78ykvyp2frfRy0nKFbjb3SgANN21JWC0z0=; b=oB3SYopo3mmIGrKtLyN1O+uAWpGnOeMpBABGdJDa7j/UvD6N+kYjurgoaDOLKt/qVGD8eQ7jerANohufBFpodu7ulRMFpfhzeYI2XE9dpa1rzx6Ep+iud+irqZVVB4ZH+Kz8ZXj728QshpjrffV9+QZ/qlxGSHUG7EmXFOIYlHA=
Received: from AM0PR07MB3844.eurprd07.prod.outlook.com (52.134.82.20) by AM0PR07MB5443.eurprd07.prod.outlook.com (20.178.22.25) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1294.27; Tue, 6 Nov 2018 01:49:55 +0000
Received: from AM0PR07MB3844.eurprd07.prod.outlook.com ([fe80::6996:3137:3456:ae8]) by AM0PR07MB3844.eurprd07.prod.outlook.com ([fe80::6996:3137:3456:ae8%5]) with mapi id 15.20.1294.032; Tue, 6 Nov 2018 01:49:55 +0000
From: "Rabadan, Jorge (Nokia - US/Mountain View)" <jorge.rabadan@nokia.com>
To: "Patrice Brissette (pbrisset)" <pbrisset@cisco.com>, "bess@ietf.org" <bess@ietf.org>, "draft-brissette-bess-evpn-l2gw-proto.authors@ietf.org" <draft-brissette-bess-evpn-l2gw-proto.authors@ietf.org>
Thread-Topic: About draft-brissette-bess-evpn-l2gw-proto-03
Thread-Index: AQHUdOwx/aMfxuqyz0+2Tgv3Lm4QIKVB60kAgACGPgA=
Date: Tue, 06 Nov 2018 01:49:55 +0000
Message-ID: <C8E3B625-ABDC-4A7C-993C-21903904F588@nokia.com>
References: <7BA1CB85-2E25-499F-A183-61C997A81B35@nokia.com> <D0B43760-3028-484D-AE8B-0F0B1E515EC8@cisco.com>
In-Reply-To: <D0B43760-3028-484D-AE8B-0F0B1E515EC8@cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.12.0.181014
x-originating-ip: [31.133.188.73]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; AM0PR07MB5443; 6:lHyh4vbkgP2vLyDkTSgxoPBZWWlJ9qTEJU4cUvmDXRmhqklg7ZnaxA+6vmVkxQQK014a2WEK/12FhX+G1AjRnXd4Y2UdYIlOFY182DzwgCC4cF+pENqr65sOQt7EeDrKVEcUss5xfra/GID7uE+xdW1S27A70x4z9MGHL6ZPlXFyVvBf9H177DSpqCHSDc/GUFBwCr0yXK3GlWIpXP8HebnvlXn74/b4A5ccK6PlV5+n82pt/N1x0+ExPRR1NXODPQqmDtUH2jVUXxADABJRNpaIbo5JV+9YCvlZV6qMSoldHY1vSrShKgUm0tgjE3gD0yBDz5ure2ERqQRdlvMGuDvmIIBO5I8zbU68NqnY9t9giSQQk58B9Fm6RPgNMR4eX0fWhoXOk5MxqoPP5DWhddZYA4vXdbEALyd6l2AXiyNU3AFFFJi8zi+6qXYDcGN7uHNLTNAzq5C/qxFMmV3EWQ==; 5:N2f1q2fr59Y5IaLTU6wQtFUC3gFuKQdACrBnoBXy1mLZOXJkGGr//Mj9mIxjzXepPsIenhw0idRmePDpFhLasq/Ayw8ptIY6h9GgRyCeVFTGwDs9Z/eGVIxsB+m6B/5Q9sODcdXYtFEToZZhnd7si4NKz3r+7Yt7g6DOI5JDFt8=; 7:2ucqxh/qpcBqWrHPbYQHmK6rAsAsbVAcqngG0LDq5GUO+ikS1/6gjt1b1kEkPtOUBO3R8K9Ouvc6htLfZ2x5HgjNBJPfRkXhbWz8cP6MJ9/MOr1FHcP+dFjYi1s2lC2Fe5Hb48ez5w2yJ3XcIJ4wXQ==
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-correlation-id: 58d6cd81-5d14-4ea2-54e0-08d6438a26ef
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(7020095)(4652040)(8989299)(5600074)(711020)(4618075)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(2017052603328)(7193020); SRVR:AM0PR07MB5443;
x-ms-traffictypediagnostic: AM0PR07MB5443:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=jorge.rabadan@nokia.com;
x-microsoft-antispam-prvs: <AM0PR07MB544382A91D769DCF3AE24AE4F7CB0@AM0PR07MB5443.eurprd07.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(163750095850)(95692535739014)(82608151540597)(195916259791689)(109105607167333)(99650590838007)(83196854966205);
x-ms-exchange-senderadcheck: 1
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(5005006)(8121501046)(3002001)(93006095)(93001095)(10201501046)(3231382)(11241501184)(806099)(944501410)(52105095)(6055026)(148016)(149066)(150057)(6041310)(20161123558120)(20161123562045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123564045)(20161123560045)(201708071742011)(7699051)(76991095); SRVR:AM0PR07MB5443; BCL:0; PCL:0; RULEID:; SRVR:AM0PR07MB5443;
x-forefront-prvs: 0848C1A6AA
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(396003)(136003)(376002)(39860400002)(366004)(346002)(189003)(199004)(13464003)(6116002)(2906002)(106356001)(6436002)(186003)(83716004)(6506007)(53546011)(102836004)(99286004)(11346002)(229853002)(71190400001)(86362001)(25786009)(3846002)(71200400001)(2900100001)(82746002)(97736004)(14444005)(36756003)(7736002)(6306002)(256004)(478600001)(110136005)(14454004)(6512007)(486006)(53936002)(6246003)(2616005)(76176011)(26005)(476003)(68736007)(305945005)(6486002)(66066001)(81166006)(58126008)(561944003)(33656002)(446003)(81156014)(5660300001)(316002)(2201001)(8676002)(8936002)(2501003)(105586002); DIR:OUT; SFP:1102; SCL:1; SRVR:AM0PR07MB5443; H:AM0PR07MB3844.eurprd07.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: nokia.com does not designate permitted sender hosts)
x-microsoft-antispam-message-info: bFeH1SVe8k5LLZ4oIF5FFlBeETUVHsuEEuTTVBeZAlyyJW/qOIb5Da3Jr7Y7yZJXmRl3k5lpzi4yeqmOLGVcB9G8bhD6zJ5lwVZlMBXEFayv+KyLefUAyqeVUxiLtkyY6ko/WTlQTKLfAgvH2smalF3Sj892mQIIJMg11fLzxm44Dhz0S2bh1EBQGRhDRZZFbSLtguMXLod5Ws7oTXwBwk2f9PF7jvIv/J+r+xKfqny+hPuAZ5sWm9KdTrMFMma0ITK17f7f6ur5KdGUNDeiCn1cklJutxV5K1I3wpgsyLHctwr8hHyQztHUvlgzfO97Wh2B0HVi2o877p1RYja8yBhZPMwb/etuX56f4Ecm77k=
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-ID: <EB48DD0EAA8EF043A0C23D597573B001@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: nokia.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 58d6cd81-5d14-4ea2-54e0-08d6438a26ef
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Nov 2018 01:49:55.6790 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5d471751-9675-428d-917b-70f44f9630b0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM0PR07MB5443
Archived-At: <https://mailarchive.ietf.org/arch/msg/bess/-fmifOlY1642cnMJ0bu4E80Yxow>
Subject: Re: [bess] About draft-brissette-bess-evpn-l2gw-proto-03
X-BeenThere: bess@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: BGP-Enabled ServiceS working group discussion list <bess.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/bess>, <mailto:bess-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bess/>
List-Post: <mailto:bess@ietf.org>
List-Help: <mailto:bess-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/bess>, <mailto:bess-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 06 Nov 2018 01:50:03 -0000

Hi Patrice,

Thank you. Please see more in-line with [JORGE].

Thx
Jorge

-----Original Message-----
From: "Patrice Brissette (pbrisset)" <pbrisset@cisco.com>
Date: Tuesday, November 6, 2018 at 7:49 AM
To: "Rabadan, Jorge (Nokia - US/Mountain View)" <jorge.rabadan@nokia.com>, "bess@ietf.org" <bess@ietf.org>, "draft-brissette-bess-evpn-l2gw-proto.authors@ietf.org" <draft-brissette-bess-evpn-l2gw-proto.authors@ietf.org>
Subject: Re: About draft-brissette-bess-evpn-l2gw-proto-03

    Hi Jorge,
    
    Please see my comments below ... <PATRICE>
    
    Regards,
     
    Patrice Brissette, Principal Engineer
    Cisco Systems
    Help us track your SP SR/EVPN Customer Opportunity/Status by filling these forms: Segment Routing <https://app.smartsheet.com/b/form/185833ace35b4894b324dfb8afbd2060> / EVPN <https://app.smartsheet.com/b/form/136bd5c3a22641bf92316523e79d6f22>
     
     
    
    On 2018-11-05, 4:44 PM, "Rabadan, Jorge (Nokia - US/Mountain View)" <jorge.rabadan@nokia.com> wrote:
    
        Dear authors,
        
        Some comments about this draft:
        
        1- the draft uses some 'non-standard' terminology. Could you use RFC7432 terminology please? An example of 'non-standard' term is EVLAG.
    <PATRICE> Will do
[JORGE] thank you.
        
        2- the draft proposes a solution for something that works today without the need of a multi-homed Ethernet Segment or any new procedures:
        - There are already EVPN deployments that use STP/G.8032 access rings.
        - The two EVPN PEs that close the ring can participate of the ring protocol, therefore the received mac flush messages will withdraw the required MAC/IP routes. 
        - Since the remote PEs will forward normally based on their MAC FIB (populated by MAC/IP routes), there is no need to specify a new "Single Flow Active" forwarding mode. This is normal MAC based forwarding. Why do we need to create a new mode?? Can you please explain?
        - Besides, by adding a bit in the ESI-label ext community different than the single-active bit, you make the solution non-backwards compatible.
    
    <PATRICE> I'm not sure why you are mentioning the draft is NOT backward compatible. You need to explain that one. May I should add "remote PE not support single-flow-active bit may ignore this mode"
[JORGE] Sure, this is what I mean: A PE that receives a non-zero ESI AD per-ES route is REQUIRED to process the route as per RFC7432. The route MUST include the extended community. The PE also needs to check the single-active bit, which can be 0 or 1. Depending on that bit, a non-upgraded PE will either behave as all-active or single-active. If you use a different bit, in the best case scenario the PE will ignore it and will behave as all-active, so your solution won't work. In the worst case scenario, the PE may 'treat as withdraw' the route.


    <PATRICE> It is true you can support ring using single-homed and you are welcome to do so. However, there are important drawbacks. For example, how do you achieve ARP and MAC sync?
[JORGE] I don't think you should sync MAC/ARPs in this scenario. In your figure 1, if you have MAC1 connected to CE2, and PE1 advertises MAC1, you don't want to sync MAC1 in PE2 against the ring ESI because PE2 can't reach MAC1 through AC2, right? 
    
        
        3- Section 6 - why do you define yet another extended community for mac flush, when we already have one? (RFC7623)
    
    <PATRICE> It is true that we can reuse the MAC mobility from RFC7623. Note taken
[JORGE] thanks!
        
        4- there is some value in the proposal though - the mass withdrawal (per-BD or per-ES) as opposed to per-MAC withdrawal may speed up convergence. Here is an alternative solution that can achieve the same thing and it's backwards compatible with RFC7432:
        
        On the L2GWs:
        a) Define a single-homed non-zero ESI per L2GW PW. The ESI can be auto-derived easily as type 3/4 and be made unique in the network.
        b) Since the ES is defined in a single PE, the ES routes will be filtered by the RR (use RTC) and won't ever reach other PEs. Alternatively you can disable the ES routes.
        c) This L2GW ES will be single-active mode (although it does not matter much).
        d) Since the ES is not shared across the L2GWs, each L2GW will always be DF for all the local VLANs. 
        e) Each L2GW will send AD per-ES and per-EVI routes for its ESI.
        f) When the L2GW receives a mac-flush notification (STP TCN, G.8032 mac-flush, TLDP MAC withdrawal etc.), the L2GW sends an update of the AD per-EVI route with the MAC Mobility extended community and a higher sequence number - note that we borrow this well-known mac flush procedure from RFC7623, only for AD per-EVI routes.
        
    <PATRICE> As we demonstrated yesterday, there many cases where single-active or all-active are simply not working. Relying on single-homed is not sufficient even with an ESI. I already gave the example of ARP/MAC sync. 
[JORGE] see my comment above. Sorry that I missed your presentation yesterday. Could you please clarify for me how you do ARP/MAC sync so that it works when the protocol in the ring decides to block a link between CEs? Again, sorry if I missed this, but it is important to understand the solution.
    
    
        On the remote PEs:
        g) The MACs will be learned against the ESIs, but there will only be one next-hop per ES. No aliasing or no backup. And RFC7432-compatible.
        h) Upon receiving an AD per-EVI update with a higher SEQ number, the PE flushes all the MACs for the BD. If the PE does not understand the MAC Mobility ext comm in the AD per-EVI route, it won't do anything and will simply flush MACs based on MAC/IP route withdrawals.
        i) Upon receiving an AD per-ES route withdrawal the PE will do mass withdrawal for all the affected BDs (this is the case where the L2GW local ES goes down).
    
    <PATRICE> I think you are considering only failure visible by PE only.
[JORGE] The AD per-EVI update can be generated upon receiving a TCN/mac-flush message, so a physical failure on a CE regardless of where. For the AD per-ES route, yes, failure on the PE itself.
        
        Please let me know your comments.
        
        Thank you.
        Jorge