[Gen-art] Gen-ART review of draft-ietf-opsec-ip-security-05

"Vijay K. Gurbani" <vkg@bell-labs.com> Mon, 03 January 2011 18:00 UTC

Return-Path: <vkg@bell-labs.com>
X-Original-To: gen-art@core3.amsl.com
Delivered-To: gen-art@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id C57943A6A36 for <gen-art@core3.amsl.com>; Mon, 3 Jan 2011 10:00:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -106.375
X-Spam-Level:
X-Spam-Status: No, score=-106.375 tagged_above=-999 required=5 tests=[AWL=0.224, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iVJ+ykTkTgeZ for <gen-art@core3.amsl.com>; Mon, 3 Jan 2011 10:00:45 -0800 (PST)
Received: from ihemail4.lucent.com (ihemail4.lucent.com [135.245.0.39]) by core3.amsl.com (Postfix) with ESMTP id 09DC43A69DA for <gen-art@ietf.org>; Mon, 3 Jan 2011 10:00:44 -0800 (PST)
Received: from umail.lucent.com (h135-3-40-63.lucent.com [135.3.40.63]) by ihemail4.lucent.com (8.13.8/IER-o) with ESMTP id p03I2jnW006524 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 3 Jan 2011 12:02:45 -0600 (CST)
Received: from shoonya.ih.lucent.com (Knoppix-135185238233.ih.lucent.com [135.185.238.233]) by umail.lucent.com (8.13.8/TPES) with ESMTP id p03I2hcq002227; Mon, 3 Jan 2011 12:02:44 -0600 (CST)
Message-ID: <4D220FCF.2040805@bell-labs.com>
Date: Mon, 03 Jan 2011 12:05:03 -0600
From: "Vijay K. Gurbani" <vkg@bell-labs.com>
Organization: Bell Laboratories, Alcatel-Lucent
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.1.15) Gecko/20101027 Fedora/3.0.10-1.fc12 Thunderbird/3.0.10
MIME-Version: 1.0
To: draft-ietf-opsec-ip-security@tools.ietf.org
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Scanned-By: MIMEDefang 2.57 on 135.245.2.39
Cc: Ron Bonica <rbonica@juniper.net>, General Area Review Team <gen-art@ietf.org>, warren@kumari.net, jabley@hopcount.ca
Subject: [Gen-art] Gen-ART review of draft-ietf-opsec-ip-security-05
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/gen-art>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 03 Jan 2011 18:00:46 -0000

I am the assigned Gen-ART reviewer for this draft. For background on
Gen-ART, please see the FAQ at
<http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq>.

Please resolve these comments along with any other Last Call comments
you may receive.

Document: draft-ietf-opsec-ip-security-05
Reviewer: Vijay K. Gurbani
Review Date: Jan-03-2011
IETF LC End Date: Dec-12-2010
IESG Telechat date: Unknown

Summary: This draft is ready as an Informational RFC.
Major issues: 0
Minor issues: 0
Nits/editorial comments: 9

Sorry for the late review, I note that this document is in
IESG evaluation state, so I suspect that one more revision
may be required.  If so, I hope the following feedback aids
in improving an already excellent document.

1) S3.3.2.2, page 14 --- please expand the acronym "RED" on first use.

2) S3.5.1, top of end of page 16 and top of page 17 --- "Linux (and
  Solaris) later set the IP Identification field on a per-IP address
  basis."  Which address --- source or destination?

3) S3.5.2.2, page 18 --- s/Packet loss is can be/Packet loss can be/

4) S3.6, underneath Figure 5 on page 20 ---
  s/In Figure 3, an attacker/In Figure 5, an attacker/

5) Same section, same page ---
  s/router that encounters that this/router to determine that this/

6) S3.7 --- when discussing the Fragment Offset, is it worth
  stating that the Fragment Offset is measured in units of 8 octets
  (thereby giving the magic number 65528 = 8191*8)?

7) S3.8.4, page 26, last bullet item at top of page ---
  s/Four hops away from D./Two hops away from D./

8) S4.1.1.3, page 51, last paragraph of that subsection ---
  Any references?

9) S4.1.1.4, page 52, first bullet item, first sentence ---
  what do you mean by "overlapping fragments"?  Maybe you meant,
  instead, "duplicate fragments"?

Thanks,

- vijay
-- 
Vijay K. Gurbani, Bell Laboratories, Alcatel-Lucent
1960 Lucent Lane, Rm. 9C-533, Naperville, Illinois 60566 (USA)
Email: vkg@{alcatel-lucent.com,bell-labs.com,acm.org}
Web:   http://ect.bell-labs.com/who/vkg/