Re: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)

"Jakob Heitz (jheitz)" <jheitz@cisco.com> Thu, 11 February 2021 00:22 UTC

Return-Path: <jheitz@cisco.com>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 16FDA3A0B12 for <idr@ietfa.amsl.com>; Wed, 10 Feb 2021 16:22:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.619
X-Spam-Level:
X-Spam-Status: No, score=-9.619 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=S+n2Y6UL; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=iqb441Wd
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RQ2tx22f9Xob for <idr@ietfa.amsl.com>; Wed, 10 Feb 2021 16:22:54 -0800 (PST)
Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 98E203A0AB5 for <idr@ietf.org>; Wed, 10 Feb 2021 16:22:54 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=23020; q=dns/txt; s=iport; t=1613002974; x=1614212574; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=Ei/QYmAAeyPw+/3ZPnDxhDY4jvFN1MTCJOuwbpTEAPc=; b=S+n2Y6ULOdCjRJVHBWl2qEhJ3v3AJLl11tBwo0pp31cDNp68wuK9CAEt iZxDUND1d9p2eI6FqN8F9U9ui6h4wG+Jxf/D5Ffa4C8SFrLuuoJED0rTt EqKTXVD15OOXYc2L9XmNfXSkOEi11SOxzMdopFc1c+y5SWXseJ6Ox9ATD w=;
X-IPAS-Result: A0ArAAD7dyRgmIUNJK1iGQEBAQEBAQEBAQEBAQEBAQEBARIBAQEBAQEBAQEBAQGCD4EjMCMufVo2MYRBg0gDjhEDmRyBQoERA1QLAQEBDQEBGAEKCgIEAQGESwIXgWwCJTgTAgMBAQEDAgMBAQEBBQEBAQIBBgQUAQEBAQEBAQGGNg2GQwEBAQEDAQEbBgQGEwEBLAsBDwIBCBEEAQEoAwICAiULFAkIAQEEAQ0FCBOCVQGBflcDLgEOpQ8CiiV2fzODBAEBBoEzAYNYGIISAwaBOAGCdYQEAYJPg3MmG4FBP4FUgiE1PoEEgVkBAQIBFoEMEioVFgmCYDSCK4FZEB0+BwdcBDIfAi8sKkUTAQUvH5QKhz+MSJFJCoJ6iTaHTIsngy+KR5UylDaLK5FvCYRUAgQCBAUCDgEBBoFsIYFZcBU7gmlQFwINjh8RCQkUgzqFFIVFcwI1AgYBCQEBAwl8iFSCQwEB
IronPort-PHdr: 9a23:KsdNuRW4O31mCQMFwfwN966m23TV8LGuZFwc94YnhrRSc6+q45XlOgnF6O5wiEPSBNyFuehNkPjLsObmVHBTqZqCsXVXdptKWldFjMgNhAUvDYaDDlGzN//laSE2XaEgHF9o9n22Kw5ZTcD5YVCBuHSp/yMRXBPyKVk9KuH8AIWHicOx2qi78IHSZAMdgj27bPtyIRy6oB+XuNMRhN5pK706zV3CpX4bdg==
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.81,169,1610409600"; d="scan'208,217";a="644147298"
Received: from alln-core-11.cisco.com ([173.36.13.133]) by alln-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 11 Feb 2021 00:22:53 +0000
Received: from XCH-ALN-002.cisco.com (xch-aln-002.cisco.com [173.36.7.12]) by alln-core-11.cisco.com (8.15.2/8.15.2) with ESMTPS id 11B0MqY2027228 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Thu, 11 Feb 2021 00:22:53 GMT
Received: from xhs-rtp-001.cisco.com (64.101.210.228) by XCH-ALN-002.cisco.com (173.36.7.12) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Wed, 10 Feb 2021 18:22:52 -0600
Received: from xhs-aln-002.cisco.com (173.37.135.119) by xhs-rtp-001.cisco.com (64.101.210.228) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Wed, 10 Feb 2021 19:22:51 -0500
Received: from NAM10-MW2-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-002.cisco.com (173.37.135.119) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Wed, 10 Feb 2021 18:22:51 -0600
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=LKpW4ntY1xShZWMU+Pw7/4/jkIMCUtc8ChHzjI+q7vt44cYvx0s+/rbm4II19uKW1MzGWwxprwJ7jcH36O8daEKhFnN5pVR08TJ1WUcMTliFtu588E81+qHuwPoP1/L6LofOfu0CNUx7R2Xh5GIFf9TyQp0aJp2hDTV2I+xn+GvuCkSquht03exeEhV1wbA2vJmxS1IS9BBek5ZPTWSXKNYNUUExuwAVACLoE5ka6vM4Eg/B98uXzWJHbToVT8jVMMG/vTFocHN7iQ2TMoZCp4+5YVoyUY+IuhG4TKq1OPGcMaLieD0n1PvJfkXSDbT1XZSulmse/uMIi9jqJOOGKg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Ei/QYmAAeyPw+/3ZPnDxhDY4jvFN1MTCJOuwbpTEAPc=; b=c/Ome+d2LKvPJfkzx8XyRuebxuayFcDoX02eSoIVudO/HDzuy6aURO2y4gjubQWeEIkp1AGHBGCsJIKa4/6Nwk0NVIMhFp8+gs94kQ6YhVct6DB1QiZVmTNxDWweov5V8ChkZNc06RD+Zr537MbshBTkB8Qz67PPpkcYXVGQ+OOgfHZ9wyDRpfuwe5uRoFXKJ+pwTUbAj3ugJm2q7g05J76qBFBKSxkXzq1CisARQfFtuz2dVWzHZzWUZIurXOD034WAzrX1zjf0ByAEbUFin0TDv2azmwSauupOXfjp84/rSooV7IMai9JvWkWJRvku7/p8LG/W9rsUjdic5IIEpw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Ei/QYmAAeyPw+/3ZPnDxhDY4jvFN1MTCJOuwbpTEAPc=; b=iqb441WdnAiD1j7Q8BbVBm9d0hvYVl/oUpo4cvB9+6ffbL9n/oW4g2HZ/PpWu+1pJGREubImhWdafoApjyuAANFNyrzyvPBD9Lg/ORsRlX3JlrFva0oW+d40yK+y+uHWawI5p0zKZckc6OQrxuCQmZN4IvcrFFhkPXtW1TUD7ec=
Received: from BYAPR11MB3207.namprd11.prod.outlook.com (2603:10b6:a03:7c::14) by BYAPR11MB2968.namprd11.prod.outlook.com (2603:10b6:a03:90::30) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3805.17; Thu, 11 Feb 2021 00:22:50 +0000
Received: from BYAPR11MB3207.namprd11.prod.outlook.com ([fe80::c951:3ae4:1aca:9daf]) by BYAPR11MB3207.namprd11.prod.outlook.com ([fe80::c951:3ae4:1aca:9daf%3]) with mapi id 15.20.3825.030; Thu, 11 Feb 2021 00:22:50 +0000
From: "Jakob Heitz (jheitz)" <jheitz@cisco.com>
To: Robert Raszuk <robert@raszuk.net>, Susan Hares <shares@ndzh.com>
CC: "idr@ietf.org" <idr@ietf.org>, "Acee Lindem (acee)" <acee=40cisco.com@dmarc.ietf.org>
Thread-Topic: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)
Thread-Index: Adb7C8Tapzr6LUQXS7CFnBh8kC9NpgErJwcAAA2IX4AABtfh4A==
Date: Thu, 11 Feb 2021 00:22:50 +0000
Message-ID: <BYAPR11MB3207C8CA2DDDDE3EEE351B6CC08C9@BYAPR11MB3207.namprd11.prod.outlook.com>
References: <010e01d6fb0b$c5c08970$51419c50$@ndzh.com> <12CC3D2A-4316-45EA-8ED8-4802F7CB56B0@cisco.com> <CAOj+MMHwHvZV5h-hihgmX8bcMBB62-s7QB2fh2yOnDYDco1LGQ@mail.gmail.com>
In-Reply-To: <CAOj+MMHwHvZV5h-hihgmX8bcMBB62-s7QB2fh2yOnDYDco1LGQ@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: raszuk.net; dkim=none (message not signed) header.d=none;raszuk.net; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [2601:647:5701:46e0:a466:79fe:7183:c553]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: d6ab8c4d-f684-4aec-5443-08d8ce232a72
x-ms-traffictypediagnostic: BYAPR11MB2968:
x-microsoft-antispam-prvs: <BYAPR11MB29683B8EA7D36461C9A3E274C08C9@BYAPR11MB2968.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 22mUbD6E0LWLagYAjPKQeiWL7rMnQm/22RPPY65M/rvTSS3RvKvcZPo0RrBmx1wXEMkFz1rqWwvszHZYSvlJqPDz/bWjMxs4Ilm9qX/XMYknKAp+kQLx0vRTG9UINpl1fbNggK0ggbIdrrx6I4ArfkqvCQSf9KmkAYsEoFuhRDddRxHoATQHKchgHyD0ZK+XLneK7XAIKIxD/8+r70AvE/O9rBzJ46tuctow30rcYIlwdlasILwvrGLSmul6zxH/bdGmbonaPAlmHUsTcp0INsrg4DhfWHddn5rQ54TPCnMD0mNbNR8+V6wqdAu8iBHUioNXm6XxPBTAqpSkeXeWgLplGZeFNuNO7YaMrgDQKpSWpo2bd+9HNrm/FCpcOOvm2aqxb+kGitPlgssUtWWT1wefsGSHyEjoTLUSacr9xSDOmIJP7AUhxYxwIBj7gs2RWorI7dzG5TnWu+Hs71zXy+W3txUUl9WcRAB5a7CWkqk3i2yZ5a83+sAfm113PDzumIvVIfXl/vIbkDK93uQ7mSfD+3ocW7Y/N7JuXkA/bzL3N6YwzH9PyizAhthDtmiWXNDW7afiP1+SIQY6O64JUBjhpGi906ksiEldrLfHouA=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BYAPR11MB3207.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(376002)(366004)(39860400002)(346002)(136003)(396003)(86362001)(7696005)(316002)(52536014)(8676002)(166002)(5660300002)(66574015)(66476007)(53546011)(66946007)(186003)(71200400001)(76116006)(478600001)(83380400001)(110136005)(9686003)(55016002)(4326008)(54906003)(966005)(8936002)(66556008)(33656002)(2906002)(6506007)(66446008)(64756008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: t4I+4/aRIdY7A1s2ZPTtSas25ki1DD/oByHlQefSzSGYfsZEODYDcKbg95OKKx0lNJtKqNAjEbmF394469QnDqvLZVAenct05jVhEWi0XnCHniyyFoK+HD3QXnSU4IkwyS9FcVJixt0hTzTziFk0N5Svj7L3/zkiVq00sQ3dJgKOVRUAZZUTYuGQk3giUWy64SS/+cr+vS+alh9NptizQIsRpIyRWNgNCCV3pqNmN4dKOxA4HudFc1yZL/7tdiaF7Us4YS1gieJPuaV47KR4qr9vWqFiCQdb5LU2bHYpEuN6ZAlYuBN+BweFIED63xGWX++rUVTYr+ZoFEvgwqetMFUJrTkNGHy1wCu4b7d8o+H5pxwv+YkOLFHXI1pXoAX/+W9mdOpRMuMqjAlTHhqNvfcSph3QS+EkbxBgpK0f0okujeJJx2Yr2DTvO3t6b+2RL/We2HJkuHbOrebTS2bLMkoQ7xIhyD0a2PuqN6Gmsg6pz1c6k82wJhT+/vYbHQBvJUogKKNFX0+Lgi7lat4Oyi7xGy4BB2D/KIOxnYL/HeobY7sUPx3Jbtir4EHc3rNqwVN8s0U+RVpZsyicnxWTJNF7gdsWSzm46M0KQryWbwQ0j/75GyAiAV5UFMx4aZwJUMhi4TOFkfumI6syui3ta9tey5xYl853xuxTuP81kqVF/nZA+sm3GBqMvKVS7PH4Vioq8Bfu05QbaeY2S6hHQuNT8dqkfFz6jgPRM2wq4YxeW5aPieoZOZ4Tpar3Go7W1gjaWCZwdKF0t6o13K2cIDj8ZoKimRNHnm51h1Ltor5BJb+vW0JHT7Ocsiszq9m2pkz+YtW2pOMlcRuyn+ImhcpBp8tTfP0QGWt1+XwvInizOup9B3tQ0pI5AA/2J+N5JPquXxkUHitjkelXgH43MxgigYtY3kSwHeVDrTMUyXBzZhYVPFczdju8l6MNKX76HGgiI9rX1Qiv/FlKHzz5m6Y/ILKCXUHI1OP9aJS7d7bMqLwvk0uNBaxR+JCvpEFu9pfwDS/DEvd6sN2mebyjdRRiERIxR25IUApn2eDRF2kaD8aMeEYe7eVHg7+ft2o+Wh6zPmWaziHoNBR6hriDG7HEzdJ3MMDNxX1jfe6dxu8Jb/oc6vrR9vmTFh/4g5CYdsNITnr4ErA8gIfGIys7ooT0qhJ58svwgny92AXyj6XkoEcKyshIDh3+2M2Job/23EtJXw9kXMpqmJqfSW584/9FRxZ356wYpsmcdbKQNAnZcZGRE9d4gDItZ+ez3WarmzPm3KGjRhtUkmszemeY5uJOx5wWFjvWs41Zh3AOaSicFTT1QSLMfluYB6WWjzeQiIH9asLe1wF5jbg+Y9H9VJ+dx9RXzv7X+bEfDOPQtALCoGOwoZhxDtDqaKoXoGSK
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_BYAPR11MB3207C8CA2DDDDE3EEE351B6CC08C9BYAPR11MB3207namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BYAPR11MB3207.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: d6ab8c4d-f684-4aec-5443-08d8ce232a72
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Feb 2021 00:22:50.3408 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: eP89rrB7TurcdfC/aU9j1hjxflpea97lX50rkXY+8Jw/yiR7VfcDJiCrVLLWMxSS+Xnzr/WO3wXi0IBZQbx2gg==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR11MB2968
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.12, xch-aln-002.cisco.com
X-Outbound-Node: alln-core-11.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/idr/6kQZVL7LKasJ49dZI0MxU0G_1uA>
Subject: Re: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Feb 2021 00:22:57 -0000

I agree with Robert.
The draft is not necessary.
Existing ORF from RF5292 can be used by using an address-prefix ORF in the VPN address family with prefix length 64.
The length 64 covers the RD portion of the prefix.
The elements of procedure in the draft are new. However, an RFC is not needed for that.
It is a local feature on each router.

But really, the overwhelmed router can just drop its own routes.
What difference does it make to send an ORF?
ORF seems to be a very little used feature.
The only question I remember getting about ORFs is "How can we limit the number of ORFs we accept from a neighbor?".
Operators don't like getting ORFs. They worry that it stresses their box.

Regards,
Jakob.

From: Idr <idr-bounces@ietf.org> On Behalf Of Robert Raszuk
Sent: Wednesday, February 10, 2021 12:52 PM
To: Susan Hares <shares@ndzh.com>
Cc: idr@ietf.org; Acee Lindem (acee) <acee=40cisco.com@dmarc.ietf.org>
Subject: Re: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)

Dear Sue & WG,

Technically the solution is broken - you can't filter based on RD when single VRF overflows due to simple fact that arriving routes at a PE with one RD are typically imported locally to many different VRFs which may be running just fine. That to me is sufficient to dismiss this proposal.

I am not even going to point out that for multihomed sites injecting both aggregates and more specifics + doing eiBGP load balancing or sharing similar mixed reachability with Inter-AS option B could  form a rather ugly data plane behaviour.

But putting those (one could say subjective claims) aside procedurally what is important here is that *entire*  protocol extension this draft is attempting to define is already defined for a long time in a RFC ... namely RFC5292 -> https://tools.ietf.org/html/rfc5292

So it would be pretty bad precedence to now define subset of it in other RFC. And what if both ORF types are used together ? Hint: VPNv4/v6 PREFIX==RD+NET

At best this draft could be turned into an informational document titled: "How to shoot yourself in the foot while using prefix ORF to filter VPN routes".  which I would support adoption of.

Kind regards,
Robert

On Wed, Feb 10, 2021 at 8:24 PM Acee Lindem (acee) <acee=40cisco.com@dmarc.ietf.org<mailto:40cisco.com@dmarc.ietf.org>> wrote:
Hi Sue, IDR WG,

I agree with Jim Uttaro with respect to the use case being weak and already solved with other mechanisms.

Also, there was much opposition to changing the RD semantics and using it for route filtering. See:

https://mailarchive.ietf.org/arch/browse/idr/?q=%22wang-idr-rd-orf%22

I don’t see that this has changed and, additionally, this will add further complexity to BGP route filtering dynamics.
Thanks,
Acee

This begins a 2 week WG adoption call for draft-wang-idr-rd-orf-05.txt (from 2/4/2021 to 2/18/2021)

This draft defines a new Outbound Route Filter (ORF) type, called the
Route Distinguisher ORF (RD-ORF).  RD-ORF is applicable when the
routers do not exchange VPN routing information directly (e.g.
routers in single-domain connect via Route Reflector, or routers in
Option B/Option AB/Option C cross-domain scenario).

Please be aware that this draft has one IPR statement attached.

https://datatracker.ietf.org/ipr/4579/..

Please consider the following questions in your review and comments:

1) Will this new ORF filter reduce routing information at key points?
2) Should the WG consider this draft given it has an IPR claim or
    Would the IDR WG prefer another approach?
3) Is this draft ready to be adopted and refined as WG draft?

Cheerily, Susan Hares


_______________________________________________
Idr mailing list
Idr@ietf.org<mailto:Idr@ietf.org>
https://www.ietf.org/mailman/listinfo/idr