Re: [I2nsf] Request for review and comments of Extensions to the Access Control Lists (ACLs) YANG Model draft-dbb-netmod-acl-01

Oscar González de Dios <oscar.gonzalezdedios@telefonica.com> Mon, 17 October 2022 16:13 UTC

Return-Path: <oscar.gonzalezdedios@telefonica.com>
X-Original-To: i2nsf@ietfa.amsl.com
Delivered-To: i2nsf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 74CB7C1524BC for <i2nsf@ietfa.amsl.com>; Mon, 17 Oct 2022 09:13:54 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.677
X-Spam-Level:
X-Spam-Status: No, score=-2.677 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.571, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=telefonica.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9OJak9DARSIJ for <i2nsf@ietfa.amsl.com>; Mon, 17 Oct 2022 09:13:49 -0700 (PDT)
Received: from EUR03-AM7-obe.outbound.protection.outlook.com (mail-am7eur03on2117.outbound.protection.outlook.com [40.107.105.117]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 77A3BC1524B8 for <i2nsf@ietf.org>; Mon, 17 Oct 2022 09:13:48 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ZHokUKW2pd8fxsluxM0unLFFeebUzYECpL5J3yJVZUdQsq8mqGfy81m5WMA25h29VcFGhMN7PuH22Xg6lckkjkJ7bTMzH8x2i+1oI7e2vonVOSl3eYRDbX47ucmsev+Xkz+ijnyzOdAzEMb6s4PwaWFvuM6CUrd2mwacfAUEAQeqnGmkc5YrZvBORTw7V8l+L6pzizKR/2g2anmqOn3Yc8oomxtURXcH/KVjGfbBGuNIU1vKoQCXnBrEJYtx2VqkOb0gYRKbpblxUFH/ARB7tOYvG6e4G/jOka6g6/70C235nwAD6oH8WEtA3S2kSEADlTeRi8z1V89F3+a6iXgMug==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=SIxuxsQxb/hwqod2iQXBeIooA6e7CSCopyvkARrZVoo=; b=by/jQnB2nOiI/1e9xAFQr7LVyS+/QyE3MCs8ydp2PhUZn06nNlAQ9mRhVOKikZUVDT5eCZlv200WII31x3TtrPr4FsO5TdDWgnNrJN8pHDG4b47hS0rvNYEw++1HlrZqERI5ILuGNTt66LCP6szsTVBQwerPPR0vAt7XtVKQtJuQ2g862sK5jr0ksKE0AcB8Fo1r33BrbaFcA48y3YD2iNl9wCnzoDIX0kxlymr3GbOaYT9PzwBneftbFrJw/8ERMQ20oG05sS/I1ir7fbz2DM4VbN6xFfEbrFxfR1BMDjrLg7HUGUaODu715zJlLy3cVEZetM2b4lmU5Z4YataH0A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=telefonica.com; dmarc=pass action=none header.from=telefonica.com; dkim=pass header.d=telefonica.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=telefonica.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=SIxuxsQxb/hwqod2iQXBeIooA6e7CSCopyvkARrZVoo=; b=N60+YrV+yRO4VPq7T3NgRRAARTADAnoSUfG86sGAiuCcU2nGoJ+aulL3NmB7Nw/rWHk1hPdZ9/uGnwjR0wft6juEnL/Z/6AUiZbcRBw0xDbl+ASwMtQs1G2N9nyM9Ppxmy3FnPRGDd6pE7X63td9Kj3iohv9s9wheZxYOe/nebM=
Received: from PAXPR06MB7872.eurprd06.prod.outlook.com (2603:10a6:102:1a3::9) by DB6PR06MB3144.eurprd06.prod.outlook.com (2603:10a6:6:e::30) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5723.29; Mon, 17 Oct 2022 16:13:43 +0000
Received: from PAXPR06MB7872.eurprd06.prod.outlook.com ([fe80::cc8b:e43f:a057:dc3d]) by PAXPR06MB7872.eurprd06.prod.outlook.com ([fe80::cc8b:e43f:a057:dc3d%3]) with mapi id 15.20.5723.033; Mon, 17 Oct 2022 16:13:43 +0000
From: Oscar González de Dios <oscar.gonzalezdedios@telefonica.com>
To: Linda Dunbar <dunbar.ll@gmail.com>
CC: "i2nsf@ietf.org" <i2nsf@ietf.org>
Thread-Topic: [I2nsf] Request for review and comments of Extensions to the Access Control Lists (ACLs) YANG Model draft-dbb-netmod-acl-01
Thread-Index: AdjddL2vkpV3/9V9SPqnq0V5uDK7SwEpNqUAAAhOL4AAAeLa4A==
Date: Mon, 17 Oct 2022 16:13:43 +0000
Message-ID: <PAXPR06MB78723EC6FBD5B721006B10E2FD299@PAXPR06MB7872.eurprd06.prod.outlook.com>
References: <PAXPR06MB787207A71BF252D21F5FB7C2FD239@PAXPR06MB7872.eurprd06.prod.outlook.com> <PAXPR06MB7872CAECB250E31F3799A0BDFD299@PAXPR06MB7872.eurprd06.prod.outlook.com> <CAP_bo1bjtafEr+E9kmn6Wwd9cx2kHor6WtB98K2wN5KyATJzww@mail.gmail.com>
In-Reply-To: <CAP_bo1bjtafEr+E9kmn6Wwd9cx2kHor6WtB98K2wN5KyATJzww@mail.gmail.com>
Accept-Language: es-ES, en-US
Content-Language: es-ES
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=telefonica.com;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PAXPR06MB7872:EE_|DB6PR06MB3144:EE_
x-ms-office365-filtering-correlation-id: cd7d9cf4-042e-43d4-37fa-08dab05a8fb5
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: XoKo+kDaQ9m1ydg4EpkF3QeQvZQpljREfnk8IR25eIfTdzi+Awir3KTv8fnS5cYhakU9F47XPdwOqy5zb9AZTFQnQ09KNdN1O7zdPiXgfNTeDAfpJktGTkFmxzevqrD6jtBqUejNI7g3k3q1/ZlzowXD5+RtAAwnAFiHRj58cbmfwFImaEpFfMNDcOV3+65FmVlaBVbDC7kwdn/3hIakUd/JEmPekgUltJuZn/mxZEIWSZPNq7dYilcM9If77NdZNYFxE7YfPIiG+OLMoghS3onWPouXE2i7GtbM0JOLRIcWre2aUjvBabWWTMPaPP6w1ZVXMFFc5uiZc9RsnE43cJ7T/rg66pKxzS1jmYbCxCVxzAJT49pV1U2yQNZDQEU1FOU5/PVMgHw4VLAG2EK2qm8Stm9Yn/y4MmpZ99TpGnb/QWTZife7NZytIJnqobd23f/AMmne1ruBjOnaNyaYDGyHvluLExD8Em3eFLmt2zMQh6TS+a6vKgKkzSociF+fYdNkCPgDueY+LPLHoTCIXxCrmojUfVBfWtGOvqQWBP7ooZehCS8+fu2zp4mikoE4A4rgGqf+b8tLebT80QGfhvxanfPhcr5xYuaXMBON3v6kvNB8jsjUzbCwE+jqsO9aGrQH2rV37FO9ud3OoIrsdLfW0jlEaPQ7xQ7YTnzvhB2T9Lv5dRF3rbwcM8tXDVOySrhdY0sZpsLVgczXc1/dQsYMTCh4ekXqk9Z2S4i7U26npxsvqxSTdyp35KnixdWtHKZPSyTMOPQmTuxvLP6tDASPiaf2An19H6jwpUdnSHa6wWDKpvkBAZIuWrf5bi4p
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PAXPR06MB7872.eurprd06.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230022)(4636009)(136003)(39860400002)(376002)(346002)(396003)(366004)(451199015)(8676002)(76116006)(66946007)(6916009)(53546011)(66476007)(66446008)(66556008)(85202003)(85182001)(26005)(6506007)(7696005)(41300700001)(64756008)(4326008)(19627235002)(5660300002)(55016003)(316002)(83380400001)(66574015)(86362001)(9686003)(52536014)(8936002)(166002)(2906002)(82960400001)(38100700002)(186003)(33656002)(71200400001)(478600001)(966005)(38070700005)(122000001)(9010500006); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: EyJLi4iyHhrN9d6AbuQPDWYebdWyyi94/cOLu+ZrBDfMosgBpp5ycExRzaf6IFdk3v4Qh3XtVCJ60pSmXcJ95WXGdGihMNj2OkNw/LL3K/3HHdRcttO/imkqCNBTOXrohIYGRyvmLBfD5+JfZrmyxW6yTghjCPtxD8oPzzZY28W1KsFskiJWIiGbzrUjdZM1Uhq1Jkh+42wF01BQPZWGFKvTl5PPifUu0hauO1gRXljv+sy4sxMgXsluNMYDCly7ZPTKj5i6f5Q3VADBgrRnSPoS+GJJvkYNyH59a8TQuBEYK8EzkBxIs8dB1+6EnzFHPTPFPEzoW81CGSZRNYWVqPcsdOrUskha/hsFhs/XQ5ILDg4vU1m9rpmlKz5SBwovVSBW7xkuh+UCBAbr66rslElvU6rQvXHo5Sd9NZc5XPQ/oYiaUO4/2y9+3eZAicTJjcmTpALYL9uYKj9d2gfRfcR7ZwBSeB3DgGaEngInBrECuUDhLtxJduIyWzOFv4P2bMVr6sWR4/NEyK3hxMwKRCvlNe07iLCD4hpOBqrYsNYkeWiEeBZsx00rlnCPnfKQDNgppKN9z9P3wGMkRPmu7D1mMyRphsxN7vvQbOt940DBqm3QHKL70R1HSMNaMv+vg4sjkiGJikEHN3V1randFuY1pFUyCy6dP01ekUGhIbyOpwgyCZShLdkWsTLfxH6PEecYRUwzA5o3gYis5SeHhzK1Gj1QR3KF5EDfgFXdsiiFrRFMRxoteQ/PiVVl94OlI82uN1nZoUvLQYDwv9PQi3oKmma5vPgPXMC+qzvT3nDyQJKKfKdPoXNT/ltsIVQimJ/LeIm/WaKWyZ3YPEEkfeEDrxWz+LZNJoE2Jm/Yu5xcFxUIctc0IK99k53ndwMO8AhJfAOWts7WT/jrohagE31BVeDDib6DBdHX8zWDeb3Tk/XeZnGnGRdwofhqCw4bAtblFwRBJA6CCTlt6EBK4pqeUNt8ovcqMJdFEWZ6ePoQ8HYppregZPEeUTMGxuNPUCoY+pASxPOHov6ezPhdKPqRVg38V/4U50VZkDjmOZaOhWR1w5L3q0I62rTQd7qWyXYXi/xqaP4vqtsdjjDLsSANhKnGmOjwpDRXabaEvEE0jAHm4ys7rxeAa+N4GiDBgwvBgAoebS1Au7XAPPAyQeZKxlsqZ0C80iCUtILsmARD1GA1s1+X9xoSDAMcoGg5h/Q3adAy15RnEl+tREi8GX0c7J6afgridhtzUPZCGAdAiEw41yzOzXuQHG7zH90G4lUL03B7MMc90bTsWocO6kj7/Jc/okRuuhUDUWMjk7XDDAynZK0VAJx4J18KqwpD3Z2OQBx0Ea2OMwn4YlnTNKk/Hxy4lfvGVR2DzILLPdplDNBidmVwl04t2s4uXaYcSv1ZO9NuasW1SV6owHeIKbJd6TBPeDCVzWA/hilxfb/tSMTMoZWBsE9gGlKhvWmfpncJseVJF5SbRo2w000/oSvan6Z4DNWohioKw0s0vPTVEucivPr3gwJP3RaBSh5xM5KTJ4Gu1imTc5TSkcvcpfSlnINU/Y3FCyY+lgqjr7fYTfmvwgyypzg4ulInevilsmAYd4lei3BkHTHrkuk0OwcYaBizksfR2nMC6S05Qw0=
Content-Type: multipart/alternative; boundary="_000_PAXPR06MB78723EC6FBD5B721006B10E2FD299PAXPR06MB7872eurp_"
MIME-Version: 1.0
X-OriginatorOrg: telefonica.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PAXPR06MB7872.eurprd06.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: cd7d9cf4-042e-43d4-37fa-08dab05a8fb5
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Oct 2022 16:13:43.0597 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 9744600e-3e04-492e-baa1-25ec245c6f10
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: WttxdOR0zfBkkSdfbLWKm56yCDvMldWTDI5U/RJloIFk9kFFvNa2JmOm8mW4SHx7OkcRlMstQgK3uosbF5Nak40GntIjsj4cfhinek8VQQ13R4G/e6Hmyem3vty2Wa/o
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB6PR06MB3144
Archived-At: <https://mailarchive.ietf.org/arch/msg/i2nsf/VsmkNx-Ta9BP77zBb8Jug9tfLAU>
Subject: Re: [I2nsf] Request for review and comments of Extensions to the Access Control Lists (ACLs) YANG Model draft-dbb-netmod-acl-01
X-BeenThere: i2nsf@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "*I2NSF: Interface to Network Security Functions mailing list*" <i2nsf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/i2nsf>, <mailto:i2nsf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/i2nsf/>
List-Post: <mailto:i2nsf@ietf.org>
List-Help: <mailto:i2nsf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/i2nsf>, <mailto:i2nsf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Oct 2022 16:13:54 -0000

Hi Linda,

                The answer is Yes. It impacts the Yang model defined in ietf-i2nsf-nsf-facing-interface which imports ietf-packet-fields.

                Current extensions are proposed as augmentations to the acl yang model. The alternative is to go for, instead of augmentations, a new version of the ACL yang model (e.g. the packet fields one). The final choice will impact on how you use the extensions from i2nsf-nsf-facing-interface.

                Another issue which might require extra work to fit is the management of sets (list of prefixes, or list of ports), which are managed at the top-level and referenced by the matches.

                Best Regards,

                               Oscar


De: I2nsf <i2nsf-bounces@ietf.org> En nombre de Linda Dunbar
Enviado el: lunes, 17 de octubre de 2022 17:12
Para: Oscar González de Dios <oscar.gonzalezdedios@telefonica.com>
CC: i2nsf@ietf.org
Asunto: Re: [I2nsf] Request for review and comments of Extensions to the Access Control Lists (ACLs) YANG Model draft-dbb-netmod-acl-01

Oscar,

Does the YANG models specified by the enhanced Access Control List draft impact what has been specified in I2NSF drafts?

Linda

On Mon, Oct 17, 2022 at 9:37 AM Oscar González de Dios <oscar.gonzalezdedios@telefonica.com<mailto:oscar.gonzalezdedios@telefonica.com>> wrote:
Dear i2nsf colleagues,

        FYI, it may be of interest to the participants of I2NSF WG the draft on enhanced Access Control Lists which has been submitted to netmod.  https://datatracker.ietf.org/doc/html/draft-dbb-netmod-acl

        The draft presents a set of enhancements to the Access Control Lists Yang Model of RFC 8519 based on operational experiences, such as  manipulating Lists of  Prefixes, creating Aliases or Defined Sets, IPv4/IPv6 Fragment Handling, better TCP Flags Handling, among others (see the draft for the whole set of proposals).

        We would like to receive feedback on the proposed extensions.

        Best Regards,

                Oscar

------------------------------------------------

A new version of I-D, draft-dbb-netmod-acl-01.txt has been successfully submitted by Mohamed Boucadair and posted to the IETF repository.

Name:           draft-dbb-netmod-acl
Revision:       01
Title:          Extensions to the Access Control Lists (ACLs) YANG Model
Document date:  2022-06-29
Group:          Individual Submission
Pages:          26
URL:            https://www.ietf.org/archive/id/draft-dbb-netmod-acl-01.txt
Status:         https://datatracker.ietf.org/doc/draft-dbb-netmod-acl/
Htmlized:       https://datatracker.ietf.org/doc/html/draft-dbb-netmod-acl
Diff:           https://www.ietf.org/rfcdiff?url2=draft-dbb-netmod-acl-01

Abstract:
   RFC 8519 defines a YANG data model for Access Control Lists (ACLs).
   This document discusses a set of extensions that fix many of the
   limitations of the ACL model as initially defined in RFC 8519.

Discussion Venues

   This note is to be removed before publishing as an RFC.

   Discussion of this document takes place on the Network Modeling
   Working Group mailing list (netmod@ietf.org<mailto:netmod@ietf.org>), which is archived at
   https://mailarchive.ietf.org/arch/browse/netmod/.

   Source for this draft and an issue tracker can be found at
   https://github.com/oscargdd/draft-dbb-netmod-enhanced-acl.




The IETF Secretariat



________________________________

Este mensaje y sus adjuntos se dirigen exclusivamente a su destinatario, puede contener información privilegiada o confidencial y es para uso exclusivo de la persona o entidad de destino. Si no es usted. el destinatario indicado, queda notificado de que la lectura, utilización, divulgación y/o copia sin autorización puede estar prohibida en virtud de la legislación vigente. Si ha recibido este mensaje por error, le rogamos que nos lo comunique inmediatamente por esta misma vía y proceda a su destrucción.

The information contained in this transmission is confidential and privileged information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it.

Esta mensagem e seus anexos se dirigem exclusivamente ao seu destinatário, pode conter informação privilegiada ou confidencial e é para uso exclusivo da pessoa ou entidade de destino. Se não é vossa senhoria o destinatário indicado, fica notificado de que a leitura, utilização, divulgação e/ou cópia sem autorização pode estar proibida em virtude da legislação vigente. Se recebeu esta mensagem por erro, rogamos-lhe que nos o comunique imediatamente por esta mesma via e proceda a sua destruição
_______________________________________________
I2nsf mailing list
I2nsf@ietf.org<mailto:I2nsf@ietf.org>
https://www.ietf.org/mailman/listinfo/i2nsf

________________________________

Este mensaje y sus adjuntos se dirigen exclusivamente a su destinatario, puede contener información privilegiada o confidencial y es para uso exclusivo de la persona o entidad de destino. Si no es usted. el destinatario indicado, queda notificado de que la lectura, utilización, divulgación y/o copia sin autorización puede estar prohibida en virtud de la legislación vigente. Si ha recibido este mensaje por error, le rogamos que nos lo comunique inmediatamente por esta misma vía y proceda a su destrucción.

The information contained in this transmission is confidential and privileged information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it.

Esta mensagem e seus anexos se dirigem exclusivamente ao seu destinatário, pode conter informação privilegiada ou confidencial e é para uso exclusivo da pessoa ou entidade de destino. Se não é vossa senhoria o destinatário indicado, fica notificado de que a leitura, utilização, divulgação e/ou cópia sem autorização pode estar proibida em virtude da legislação vigente. Se recebeu esta mensagem por erro, rogamos-lhe que nos o comunique imediatamente por esta mesma via e proceda a sua destruição