Re: [Gen-art] Gen-ART review of draft-ietf-tsvwg-behave-requirements-update

"Romascanu, Dan (Dan)" <dromasca@avaya.com> Mon, 15 February 2016 16:31 UTC

Return-Path: <dromasca@avaya.com>
X-Original-To: gen-art@ietfa.amsl.com
Delivered-To: gen-art@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 124101A007C for <gen-art@ietfa.amsl.com>; Mon, 15 Feb 2016 08:31:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.905
X-Spam-Level:
X-Spam-Status: No, score=-6.905 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-0.006] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LHM3eBLXdscZ for <gen-art@ietfa.amsl.com>; Mon, 15 Feb 2016 08:31:53 -0800 (PST)
Received: from de307622-de-outbound.net.avaya.com (de307622-de-outbound.net.avaya.com [198.152.71.100]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B69EE1A0092 for <gen-art@ietf.org>; Mon, 15 Feb 2016 08:31:49 -0800 (PST)
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A2D5AQAc/cFW/xUHmMZeGQEBAQEPAQEBAYI+IStSbQaFN7RgAQ2BZyCFbQKBNTgUAQEBAQEBAYEKhEEBAQEBAxIbTBACAQgNBAMBAQELFgcHMhQJCAEBBAENBQgah3gBDaMgmRQBAQEBAQEBAQEBAQEBAQEBAQEBAQEVhhKENIQyIA0JCIJtgQ8FjV+FD4QLAYVOiWJKg3mDGoU7hW+ITx4BAUKBTIIXagEBAYd5AXsBAQE
X-IPAS-Result: A2D5AQAc/cFW/xUHmMZeGQEBAQEPAQEBAYI+IStSbQaFN7RgAQ2BZyCFbQKBNTgUAQEBAQEBAYEKhEEBAQEBAxIbTBACAQgNBAMBAQELFgcHMhQJCAEBBAENBQgah3gBDaMgmRQBAQEBAQEBAQEBAQEBAQEBAQEBAQEVhhKENIQyIA0JCIJtgQ8FjV+FD4QLAYVOiWJKg3mDGoU7hW+ITx4BAUKBTIIXagEBAYd5AXsBAQE
X-IronPort-AV: E=Sophos;i="5.22,451,1449550800"; d="scan'208,217";a="142706982"
Received: from unknown (HELO co300216-co-erhwest-exch.avaya.com) ([198.152.7.21]) by de307622-de-outbound.net.avaya.com with ESMTP; 15 Feb 2016 11:31:46 -0500
X-OutboundMail_SMTP: 1
Received: from unknown (HELO AZ-FFEXHC04.global.avaya.com) ([135.64.58.14]) by co300216-co-erhwest-out.avaya.com with ESMTP/TLS/AES256-SHA; 15 Feb 2016 11:31:30 -0500
Received: from AZ-FFEXMB04.global.avaya.com ([fe80::6db7:b0af:8480:c126]) by AZ-FFEXHC04.global.avaya.com ([135.64.58.14]) with mapi id 14.03.0174.001; Mon, 15 Feb 2016 17:31:24 +0100
From: "Romascanu, Dan (Dan)" <dromasca@avaya.com>
To: "mohamed.boucadair@orange.com" <mohamed.boucadair@orange.com>, General Area Review Team <gen-art@ietf.org>
Thread-Topic: Gen-ART review of draft-ietf-tsvwg-behave-requirements-update
Thread-Index: AdFoDG1bAr2kmwOBSYap3KbgE7aDwwAAEJNwAABec9A=
Date: Mon, 15 Feb 2016 16:31:24 +0000
Message-ID: <9904FB1B0159DA42B0B887B7FA8119CA6BF1954D@AZ-FFEXMB04.global.avaya.com>
References: <9904FB1B0159DA42B0B887B7FA8119CA6BF19524@AZ-FFEXMB04.global.avaya.com> <787AE7BB302AE849A7480A190F8B933008CE2C34@OPEXCLILMA3.corporate.adroot.infra.ftgroup>
In-Reply-To: <787AE7BB302AE849A7480A190F8B933008CE2C34@OPEXCLILMA3.corporate.adroot.infra.ftgroup>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [135.64.58.48]
Content-Type: multipart/alternative; boundary="_000_9904FB1B0159DA42B0B887B7FA8119CA6BF1954DAZFFEXMB04globa_"
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/gen-art/wiPm3igAuD7RScydPIH33lijBrY>
Cc: "draft-ietf-tsvwg-behave-requirements-update.all@tools.ietf.org" <draft-ietf-tsvwg-behave-requirements-update.all@tools.ietf.org>
Subject: Re: [Gen-art] Gen-ART review of draft-ietf-tsvwg-behave-requirements-update
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/gen-art/>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Feb 2016 16:31:59 -0000

Hi Med,

Thank you for the quick answer and for addressing my comments. Your suggestions are fine with me.

Regards,

Dan


From: mohamed.boucadair@orange.com [mailto:mohamed.boucadair@orange.com]
Sent: Monday, February 15, 2016 6:29 PM
To: Romascanu, Dan (Dan); General Area Review Team
Cc: draft-ietf-tsvwg-behave-requirements-update.all@tools.ietf.org
Subject: RE: Gen-ART review of draft-ietf-tsvwg-behave-requirements-update

Hi Dan,

Thank you for the review.

Please see inline.

Cheers,
Med

De : Romascanu, Dan (Dan) [mailto:dromasca@avaya.com]
Envoyé : lundi 15 février 2016 17:18
À : General Area Review Team
Cc : draft-ietf-tsvwg-behave-requirements-update.all@tools.ietf.org<mailto:draft-ietf-tsvwg-behave-requirements-update.all@tools.ietf.org>
Objet : Gen-ART review of draft-ietf-tsvwg-behave-requirements-update


I am the assigned Gen-ART reviewer for this draft. The General Area Review Team (Gen-ART) reviews all IETF documents being processed by the IESG for the IETF Chair.  Please treat these comments just like any other last call comments.



For more information, please see the FAQ at



< http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq<https://urldefense.proofpoint.com/v2/url?u=http-3A__wiki.tools.ietf.org_area_gen_trac_wiki_GenArtfaq&d=BQMFAw&c=BFpWQw8bsuKpl1SgiZH64Q&r=I4dzGxR31OcNXCJfQzvlsiLQfucBXRucPvdrphpBsFA&m=ZC04CHRXTc4mZGTQ1SDzY8k4-iq-WKS6FwdW1xbjofw&s=faCxz22-2duDulDbAWv3aWHO3iJ5naIHyqseY1pxc40&e=>>



Document:  draft-ietf-tsvwg-behave-requirements-update-06

Reviewer: Dan Romascanu

Review Date: 2/15/16

IETF LC End Date: 2/16/16

IESG Telechat date:



Summary: This document is ready with minor issues.



Major issues:



None



Minor issues:



1.       The text in the second and third paragraphs in section 2.2 is rather confusing. Do these belong to updates, or should they be under Notes?



Ø  Admittedly, the NAT has to verify whether received TCP RST packets belong to a connection. This verification check is required to avoid off-path attacks.



Ø  If the NAT removes immediately the NAT mapping upon receipt of a TCP RST message, stale connections may be maintained by endpoints if the first RST message is lost between the NAT and the recipient.



If they belong to Updates 'Admittedly' needs to be dropped, 'has to verify' becomes 'SHOULD verify', etc.

Else, if these are rather notes they should be labeled Notes or Clarification



[Med] These are notes. What about making this change?



OLD:


      Admittedly, the NAT has to verify whether received TCP RST packets
      belong to a connection.  This verification check is required to
      avoid off-path attacks.

      If the NAT removes immediately the NAT mapping upon receipt of a
      TCP RST message, stale connections may be maintained by endpoints
      if the first RST message is lost between the NAT and the
      recipient.



NEW:



      Notes:

      *   Admittedly, the NAT has to verify whether received TCP RST packets

      belong to a connection.  This verification check is required to

      avoid off-path attacks.



      * If the NAT removes immediately the NAT mapping upon receipt of a

      TCP RST message, stale connections may be maintained by endpoints

      if the first RST message is lost between the NAT and the

      recipient.







2.       In section 5:



Ø  This update is compliant with the stateful NAT64 [RFC6146] that clearly specifies three binding information bases (TCP, UDP, ICMP).



As the focus of this document is NAT44, I do not believe that 'compliant' is the right word. Probably 'consistent' would be more appropriate.



[Med] I changed it to "consistent" in my local copy. Thank you for catching this.



3.       EIF is never expanded

[Med] Fixed.



Nits/editorial comments:


None.