Re: [Idr] FW: New Version Notification for draft-ietf-idr-bgp-open-policy-22.txt

"Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov> Tue, 15 February 2022 22:52 UTC

Return-Path: <kotikalapudi.sriram@nist.gov>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D4D6A3A0D10; Tue, 15 Feb 2022 14:52:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.928
X-Spam-Level:
X-Spam-Status: No, score=-2.928 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.576, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_GOV_DKIM_AU=-0.351, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=nist.gov
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RiQwbyVQ40wU; Tue, 15 Feb 2022 14:52:23 -0800 (PST)
Received: from GCC02-BL0-obe.outbound.protection.outlook.com (mail-bl2gcc02on2104.outbound.protection.outlook.com [40.107.89.104]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id CAA413A0CFE; Tue, 15 Feb 2022 14:52:22 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=cW1GbzwQus3W+svRBTiDAmXJbQTZpuoWrEJHG2TGw1KVey6Pv80aCiQJYg0kKh2dcB7ByJq7nfUrwyGMyVsg6i0X15oFhSCShgS/OQ7FLxTtebqRm0z8nSAGbSlXEgPuhfGex8Z6EXf6EKZCgj5hslb7XH9q3327063g/ZMZWYei9c9AqGO+lr34J4CP7p3MoDJvauNrOvFAzi+NnS0Lrh0XXC8HtFpGyH8vbJGeVHwVjTzsEFtV9UtZaKCjxBqFI+MM4flBROT4KMuvMh4+2JlCEZE38LmEuRjR4WZqvzWmOSAB9mz0RyHc1VgPZT3Uq8+OoLrqk+Ftsi/y/akgwQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=M9Zx6c/6V3ryTSNWOutZClmiKAF2+8UdRbl48+KFBUI=; b=iJsC0xYnTGi91fABsa4TeS4CCWezd+JdbFapb+W/DUyaiURBpQ3CQvL+jOEy+9Vl3FAmtYezLAjzjZNDGcvffu9YJuBA3LZq/F0jbD+Zo70OqzjzUeLwt3w2r+qnp5i3gr3nWBGct45GOG2fswNhNxWqZA8ICGDXXgkgL8npjl01KUTUqpc+ZK2ROpvoQsdK5tSfwC/VCML8SM4nKBFiomGcx203SFzJRfFnK0/uyQif/tMMvLaG1waTz2mVjv0zw+x9a71ffJB2JGJOhBeJoY4Kz+GkrGyNcNGaM+QGLMC2HumXwF2/ymNz80JL3UVohxmk4oLBkdUkR7gaaHet/Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nist.gov; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=M9Zx6c/6V3ryTSNWOutZClmiKAF2+8UdRbl48+KFBUI=; b=L25EAPqZrXM+037OyyooynHqj3ySPiJTf9phKho9BzlPMc1bI7jr0FqSsoVk9fnB34swA/uQ7m5PvgmOpANwGOP+aIAl6Eu9iY53Zns3fvYDkOy2zeu9OlU7Knnzl/FycE03Ui/5x/Mqk0StSuLaDbWaAVBLOF5iSMxN0qiCgE4=
Received: from SA1PR09MB8142.namprd09.prod.outlook.com (2603:10b6:806:171::8) by SA1PR09MB8222.namprd09.prod.outlook.com (2603:10b6:806:181::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4975.12; Tue, 15 Feb 2022 22:52:17 +0000
Received: from SA1PR09MB8142.namprd09.prod.outlook.com ([fe80::c99c:1af3:8454:5d6a]) by SA1PR09MB8142.namprd09.prod.outlook.com ([fe80::c99c:1af3:8454:5d6a%6]) with mapi id 15.20.4995.015; Tue, 15 Feb 2022 22:52:17 +0000
From: "Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram@nist.gov>
To: "bruno.decraene@orange.com" <bruno.decraene@orange.com>, Alexander Azimov <a.e.azimov@gmail.com>, Jeffrey Haas <jhaas@pfrc.org>
CC: "idr@ietf.org" <idr@ietf.org>, "Alvaro Retana (aretana)" <aretana@cisco.com>, "idr-chairs@ietf.org" <idr-chairs@ietf.org>, Susan Hares <shares@ndzh.com>
Thread-Topic: [Idr] FW: New Version Notification for draft-ietf-idr-bgp-open-policy-22.txt
Thread-Index: AQHYHoPUcRrU0wMtckC6/hoQL0yXgayMy/awgAAH1wCAABYAUIAAClyAgAAtbMCAAOKTQIAAbNYAgAUZ+1CAAS47gIAACxqAgAAX4YCAAFCuYA==
Date: Tue, 15 Feb 2022 22:52:17 +0000
Message-ID: <SA1PR09MB81422436070DEC3E9E3EC1C384349@SA1PR09MB8142.namprd09.prod.outlook.com>
References: <164450039103.18823.6537348944134332594@ietfa.amsl.com> <SA1PR09MB81425A2C93A8B01D69ECF4C0842F9@SA1PR09MB8142.namprd09.prod.outlook.com> <20220210141346.GA28463@pfrc.org> <SA1PR09MB8142F6BCFCA2FAC557CE1F4E842F9@SA1PR09MB8142.namprd09.prod.outlook.com> <20220210160935.GD28463@pfrc.org> <SA1PR09MB814282B289F4061F72EBC356842F9@SA1PR09MB8142.namprd09.prod.outlook.com> <14670_1644570888_62062908_14670_192_1_f1ffc8e0bc5d417cbe88d57935bf4506@orange.com> <20220211145238.GH28463@pfrc.org> <SA1PR09MB8142DCF7B9B8982F5BBEE18084339@SA1PR09MB8142.namprd09.prod.outlook.com> <20220215144839.GL15589@pfrc.org> <CAEGSd=Amz_PcBaUmWfXkhaQcXRBR6r5dx-_VhK34gsD3--DBYg@mail.gmail.com> <30174_1644944032_620BDA9F_30174_157_1_6055cc07dbfc42b6b6418b48ce4c6e5f@orange.com>
In-Reply-To: <30174_1644944032_620BDA9F_30174_157_1_6055cc07dbfc42b6b6418b48ce4c6e5f@orange.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Enabled=true; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_SetDate=2022-02-15T16:53:49Z; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Method=Standard; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_Name=Orange_restricted_external.2; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_SiteId=90c7a20a-f34b-40bf-bc48-b9253b6f5d20; MSIP_Label_f47c794b-e3ab-43f0-9e0f-29fc3e503192_ContentBits=2
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=nist.gov;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 667e475c-c806-4408-b5e5-08d9f0d5d10c
x-ms-traffictypediagnostic: SA1PR09MB8222:EE_
x-microsoft-antispam-prvs: <SA1PR09MB822265A95EA48FCF04B9DC6184349@SA1PR09MB8222.namprd09.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: flsZhTQdk3KaWYFwOuGItX5e8EXerRTHt8/hkI5GtAMuMbLlE8Trny0M2O7VZ2AYt9TfMT3KAiFwoIBoQN+KHcluON6iNjAyeRwyr1MlY0fRyyGqmO69KEqmwLwh3bGsJnXRRCHQlKdE4FNtghjQ86J38Zj3wJdKmMa/oKYW1sKyX3kwYUQsoHkDF/3CZc4GCDp/V9gGyWHKB6cg6U7NPqd8XecCZ29NOq6v0UNdZ9LirQN05OsF0A5QDUMCbzzX3eDOvEukgvH3q2iUvzKQnZRkRngMl3zlcVT9wbjHSLysqZ43qGioQEKZEP/BWbPGNA8P5+WHS3xX2jhbFMSB6HkVVN4c8qX0MvS62bh4xBq+iQmwpDGrKv1oHjGdZe9cT909tABxczubrXG68dLC3qnOwHd27PjC3fmrgDueSF3Uq/jKDAyV9NBVx3xkLLPlCvhc2wL6H1VomsQQWdLZf7dXIE8rS8VyRCWxQuDhy0KK4hIh0cDrg2G5He7RgD9VQBYFDezOkcmHXRxVhVfkSF6eagGRrCTdru4RZk2fJuHoupGihHNW8yv7pwdKVPT+ZeVIdXANgQk4H2BROqMblqqgGJfKK4QmowVsowh7xZIJa4q3dLv4bUT2DiASUMKcN4zFi3P1z8TMgqMgWlrcFV27cRUTEyal3Lw7ufOx5Wp+y8be1qCSUzUIOQUl2f8RcX0g4bcw/DGivHDzdsQGiw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:SA1PR09MB8142.namprd09.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230001)(4636009)(366004)(71200400001)(38070700005)(4326008)(38100700002)(15650500001)(83380400001)(186003)(30864003)(33656002)(5660300002)(8936002)(52536014)(2906002)(55016003)(66946007)(7696005)(508600001)(966005)(86362001)(66446008)(6506007)(9686003)(26005)(76116006)(66556008)(316002)(8676002)(82960400001)(66476007)(122000001)(110136005)(45080400002)(54906003)(64756008); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: hs8gU0brF2VuFxoJnM/NzM0vCx3YvRJ8QkcsxgQRzpr+avLnOmkSJ1jtSDPuoq33ZZVit2BeALNr+sOsG3G5jgqkr3AC1TUfn7EBFp4VM6MaI0HMR8BXC6C/GmxcBLWLXaZiOAgBExCL6OtHChUe8vujK004lITHO7lmEh1hKmzskubWHw0+kHfTbYsKYSzbagW8PK7dES9Ad6ET9inp9qWB0ICbOrds/BKYgudzNcBiX+KuVAOducI9Md6D+If3K4UgzpCI2137FQdOQkhX0dMn2Ol7uC8LN8r5jNo/7gV1CXS2BDUL9EOUwU/TjRPyhVz8aL+vArZOou2QfmApKykvioll0CTmoP1lmvquRDP7gEtRq7oN7zrvRGHp4x6+y6G6OveKqzvy+QGWV/7AlOqcbmWCBqjq6eFLCrVgZb7PAfWKjxUuv9fFiTdYZXLWMCvPyqupM5yJb0a6Oq9KNdF4D+d3TEIOhXZR85nnoWOaZIilPNBu2Ahzk+Y1ROazNPDB8K3Zefi6GNHGgmZ4JVd/j4gIt/C3RAhNaGZR7+VukuvSNYzML1wYyokDxMrvCLpnX4etSryd20drQAW+Xc9sLGGH31JB4SEyy8wEZVWAw86043E6vxO2y+szBThab+x+sPEY/8IwdwOvZQR4oyY8bqTxTZ2MwUSxTplNrK/C6qLpSR7YSxrpsyJYyKW8R0/uosdG9U7mvyBeKd/Wl/ze/l98PIibzMApMuc4/pGNGLb130hxrnUGKiT/cwhf/nNV0NDLkE4f3dDKdqfHd8f6jHz+kxZHgUf4cTMFi37PDv/+9BpzJO0bCuOXkpS+rQZB4izuFNIhqixVWAuBCZdRleocNRqPDnyBnZbb6OnYBdSmxWWbAcBN7ub2jGtTWAZS5xC6pLu5kK4XpbB1NDmkL8vdCP5P1t5dRGvuvwb7d4CoGS3wpWOdUcLL+8T1riuwsvtnWto2i4+7yeMEpk+3gnxUjx2I4SumgZPE3SKxxkJH9TGtK1tYEhQm6+WL646bp/6VPMYMAjWK67Uh/kvwScPpCOGdgtJo6Qqt9tqDZPe0Jio+PMdMw848Ba7fCqeBL7ZGV9ke6YUYYBMwyueIA9tgxDedn1fQEtWTFYfJ/Yt/ph/zh8vCwwnGvUkr3P1UmyksM7zwU9oB8MpP+265gl5cEwKRpqAI7tar+kycVeED4wfnUxHgI65HM8VN7Gl0jVV/rBplVKPo32WEdhAA9skiv29BzvCDCFRwxhiZp6nrYqZf5+pq5mSnQZJ6J2Q5dNyfl/pR7VSvbiZZbcZlMu7PgWbXwo6UliTCjzIS/mpP9M2t1eJg0NKhl+gj
Content-Type: multipart/alternative; boundary="_000_SA1PR09MB81422436070DEC3E9E3EC1C384349SA1PR09MB8142namp_"
MIME-Version: 1.0
X-OriginatorOrg: nist.gov
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SA1PR09MB8142.namprd09.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 667e475c-c806-4408-b5e5-08d9f0d5d10c
X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Feb 2022 22:52:17.4669 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 2ab5d82f-d8fa-4797-a93e-054655c61dec
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA1PR09MB8222
Archived-At: <https://mailarchive.ietf.org/arch/msg/idr/1K8ZT9OzX1zSNUPcsiBWoEFJyzM>
Subject: Re: [Idr] FW: New Version Notification for draft-ietf-idr-bgp-open-policy-22.txt
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 15 Feb 2022 22:52:28 -0000

Hi Bruno,

Comments inline marked with [Sriram].

>[Bruno] - RFC7606 provides a guidance https://datatracker.ietf.org/doc/html/rfc7606#section-8<https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fhtml%2Frfc7606%23section-8&data=04%7C01%7Ckotikalapudi.sriram%40nist.gov%7Cb7a059d3cee145ca531c08d9f0a3c35f%7C2ab5d82fd8fa4797a93e054655c61dec%7C1%7C0%7C637805408436586543%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=Fsbz%2B8gTR8c0r94m4SoaamR4O%2BmHiMYH5tY9uRCXTHk%3D&reserved=0> . It's only half a page so anyone interested could read. I don't think it can be summarized as per you above sentence.

[Sriram] Section 8 of RFC 7606 that you cite, says:

   A document that specifies a new BGP attribute MUST provide specifics
   regarding what constitutes an error for that attribute and how that
   error is to be handled.  Allowable error-handling approaches are
   detailed in Section 2.

[Sriram] From the list of error-handling approaches detailed in Section 2, only treat-as-withdraw and attribute discard are relevant for us. Since the RFC says, "Allowable error-handling approaches are detailed in Section 2",  it does not allow for applying none of the approaches as an option.

>[Bruno] In particular there is not such "SHALL be handled using the approach of "treat-as-withdraw".

[Sriram] Regarding attribute discard, RFC 7606 says: "This approach MUST NOT be used except in the case of an attribute that has no effect on route selection or installation." This implies: This approach MUST NOT be used in the case of an attribute that has an effect on route selection or installation. Do you agree? The route does propagate from iBGP (ingress) to eBGP (in the ASBR), where the attribute plays a role in route selection for propagation.

>[Bruno] It also specifically calls for attention to optional transitive attributes (such as OTC) for which "the damage inflicted may be multiplied  manyfold >

[Sriram] The "damage inflicted may be multiplied manyfold" is about session reset. That is why the RFC urges the use of treas-as-withdraw or attribute discard instead.

>[Bruno] Without double checking, I don't recall that OTC is acted upon within IBGP. So in this case it does not affect routing selection. Let's just specify to not even look at it (it's optional) and problem is solved.

[Sriram] iBGP and eBGP within an ASBR are not isolated operations. Please see my comment above. Not to look at OTC is not an option. A compliant router checks syntax errors in iBGP (just as in eBGP) based on its expectations of the OTC Attribute. If the length value does not match, the Attribute is malformed.

[Sriram] If the OTC attribute is malformed for any reason, we cannot be sure that even the Attribute type value is correct (or as intended). Then must it be propagated from iBGP to eBGP (in the ASBR) and then to eBGP neighbors?

Thanks.

Sriram