Re: [Dcpel] DCPEL Proposal

Roland Bless <bless@tm.uka.de> Fri, 07 October 2005 12:24 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1ENrGe-0004mH-5g; Fri, 07 Oct 2005 08:24:04 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1ENrGc-0004m8-IN for dcpel@megatron.ietf.org; Fri, 07 Oct 2005 08:24:02 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id IAA14577 for <dcpel@ietf.org>; Fri, 7 Oct 2005 08:24:01 -0400 (EDT)
Received: from iramx1.ira.uni-karlsruhe.de ([141.3.10.80] ident=[U2FsdGVkX196Hywpvf2qidQfaFdE7ip6EylgYCP4RBE=]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1ENrPt-0003fg-Ly for dcpel@ietf.org; Fri, 07 Oct 2005 08:33:38 -0400
Received: from i72ms2.tm.uni-karlsruhe.de ([141.3.70.17] helo=smtp.ipv6.tm.uni-karlsruhe.de) by iramx1.ira.uni-karlsruhe.de with esmtps id 1ENrGX-0002Hd-D8 for <dcpel@ietf.org>; Fri, 07 Oct 2005 14:23:59 +0200
Received: from vorta.ipv6.tm.uni-karlsruhe.de (vorta.ipv6.tm.uni-karlsruhe.de [IPv6:2001:638:204:6:207:e9ff:fe0c:5e44]) by smtp.ipv6.tm.uni-karlsruhe.de (Postfix) with ESMTP id D2E378B6E for <dcpel@ietf.org>; Fri, 7 Oct 2005 14:23:55 +0200 (CEST)
Received: from localhost ([127.0.0.1]) by vorta.ipv6.tm.uni-karlsruhe.de with esmtp (Exim 4.44) id 1ENrGV-0004fi-Fy for dcpel@ietf.org; Fri, 07 Oct 2005 14:23:55 +0200
Message-ID: <434668DA.3010302@tm.uka.de>
Date: Fri, 07 Oct 2005 14:23:54 +0200
From: Roland Bless <bless@tm.uka.de>
Organization: Institute of Telematics, University of Karlsruhe
User-Agent: Mozilla Thunderbird 1.0.7 (X11/20050923)
X-Accept-Language: de-DE, de, en-us, en
MIME-Version: 1.0
To: dcpel@ietf.org
Subject: Re: [Dcpel] DCPEL Proposal
References: <43464A00.2020909@tm.uka.de>
In-Reply-To: <43464A00.2020909@tm.uka.de>
X-Enigmail-Version: 0.92.0.0
Content-Type: text/plain; charset="ISO-8859-15"
Content-Transfer-Encoding: 7bit
X-Spam-Score: -4.5 (----)
X-Spam-Status: No
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 08170828343bcf1325e4a0fb4584481c
Content-Transfer-Encoding: 7bit
X-BeenThere: dcpel@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Mailing list for possible diffserv control plane elements WG <dcpel.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/dcpel>, <mailto:dcpel-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/dcpel>
List-Post: <mailto:dcpel@ietf.org>
List-Help: <mailto:dcpel-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/dcpel>, <mailto:dcpel-request@ietf.org?subject=subscribe>
Sender: dcpel-bounces@ietf.org
Errors-To: dcpel-bounces@ietf.org

Hi,

I forgot to mention that an important operational point
is the security. The correct operation of DiffServ networks
depends heavily on a correct marking at the first-hop/boundary
node. Due to aggregation it is usually later not easily possible
to figure out a particular non-admitted flow...
Consequently, one should probably use an IPsec tunnel for packets
sent to the first-hop router in order to authenticate packets from
legitimate users and thus to prevent theft of resources
etc. This IMHO would increase the operational complexity
a lot...

Regards,
 Roland

_______________________________________________
Dcpel mailing list
Dcpel@ietf.org
https://www1.ietf.org/mailman/listinfo/dcpel