Re: [Idr] Comments on draft-ietf-idr-aspath-orf-10.txt

"John G. Scudder" <jgs@juniper.net> Mon, 13 July 2015 19:54 UTC

Return-Path: <jgs@juniper.net>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 88A4D1B2DF5 for <idr@ietfa.amsl.com>; Mon, 13 Jul 2015 12:54:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EUbDS6tGJuIJ for <idr@ietfa.amsl.com>; Mon, 13 Jul 2015 12:54:37 -0700 (PDT)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0122.outbound.protection.outlook.com [65.55.169.122]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DD2191B2DEF for <idr@ietf.org>; Mon, 13 Jul 2015 12:54:31 -0700 (PDT)
Authentication-Results: pfrc.org; dkim=none (message not signed) header.d=none;
Received: from kblanc-sslvpn-nc.jnpr.net (66.129.241.11) by BLUPR0501MB1825.namprd05.prod.outlook.com (10.163.121.148) with Microsoft SMTP Server (TLS) id 15.1.213.14; Mon, 13 Jul 2015 19:54:30 +0000
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0 (Mac OS X Mail 8.2 \(2102\))
From: "John G. Scudder" <jgs@juniper.net>
In-Reply-To: <20150713194213.GY13783@pfrc.org>
Date: Mon, 13 Jul 2015 15:54:20 -0400
Content-Transfer-Encoding: quoted-printable
Message-ID: <A59AC52A-9468-4E81-93F8-10251BF2C128@juniper.net>
References: <20150706141017.31158.42788.idtracker@ietfa.amsl.com> <20150710210111.GU13783@pfrc.org> <m2zj33zp19.wl%randy@psg.com> <20150713194213.GY13783@pfrc.org>
To: Jeffrey Haas <jhaas@pfrc.org>
X-Mailer: Apple Mail (2.2102)
X-Originating-IP: [66.129.241.11]
X-ClientProxiedBy: BN3PR09CA0002.namprd09.prod.outlook.com (25.160.111.140) To BLUPR0501MB1825.namprd05.prod.outlook.com (25.163.121.148)
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB1825; 2:cyAVgVCmS7blFbuqcn4CUk3J6M3pj+RByHZpCuQ/NGmfKPptWCz1whxxWIaUHiuu; 3:amw2kYrapv7ckJT9uyN+652KPNh1jiD/IfTgLqr+YbVaVWd7B3vBIY3bTUzu6SHMT8YtLs+vnwByYrYjE932HvpCDtmozU0Ktdyb57RonzdgCdjBNHKUWQt3t29jkRD9DaGKVVzsVqQcrH92SZ7FLA==; 25:J4DeHyRZ7HLqBTGYiLATmqNEucqDAvIX1dMNiFwUb+WEu6Wcoe6JqTjOPSHrg8e/WtCcrPl/aRJoEdcD8iHlVpMYIcdD0/gDI7CUmrC6gLjiM1p4KIAEuOELki3vqCPk7Kps5pOoxIxH7SsgOvjg0RUFRW6858gdXU1fw/94L1QZIU79GxnETG2XWYDdltVrVG8zIbnKfp6YL2WGcxFVRukDzvTUYLrq2w/j/XDh8y7GiRhJKWevj8Z1QJ4OPWZRkYK3x/xj8baeDrNUbLojgw==
X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BLUPR0501MB1825;
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB1825; 20:t/1kLuUSgj9nzD419CRNzOaGnhPkN1LoTPzoJdLv8g7bp5gzQ6ycAl3o1v5KG3C/9BYaYV1HYkNXP/n6esyk3sHtFZMdgR+v5GimnqKKPVW02zOVSw0hSTqpXqaZrABudST063oR1tU/7YVaRHHTZcM5Dk+K/6Zx4jI8eR/ba/MWM6wDfks20hGu723d5rlSSYZPoe5KoOQj5RnaAZMf5DYee5evISLCC56xKvn7N5ciYcLlK2/QVG3U9zBTsPX+lYXF4PENIIngml7zjZpOrEvlLHpZyhWprRuJa2cp9H41YSewVZskTDJDRzWDVSKKHpV2qgX/xz8eQQoacYj3aqTnSUxU7P5qx3vR+XQAZB/MCjlld7fzxCcqAzAO64Q4ODG+iivWN2o7UQs04piy35SM8LsN+0dp2i1Hw6rm67me2dGZzr0LSSotnEGcUKiE1xsqqEoOAys0Rwz7INOQKbbHrtQ1mAPwfuvgS822GawPUGvpVE4uu7tWjbjLIOnb; 4:hq+Ay9u7eoIy06oFI71aebiodvAFNqio+5KjgJboyGmJi66qY03OwP493iCy4b7Fs0dhmnPpby80NW9EKxT2C6hHOzTp5Jcx1h0ySRjhpjNBb3/qRkGJBgT81EZU4X+z9CdrCIGyGbCj/HY8sOYr4EeWghvWEXRA3cd3t8PAJA8uQ6AlJIeT51S44DcCDWgng+TOaeMchavbirlzffSBjw1/JO2Yytqzy+mutNKvlckihs3DhaXQbKTREEEH4vZjNSKPH2y7U5QNKzgvrax/jZXCMM6k8ePdyBlViC8YxWo=
BLUPR0501MB1825: X-MS-Exchange-Organization-RulesExecuted
X-Microsoft-Antispam-PRVS: <BLUPR0501MB182597FEEFEADA528D14A891AA9C0@BLUPR0501MB1825.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:;
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(601004)(5005006)(3002001); SRVR:BLUPR0501MB1825; BCL:0; PCL:0; RULEID:; SRVR:BLUPR0501MB1825;
X-Forefront-PRVS: 0636271852
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(6009001)(51704005)(24454002)(377454003)(19580405001)(19580395003)(87976001)(46102003)(46406003)(53416004)(23726002)(83716003)(230783001)(76176999)(97756001)(86362001)(66066001)(47776003)(36756003)(93886004)(42186005)(77156002)(92566002)(62966003)(50226001)(2950100001)(82746002)(110136002)(122386002)(50986999)(40100003)(189998001)(5001960100002)(50466002)(33656002)(77096005)(57306001)(42262002)(104396002); DIR:OUT; SFP:1102; SCL:1; SRVR:BLUPR0501MB1825; H:kblanc-sslvpn-nc.jnpr.net; FPR:; SPF:None; MLV:sfv; LANG:en;
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB1825; 23:eRh4Y+RyXI84vdB037ENT17v/7yt7jZZ5Se4ElMl1JakaasLogAH46TdcDypjZRdTUg9H03eMJI/hTRAA4aN6B9KXH2M7lLsI6iBLbSK5JJLfNNyXD81FBxZonYGn4UCAL9IrYrUjpPoSLkvy//meRijVjj7S/fdp+RnHUDjNy/vV1tZgCoVdgvV1eKZjEpX1GyKGc5ilGfj98BWdogLf5K6os6NGqCQ0kOgLU9HDgozFZmE+2eKMMJncxlgDCeNuJA20zqq0a4sGnQkZwSixpwXyQZLiMxytaRBusA7/iCSCjBDvKh20qbUsQaSYXhy1c/cP95p46y0yPUYoWm6cN5dFn5fyZ9SKpvlOZ887NoGbaE9QSr16VUzj27ifGKUcPW9E5JDXfgmZb7pVlM4piwyP1ZrG1O6GBIV1S7+0HaRdz9eLiu+1yx3/InclJwmDRtrAmJZcd3rVD7gf0MtscnUivcDAFdV9qqLqO365yNOcivQ/00kMFuvqdSUKpru/dZlDkOhecd/tGRChw3JoD1uM1sxp3pNngA0GdjdwpnOIXMaihqSfw9G4udP9m6hS3N6TNefDXlVoOnqxR3I36Kr+hTxIzIBbyOZxUHKtJHkFiQIh68PubH6MvpqC5euhugwbLoeLCuggeGOI9XudWTRa6tBSEMNfzOwz+l2JUrbERkl6HGQNxYXGQwpqnjyMODmrRxNspP4/1aHw/bDzf/vRskZ2F1uYlG6J1f02kmjgkhqsOJg2AMBghBTM54hOxtt0uf7oP8R7DEQ/2kaQ9XawDT7a8z5I8moSiRd1jTCvdy7HXZLTypNfx8ZXUWhIWfe9myMksdwyzddJf4682BsWov5A8iw2w5UVV09eyCB/jK4AESrkRWYbSdcJELUTpbhYGng3iWvl0Y7cLrUwS2ZUpuuRj6FgWsdkmG7b344nXOcUk7x1BRd1nz/cCP79KswrIyGVbxwntRuodR+91xZbZATscUFibDU39wMr08fM2z6I362Sma/Iy+sEhZ+
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB1825; 5:Jkh2iupmD9sgOxkteUMH6SCy+U5oPYaonDDTUd8yrvE2Gq/F6NxjMcdni97ZSiHFFt//HNqLnbpzjMdsz40EMLJszdPIXguQGOYpcSPom9seoDgTfJBm0qO9eWfPt/PyevQyZJBeZGG8RuAZv2f5nw==; 24:zSAzQf0ZCkA6SzDJLiqZfNVel6JNCffq8DZN2URlYZERaXlTKjJF4u9h7/A4PcJuTZwHELD2LWTs0vbjilh0YKWBckYpa248cX1s17fGtNk=; 20:K+1JyTiO/cM8QRklu1DPlGqtfxgdk8BopsKcrD2zuelLygDe6VBWLk9K+8FDqv4WZhUdvxDfOSinYJkLxcgwbQ==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 13 Jul 2015 19:54:30.2132 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BLUPR0501MB1825
Archived-At: <http://mailarchive.ietf.org/arch/msg/idr/Ln9g7DsVfqbaUJfn699mFK6ctLg>
Cc: idr wg list <idr@ietf.org>
Subject: Re: [Idr] Comments on draft-ietf-idr-aspath-orf-10.txt
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Jul 2015 19:54:38 -0000

On Jul 13, 2015, at 3:42 PM, Jeffrey Haas <jhaas@pfrc.org> wrote:
> 
> On Fri, Jul 10, 2015 at 02:22:10PM -0700, Randy Bush wrote:
>>> I must admit to being somewhat dismayed by seeing this draft resurrected.
>> 
>> what gets me is the threat model.  you can trust me to tell you what you
>> can trust from me.
> 
> There's perhaps an amusing element of "trust, but verify" to ORFs.  In
> theory, they may be generated by your inbound policy sent out as an ORF.
> This doesn't mean you shut off your inbound policy, just that you hope that
> by pushing it outward you have to do less work.

... and you can argue that the cost to the sending router ends up being low, nil or even negative, making it a win-win. This is because, while on the one hand the sending router has to evaluate extra policy, on the other hand it may construct and transmit fewer updates. Of course whether this ends up being borne out in practice depends on details of the implementation and the contents of the Loc-RIB and the ORFs.

--John