[Dots] call-Home: Identification of the CPE when an on-path NAT

<mohamed.boucadair@orange.com> Fri, 09 November 2018 08:40 UTC

Return-Path: <mohamed.boucadair@orange.com>
X-Original-To: dots@ietfa.amsl.com
Delivered-To: dots@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 901CF127332 for <dots@ietfa.amsl.com>; Fri, 9 Nov 2018 00:40:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id V5TbOz05lsj9 for <dots@ietfa.amsl.com>; Fri, 9 Nov 2018 00:40:10 -0800 (PST)
Received: from orange.com (mta134.mail.business.static.orange.com [80.12.70.34]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C5A96124408 for <dots@ietf.org>; Fri, 9 Nov 2018 00:40:09 -0800 (PST)
Received: from opfednr05.francetelecom.fr (unknown [xx.xx.xx.69]) by opfednr25.francetelecom.fr (ESMTP service) with ESMTP id 42rtrS0QpszCrxR; Fri, 9 Nov 2018 09:40:08 +0100 (CET)
Received: from Exchangemail-eme2.itn.ftgroup (unknown [xx.xx.31.63]) by opfednr05.francetelecom.fr (ESMTP service) with ESMTP id 42rtrR6qbgzyQ5; Fri, 9 Nov 2018 09:40:07 +0100 (CET)
Received: from OPEXCLILMA3.corporate.adroot.infra.ftgroup ([fe80::60a9:abc3:86e6:2541]) by OPEXCLILM6E.corporate.adroot.infra.ftgroup ([fe80::f5a7:eab1:c095:d9ec%18]) with mapi id 14.03.0415.000; Fri, 9 Nov 2018 09:40:07 +0100
From: mohamed.boucadair@orange.com
To: "Panwei (William) (william.panwei@huawei.com)" <william.panwei@huawei.com>
CC: "dots@ietf.org" <dots@ietf.org>
Thread-Topic: call-Home: Identification of the CPE when an on-path NAT
Thread-Index: AdR4B9D3EgloP+x7Q3CYe1K0EJt0PQ==
Date: Fri, 09 Nov 2018 08:40:07 +0000
Message-ID: <787AE7BB302AE849A7480A190F8B93302E042CB4@OPEXCLILMA3.corporate.adroot.infra.ftgroup>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.168.234.4]
Content-Type: multipart/alternative; boundary="_000_787AE7BB302AE849A7480A190F8B93302E042CB4OPEXCLILMA3corp_"
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/dots/W8DMTHPJry4AmLY1otdoMashP9Q>
Subject: [Dots] call-Home: Identification of the CPE when an on-path NAT
X-BeenThere: dots@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "List for discussion of DDoS Open Threat Signaling \(DOTS\) technology and directions." <dots.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dots>, <mailto:dots-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dots/>
List-Post: <mailto:dots@ietf.org>
List-Help: <mailto:dots-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dots>, <mailto:dots-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 09 Nov 2018 08:40:12 -0000

Hi Wei,

You raised a comment about CPE identification when a NAT is present on path. I guess you are referring to the general issue discussed in : https://tools.ietf.org/html/rfc7620

In the particular case of call home, we assume that the access provider is the one providing the DOTS service. That is, if there is an address sharing mechanism (not only a basic NAT), that mechanism is also controlled by the same provider providing the DOTS server.

The correlation between external and internal reals can be achieved by a variety of means. For example, the use of the NETCONF/YANG (https://tools.ietf.org/html/draft-ietf-opsawg-nat-yang) or the access of the NAT MIB (RFC7659) allow to correlate both the internal and external realms, and therefore identify the appropriate CPE.

Please let us know If this clarifies your concern. Thank you.

We can update the draft to record this point.

Cheers,
Med