Re: [Idr] [GROW] Invite comments on updated AS_SET deprecation draft

Job Snijders <job@fastly.com> Sun, 29 January 2023 10:26 UTC

Return-Path: <job@fastly.com>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E7F0AC14CEED for <idr@ietfa.amsl.com>; Sun, 29 Jan 2023 02:26:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=fastly.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nyZWxwa9d1Uc for <idr@ietfa.amsl.com>; Sun, 29 Jan 2023 02:26:06 -0800 (PST)
Received: from mail-ed1-x531.google.com (mail-ed1-x531.google.com [IPv6:2a00:1450:4864:20::531]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A82BEC14F748 for <idr@ietf.org>; Sun, 29 Jan 2023 02:26:06 -0800 (PST)
Received: by mail-ed1-x531.google.com with SMTP id f7so1160004edw.5 for <idr@ietf.org>; Sun, 29 Jan 2023 02:26:06 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=fastly.com; s=google; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=3PlU/6bZBZXzjNdNryJ9T5CkAt/2fVKupyb+CIRrOpI=; b=lBlmXxtDbgxK9iOaIFixL2MvVfqWVVg9V39ngX8lRUbsuWcMH+C1ZsF2b4k0E5FmgV ldtgF8pIEO2WEJT6CP3nUmPfSYLI8V7rc8IwDG283gQvIoRvntpDaYXnC3e5DfG42DCt VU1Nu11pQr4x5DRu90K4m48aId4w84XI16knc=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=3PlU/6bZBZXzjNdNryJ9T5CkAt/2fVKupyb+CIRrOpI=; b=NtCEX7MCkhM5mTI9OclyL+QYWYobM3hfsFU0ybNjZLDKt0eU8JheuVM9xx9ju3L3AP 1damvW9KrkBbANwZmQ8VqZL95NYRcJziggmiZnoCUqA47++RBQAz3YdfRl9U1wSfPjt5 zfIEkSoTEkkDWbN050RwVkgdYonzHUpJioCEMYbRqaCkiLZEstp4viEC9xHOZPTWlgRX ggPWltayMG/HwZzTV3CAsnnh8V7iTLPAuE9dqnVokX8fl5mOqLM8i4fcER2Gwz41k1fq jZuKc2JEDcyVx+us2/nWRs2TaV3GDjfRgqxELtOC/tCdlMrInXVC9SpH5ormbSwJPfeJ EFEw==
X-Gm-Message-State: AO0yUKUKUQTi+WTjJNtN/zgqVFb+rk80k4FqNN8pMKY6n5gNXofZ9Wk5 CgjqRcMZMZaMWfo5ejXVc/MIhQ==
X-Google-Smtp-Source: AK7set/0/8wVK90ELEuGvw6DqHxcRgJ1RodCmtMmR5NUMmzYN5B2IYH0J/Nxfr1fqvX/KwDFVzz26A==
X-Received: by 2002:a05:6402:5173:b0:4a1:2b1e:8292 with SMTP id d19-20020a056402517300b004a12b1e8292mr10660730ede.20.1674987964981; Sun, 29 Jan 2023 02:26:04 -0800 (PST)
Received: from snel ([2a10:3781:276:1:16f6:d8ff:fe47:2eb7]) by smtp.gmail.com with ESMTPSA id n3-20020a05640204c300b004a23609fab4sm914368edw.70.2023.01.29.02.26.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 29 Jan 2023 02:26:04 -0800 (PST)
Date: Sun, 29 Jan 2023 11:26:02 +0100
From: Job Snijders <job@fastly.com>
To: "Sriram, Kotikalapudi (Fed)" <kotikalapudi.sriram=40nist.gov@dmarc.ietf.org>
Cc: "idr@ietf.org" <idr@ietf.org>, "grow@ietf.org" <grow@ietf.org>, "draft-ietf-idr-deprecate-as-set-confed-set@ietf.org" <draft-ietf-idr-deprecate-as-set-confed-set@ietf.org>
Message-ID: <Y9ZJuj2WIhqDjkII@snel>
References: <SA1PR09MB81421F871DE2272D8F6AEDAD84CE9@SA1PR09MB8142.namprd09.prod.outlook.com> <SA1PR09MB814253A3F593917A81094A0484CE9@SA1PR09MB8142.namprd09.prod.outlook.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <SA1PR09MB814253A3F593917A81094A0484CE9@SA1PR09MB8142.namprd09.prod.outlook.com>
X-Clacks-Overhead: GNU Terry Pratchett
Archived-At: <https://mailarchive.ietf.org/arch/msg/idr/Hl2aJXBrC-dkOWu-rQK2Sz_QkHM>
Subject: Re: [Idr] [GROW] Invite comments on updated AS_SET deprecation draft
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 29 Jan 2023 10:26:11 -0000

Dear Sriram, others,

(speaking as working group participant)

On Wed, Jan 25, 2023 at 05:17:08PM +0000, Sriram, Kotikalapudi (Fed) wrote:
> Please let us also know if you would have interest in providing an
> implementation.

Perhaps it is worthwhile adding a suggestion to the document for BGP
stack vendors to make it super easy to reject BGP routes that contain an
AS_SET anywhere in the AS_PATH?

Modern versions of OpenBGPD have a single 'global' knob to reject BGP
routes with AS_SETs: https://man.openbsd.org/bgpd.conf#reject
As draft-ietf-idr-deprecate-as-set-confed-set progresses towards
publication, I think it'll make sense to change the default setting to
become 'reject routes with AS_SETs'.

I imagine operators would benefit from availability of similar knobs in
other BGP implementations too.

Kind regards,

Job