Return-Path: <shares@ndzh.com>
X-Original-To: i2nsf@ietfa.amsl.com
Delivered-To: i2nsf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id 5B8E81A9100
 for <i2nsf@ietfa.amsl.com>; Sat, 19 Dec 2015 11:30:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -96.354
X-Spam-Level: 
X-Spam-Status: No, score=-96.354 tagged_above=-999 required=5
 tests=[BAYES_50=0.8, DOS_OUTLOOK_TO_MX=2.845, HTML_MESSAGE=0.001,
 USER_IN_WHITELIST=-100] autolearn=no
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id NNyyAIMS3umz for <i2nsf@ietfa.amsl.com>;
 Sat, 19 Dec 2015 11:30:41 -0800 (PST)
Received: from hickoryhill-consulting.com (hhc-web3.hickoryhill-consulting.com
 [64.9.205.143])
 (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 32E8D1A90FF
 for <i2nsf@ietf.org>; Sat, 19 Dec 2015 11:30:41 -0800 (PST)
X-Default-Received-SPF: pass (skip=loggedin (res=PASS)) x-ip-name=74.43.47.177; 
From: "Susan Hares" <shares@ndzh.com>
To: "'Anil Kumar S N \(VRP Network BL\)'" <anil.sn@huawei.com>,
 "'Linda Dunbar'" <linda.dunbar@huawei.com>,
 <draft-dunbar-i2nsf-problem-statement-05@ietf.org>
References: <327562D94EA7BF428CD805F338C31EF06C07EC8B@nkgeml512-mbx.china.huawei.com>
 <4A95BA014132FF49AE685FAB4B9F17F657DA6474@dfweml701-chm>
 <327562D94EA7BF428CD805F338C31EF06C07EFE5@nkgeml512-mbx.china.huawei.com>
In-Reply-To: <327562D94EA7BF428CD805F338C31EF06C07EFE5@nkgeml512-mbx.china.huawei.com>
Date: Sat, 19 Dec 2015 14:30:22 -0500
Message-ID: <000c01d13a93$b432d9d0$1c988d70$@ndzh.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;
 boundary="----=_NextPart_000_000D_01D13A69.CB6165B0"
X-Mailer: Microsoft Outlook 14.0
Thread-Index: AQKWPF/8Z7KcSyRLXKDKN5r6nGdP1wKVa8pQAhmmqwedIzUnsA==
Content-Language: en-us
X-Authenticated-User: skh@ndzh.com 
Archived-At: <http://mailarchive.ietf.org/arch/msg/i2nsf/JZVxSGm1wLOPLrlDT_eCvCey6ik>
Cc: 'Jayaraghavendran k' <jayaraghavendran.k@huawei.com>, i2nsf@ietf.org
Subject: Re: [I2nsf] Comments on draft-dunbar-i2nsf-problem-statement-05
X-BeenThere: i2nsf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "*I2NSF: Interface to Network Security Functions mailing list*"
 <i2nsf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/i2nsf>,
 <mailto:i2nsf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/i2nsf/>
List-Post: <mailto:i2nsf@ietf.org>
List-Help: <mailto:i2nsf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/i2nsf>,
 <mailto:i2nsf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 19 Dec 2015 19:30:46 -0000

This is a multipart message in MIME format.

------=_NextPart_000_000D_01D13A69.CB6165B0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

Anil, Linda and all:

 

I've put in most of your changes into the combined problem statement and use
case.  However, I can no longer find a copy or reference to: [I2NSF-Mobile].

 

Would you point me to the current document? 

 

Thank you,

 

Sue Hares 

 

From: I2nsf [mailto:i2nsf-bounces@ietf.org] On Behalf Of Anil Kumar S N (VRP
Network BL)
Sent: Sunday, November 22, 2015 11:04 PM
To: Linda Dunbar; draft-dunbar-i2nsf-problem-statement-05@ietf.org
Cc: Jayaraghavendran k; i2nsf@ietf.org
Subject: Re: [I2nsf] Comments on draft-dunbar-i2nsf-problem-statement-05

 

Hi Linda,

 

Reply is inline.

 

Thanks & Regards

Anil S N

 

"Be liberal in what you accept, and conservative in what you send" - Jon
Postel

 

 

From: Linda Dunbar 
Sent: 21 November 2015 06:07
To: Anil Kumar S N (VRP Network BL);
draft-dunbar-i2nsf-problem-statement-05@ietf.org
Cc: Jayaraghavendran k; i2nsf@ietf.org
Subject: RE: Comments on draft-dunbar-i2nsf-problem-statement-05

 

Anil, 

 

Thank you very much for the comments. Reply are inserted below:

 

 

From: Anil Kumar S N (VRP Network BL) 
Sent: Thursday, November 19, 2015 8:23 PM
To: draft-dunbar-i2nsf-problem-statement-05@ietf.org
Cc: Linda Dunbar; Jayaraghavendran k; i2nsf@ietf.org
Subject: Comments on draft-dunbar-i2nsf-problem-statement-05

 

Hi Authors,

 

          I was reading the draft for understanding and contributing towards
I2NSF working group and found few comments :

 

.         Introduction section :  I think all these use cases are merged as
"draft-pastor-i2nsf-merged-use-cases-00" request you to update the same

 

 

This document does not elaborate on specific use case. The reader

should refer to [I2NSF-ACCESS], [I2NSF-DC] and [I2NSF-Mobile] for a

more in-depth discussion on the I2NSF use cases.        

 

[Linda] you are correct. Actually all of them will be merged together with
the problem statement. 

 

.         Requirements Language, terms and acronyms section : We need to
describe following abbreviations which are used in the documents as it the
first document 

to be referred by any newcomer into I2NSF WG

 

IPS, IDS, ACL, FWs, AAA, CA, VNFpool, Etc...

 

[Linda] Good point. Has been added. 

 

 

.         3.1.1. Diverse types of Security Functions Section :  Below
statement is contradicting each other, I2NSF wants to standardize the
interface to control the behavior of NSF 

but doesn't want to standardize the interface which carries the information
of firewall filter and its application on specific flow. I Feel we could add
more clarity on the scope of I2NSF with respect to 

what is under its perview and what is not in this document if at all we want
to talk about "what is needed" in this document.

 

     there is no need to standardize on how a

     firewall filters are created or applied. What is needed is having

     an interface to control and monitor the behavior of NSFs.

[Linda]  What in the I2NSF scope is "Rule Set" to those "Firewall filter". 

How about this: "What is needed is having an interface to control and
monitor the rule sets that NSFs use to treat packets traversing through."

[[Anil >>]] Sounds good

          

.         3.1.2.  Diverse Interface to monitor the behavior of NSFs :
Reparsed as below 

You Can't Monitor What You Can't See. So enabling a security function 
(e.g., firewall [I-D.ietf-opsawg-firewalls]) does not mean that a network is
protected. 
As such, it is necessary to have a mechanism to monitor and provide
execution status of NSFs to
security and compliance management tools. There exist various network
security monitoring vendor specific interfaces 
for forensics and troubleshooting 
 
 
.         Adding new section :
3.1.9 Lack of mechanism for Key Management/Deterministic Generation and
Provisioning for communicating protocols
 
[Linda] Do you see it as challenge facing providers? Or the customers?  Do
you mean  "Lack of Mechanism for security keys distribution to NSFs by
different vendors"? 
 
 
There is a need for a framework/data model for a key management protocol
that may be used to create and manage session
 
[Linda] You need to provide more wording: Manage What Session? Is it IPSec
session ? is VPN session? 
What do you think of this 
"There is a need for controller to distribute various keys to distributed
NSFs." 
 
[[Anil >>]] Agreed, Will rephrase; Idea is that there are many key
management methods and KDF (key derivation function) exist 
but there is a need for standardizing the interface to provision and manage
it.  Here any two communicating protocols could use same KDF 
to deterministically derive keys and  to communicate. The reference to
session should have been two communicating entities.
Which will enhances the security by reducing life time of a key used and non
repetitive of the keys for a very long time which is very much important for
control plane packets.
Derived keys may be extended to IPsec/VPN  data packet.
Since the lack of such management framework/interface limited service
providers to use keys with very longer lifetime or a key chain with a set of
key which were repeated in a cycle.
We would like to address above issue with I2NSF framework. Please correct me
if I am wrong.
 
keys for message authentication and integrity. As of now there is no much
focus on an abstraction for keying information that describes the interface
between protocols, operators, and automated key management.
 
[[Anil >>]] How about below text :
3.1.9 Lack of framework/standard interface to provisioning the usage of Key
Derivation Function (KDF) and managing KDF
 
A Key Derivation Function (KDF) or Key Derivation Algorithm is intended to
be used in two ways: 
(1) to derive a long-term Master Secret from a short-lived shared secret 
(2) to derive secure channel session keys from a shared secret and a seed.
 
There is a need for a framework to ensure secure exchange of initial secrete
between managing entity and managed entity (NSF). 
 
There is a need for a framework/standard interface in provisioning two
communicating protocols to use KDF as their key source for 
Specific period of time or for a set of interaction. 
There is also need for framework/standard interface in controlling and
managing KDF used between two communicating protocols 
The Provisioning and Managing framework could be extended to data plane too.

 
With Regards
Anil S N
 

"Be liberal in what you accept, and conservative in what you send" - Jon
Postel


------=_NextPart_000_000D_01D13A69.CB6165B0
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><META =
HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii"><meta name=3DGenerator content=3D"Microsoft Word 14 =
(filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:"Bookman Old Style";
	panose-1:2 5 6 4 5 5 5 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
p.MsoDate, li.MsoDate, div.MsoDate
	{mso-style-priority:99;
	mso-style-link:"Date Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph
	{mso-style-priority:34;
	margin-top:0in;
	margin-right:0in;
	margin-bottom:0in;
	margin-left:.5in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:"Courier New";}
span.DateChar
	{mso-style-name:"Date Char";
	mso-style-priority:99;
	mso-style-link:Date;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.EmailStyle24
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.EmailStyle25
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle26
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle27
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle28
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:1403142831;
	mso-list-type:hybrid;
	mso-list-template-ids:-608653264 1089655390 67698691 67698693 67698689 =
67698691 67698693 67698689 67698691 67698693;}
@list l0:level1
	{mso-level-start-at:8;
	mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;
	font-family:Symbol;
	mso-fareast-font-family:"Times New Roman";
	mso-bidi-font-family:"Courier New";}
@list l0:level2
	{mso-level-tab-stop:1.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level3
	{mso-level-tab-stop:1.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level4
	{mso-level-tab-stop:2.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level5
	{mso-level-tab-stop:2.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level6
	{mso-level-tab-stop:3.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level7
	{mso-level-tab-stop:3.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level8
	{mso-level-tab-stop:4.0in;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level9
	{mso-level-tab-stop:4.5in;
	mso-level-number-position:left;
	text-indent:-.25in;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Anil, Linda and all:<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>I&#8217;ve put in most =
of your changes into the combined problem statement and use case.&nbsp; =
However, I can no longer find a copy or reference to: =
[I2NSF-Mobile].<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Would you point me to =
the current document? <o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Thank =
you,<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Sue Hares =
<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> =
I2nsf [mailto:i2nsf-bounces@ietf.org] <b>On Behalf Of </b>Anil Kumar S N =
(VRP Network BL)<br><b>Sent:</b> Sunday, November 22, 2015 11:04 =
PM<br><b>To:</b> Linda Dunbar; =
draft-dunbar-i2nsf-problem-statement-05@ietf.org<br><b>Cc:</b> =
Jayaraghavendran k; i2nsf@ietf.org<br><b>Subject:</b> Re: [I2nsf] =
Comments on =
draft-dunbar-i2nsf-problem-statement-05<o:p></o:p></span></p></div></div>=
<p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Hi Linda,<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Reply is =
inline.<o:p></o:p></span></p><div><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Thanks &amp; =
Regards<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Anil S N<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>&#8220;Be liberal in =
what you accept, and conservative in what you send&#8221; - Jon =
Postel<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p></div><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><div =
style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt'><div><div style=3D'border:none;border-top:solid #B5C4DF =
1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> =
Linda Dunbar <br><b>Sent:</b> 21 November 2015 06:07<br><b>To:</b> Anil =
Kumar S N (VRP Network BL); <a =
href=3D"mailto:draft-dunbar-i2nsf-problem-statement-05@ietf.org">draft-du=
nbar-i2nsf-problem-statement-05@ietf.org</a><br><b>Cc:</b> =
Jayaraghavendran k; <a =
href=3D"mailto:i2nsf@ietf.org">i2nsf@ietf.org</a><br><b>Subject:</b> RE: =
Comments on =
draft-dunbar-i2nsf-problem-statement-05<o:p></o:p></span></p></div></div>=
<p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>Anil, <o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>Thank you very much for =
the comments. Reply are inserted below:<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><div><div =
style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> =
Anil Kumar S N (VRP Network BL) <br><b>Sent:</b> Thursday, November 19, =
2015 8:23 PM<br><b>To:</b> <a =
href=3D"mailto:draft-dunbar-i2nsf-problem-statement-05@ietf.org">draft-du=
nbar-i2nsf-problem-statement-05@ietf.org</a><br><b>Cc:</b> Linda Dunbar; =
Jayaraghavendran k; <a =
href=3D"mailto:i2nsf@ietf.org">i2nsf@ietf.org</a><br><b>Subject:</b> =
Comments on =
draft-dunbar-i2nsf-problem-statement-05<o:p></o:p></span></p></div></div>=
<p class=3DMsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old Style","serif"'>Hi =
Authors,<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; I =
was reading the draft for understanding and contributing towards I2NSF =
working group and found few comments :<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Bookman =
Old Style","serif"'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoListParagraph style=3D'text-indent:-.25in;mso-list:l0 level1 =
lfo2'><![if !supportLists]><span =
style=3D'font-size:12.0pt;font-family:Symbol'><span =
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></span></span><![endif]><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'>Introduction section :&nbsp; I think all these use cases =
are merged as &#8220;draft-pastor-i2nsf-merged-use-cases-00&#8221; =
request you to update the same<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Bookman =
Old Style","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:1.0in'><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old Style","serif"'>This =
document does not elaborate on specific use case. The =
reader<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:1.0in'><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'>should refer to [I2NSF-ACCESS], [I2NSF-DC] and =
[I2NSF-Mobile] for a<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'margin-left:1.0in'><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old Style","serif"'>more =
in-depth discussion on the I2NSF use =
cases.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>[Linda] you are correct. =
Actually all of them will be merged together with the problem statement. =
<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoListParagraph =
style=3D'text-indent:-.25in;mso-list:l0 level1 lfo2'><![if =
!supportLists]><span style=3D'font-size:12.0pt;font-family:Symbol'><span =
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></span></span><![endif]><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'>Requirements Language, terms and acronyms section : We =
need to describe following abbreviations which are used in the documents =
as it the first document <o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Bookman =
Old Style","serif"'>to be referred by any newcomer into I2NSF =
WG<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old Style","serif"'>IPS, =
IDS, ACL, FWs, AAA, CA, VNFpool, Etc...<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>[Linda] Good point. Has =
been added. <o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Bookman =
Old Style","serif"'><o:p>&nbsp;</o:p></span></p><p =
class=3DMsoListParagraph style=3D'text-indent:-.25in;mso-list:l0 level1 =
lfo2'><![if !supportLists]><span =
style=3D'font-size:12.0pt;font-family:Symbol'><span =
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></span></span><![endif]><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'>3.1.1. Diverse types of Security Functions Section : =
&nbsp;Below statement is contradicting each other, I2NSF wants to =
standardize the interface to control the behavior of NSF =
<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old Style","serif"'>but =
doesn&#8217;t want to standardize the interface which carries the =
information of firewall filter and its application on specific flow. I =
Feel we could add more clarity on the scope of I2NSF with respect to =
<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old Style","serif"'>what =
is under its perview and what is not in this document if at all we want =
to talk about &#8220;what is needed&#8221; in this =
document.<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'>&nbsp;&nbsp;&nbsp;&nbsp; there is no need to standardize =
on how a<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'>&nbsp;&nbsp;&nbsp;&nbsp; firewall filters are created or =
applied. What is needed is having<o:p></o:p></span></p><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Bookman =
Old Style","serif"'>&nbsp;&nbsp;&nbsp;&nbsp; an interface to control and =
monitor the behavior of NSFs.<span =
style=3D'color:black'><o:p></o:p></span></span></p><p =
class=3DMsoNormal><span style=3D'color:#1F497D'>[Linda] &nbsp;What in =
the I2NSF scope is &#8220;Rule Set&#8221; to those &#8220;Firewall =
filter&#8221;. <o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'color:#1F497D'>How about this: &#8220;What is needed is having =
an interface to control and monitor the rule sets that NSFs use to treat =
packets traversing through.&#8221;<o:p></o:p></span></p><p =
class=3DMsoNormal><b><i><span style=3D'color:#1F497D'>[[Anil &gt;&gt;]] =
Sounds good</span></i></b><span =
style=3D'color:#1F497D'><o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
<o:p></o:p></span></p><p class=3DMsoListParagraph =
style=3D'text-indent:-.25in;mso-list:l0 level1 lfo2'><![if =
!supportLists]><span style=3D'font-size:12.0pt;font-family:Symbol'><span =
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></span></span><![endif]><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'>3.1.2.&nbsp; Diverse Interface to monitor the behavior =
of NSFs : &nbsp;Reparsed as below <o:p></o:p></span></p><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:black'>You Can&#8217;t Monitor What You Can&#8217;t =
See. So enabling a security function <o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:black'>(e.g., firewall [I-D.ietf-opsawg-firewalls]) =
does not mean that a network is protected. =
<o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:black'>As such, it is necessary to have a mechanism =
to monitor and provide execution status of NSFs =
to<o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'>security and compliance management tools. There exist =
various network security monitoring vendor specific interfaces =
<o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old Style","serif"'>for =
forensics and troubleshooting <o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif"'><o:p>&nbsp;</o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'><o:p>&nbsp;</o:p></span></pre><pre =
style=3D'margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 =
lfo2'><![if !supportLists]><span =
style=3D'font-size:12.0pt;font-family:Symbol;color:#17365D'><span =
style=3D'mso-list:Ignore'>&middot;<span style=3D'font:7.0pt "Times New =
Roman"'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
</span></span></span><![endif]><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>Adding new section =
:<o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>3.1.9 Lack of mechanism for Key =
Management/Deterministic Generation and Provisioning for communicating =
protocols<o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#1F497D'><o:p>&nbsp;</o:p></span></pre><pre><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>[Linda] Do you see it as challenge facing providers? Or the =
customers? &nbsp;Do you mean &nbsp;&#8220;Lack of Mechanism for security =
keys distribution to NSFs by different vendors&#8221;? =
<o:p></o:p></span></pre><pre><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></pre><pre><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>There is a need for a framework/data model =
for a key management protocol that may be used to create and manage =
session<o:p></o:p></span></pre><pre><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></pre><pre><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>[Linda] You need to provide more wording: Manage What Session? Is it =
IPSec session ? is VPN session? <o:p></o:p></span></pre><pre><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>What do you think of this <o:p></o:p></span></pre><pre><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>&#8220;There is a need for controller to distribute various keys to =
distributed NSFs.&#8221; <o:p></o:p></span></pre><pre><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></pre><pre><b><i><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>[[Anil &gt;&gt;]] Agreed, Will rephrase; Idea is that there are many =
key management methods and KDF (key derivation function) exist =
<o:p></o:p></span></i></b></pre><pre><b><i><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>but there is a need for standardizing the interface to provision and =
manage it. &nbsp;Here any two communicating protocols could use same KDF =
<o:p></o:p></span></i></b></pre><pre><b><i><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>to deterministically derive keys and &nbsp;to communicate. The =
reference to session should have been two communicating =
entities.<o:p></o:p></span></i></b></pre><pre><b><i><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Which will enhances the security by reducing life time of a key used =
and non repetitive of the keys for a very long time which is very much =
important for control plane =
packets.<o:p></o:p></span></i></b></pre><pre><b><i><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Derived keys may be extended to IPsec/VPN &nbsp;data =
packet.<o:p></o:p></span></i></b></pre><pre><b><i><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>Since the lack of such management framework/interface limited service =
providers to use keys with very longer lifetime or a key chain with a =
set of key which were repeated in a =
cycle.<o:p></o:p></span></i></b></pre><pre><b><i><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>We would like to address above issue with I2NSF framework. Please =
correct me if I am wrong.<o:p></o:p></span></i></b></pre><pre><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></pre><pre =
style=3D'page-break-before:always'><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>keys for message authentication and =
integrity. As of now there is no much focus on an abstraction for keying =
information that describes the interface<o:p></o:p></span></pre><pre =
style=3D'page-break-before:always'><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>between protocols, operators, and =
automated key management.<o:p></o:p></span></pre><pre =
style=3D'page-break-before:always'><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#1F497D'><o:p>&nbsp;</o:p></span></pre><pre =
style=3D'page-break-before:always'><b><i><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>[[Anil &gt;&gt;]] How about below text =
:<o:p></o:p></span></i></b></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>3.1.9 Lack of framework/standard interface =
to provisioning the usage of Key Derivation Function (KDF) and managing =
KDF<o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'><o:p>&nbsp;</o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>A Key Derivation Function (KDF) or Key =
Derivation Algorithm is intended to be used in two ways: =
<o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>(1) to derive a long-term Master Secret =
from a short-lived shared secret <o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>(2) to derive secure channel session keys =
from a shared secret and a seed.<o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'><o:p>&nbsp;</o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>There is a need for a framework to ensure =
secure exchange of initial secrete between managing entity and managed =
entity (NSF). <o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'><o:p>&nbsp;</o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>There is a need for a framework/standard =
interface in provisioning two communicating protocols to use KDF as =
their key source for <o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>Specific period of time or for a set of =
interaction. <o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>There is also need for framework/standard =
interface in controlling and managing KDF used between two communicating =
protocols <o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:#17365D'>The Provisioning and Managing framework =
could be extended to data plane too. <o:p></o:p></span></pre><pre =
style=3D'page-break-before:always'><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></pre><pre =
style=3D'page-break-before:always'><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:black'>With Regards<o:p></o:p></span></pre><pre =
style=3D'page-break-before:always'><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:black'>Anil S N<o:p></o:p></span></pre><pre><span =
style=3D'font-size:12.0pt;font-family:"Bookman Old =
Style","serif";color:black'><o:p>&nbsp;</o:p></span></pre><p =
class=3DMsoNormal><span style=3D'font-size:12.0pt;font-family:"Bookman =
Old Style","serif"'>&#8220;Be liberal in what you accept, and =
conservative in what you send&#8221; - Jon =
Postel<o:p></o:p></span></p></div></div></body></html>
------=_NextPart_000_000D_01D13A69.CB6165B0--

