Re: [Idr] WKLC transitivity considerations (was Re: Adoption call for draft-heitz-idr-wklc-02 (3/9 to 3/23))

Ben Maddison <benm@workonline.africa> Sat, 20 March 2021 07:55 UTC

Return-Path: <benm@workonline.africa>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 100CD3A1D04 for <idr@ietfa.amsl.com>; Sat, 20 Mar 2021 00:55:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, MSGID_FROM_MTA_HEADER=0.001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=workonline.africa
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QgtdUx6KUTzs for <idr@ietfa.amsl.com>; Sat, 20 Mar 2021 00:54:56 -0700 (PDT)
Received: from EUR03-AM5-obe.outbound.protection.outlook.com (mail-eopbgr30080.outbound.protection.outlook.com [40.107.3.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BD2903A1D03 for <idr@ietf.org>; Sat, 20 Mar 2021 00:54:54 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=iQPbhmgodzDrNPmrJBaCYLia+lIyCT+FTiIkfq8CEuASTDjigJWQMrhYr4xGLzKoXE7Mw5FAE0abERQYFHBUdpyf/GoDqM2wFw9OKWmsywFQM7t5zDRvwK+ZTROGOy3FGsmUQg4t7MHsUop4pwzgfK61XyaaCWqq92NHQlpMi3ZjVpnBTZdAE69vCjNtCRZ65bEB60C628IdhR70lb9DH9T6BtTqTukWT8Y/6oACtJB48pof/UpCVI8QVYSgpNEOAlHtyC1MEh2AO/oKJlJXQnuNz8Ci7Tso857qrtHQT6+qn2wbVcxt2WmoZZSSLXGEe11cJmj1GlcZbXWAIGCuFw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=7IIsPzckzhMMl5Y0khBJARfefxWATIAR3Rg87plpkdI=; b=CeuKK+R6d5dM18r6Mmdl2D/7fZ+CWdArIfZAtC352zcruv/s5DkoMTbhxjxcmYNOkpyRW7Erm4vuX0B4t9hHJU463JxlR1Oeo9F0bI/bhPfCYqzuqxbN0QHZF0+T5OkuoqrXdiCShPPPyxsKyHyAWERCkl/B44PRv0VR0gzZBE4dGaJOZNgqpZ5TNh4jgXXoJonzgvMgAotnrshNBwXEKA6d2ZCkyrS6clxy6T9UGB0b3ohlHJzIUrGCyv4O7+Tf78M3izS5vaLVFsNfAa3yDvC1tfvZM36MHfPUyZyTRpYwppgBBCroF0kqe52Gu7mtomDEW72lPwPar3hlN10unQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=workonline.africa; dmarc=pass action=none header.from=workonline.africa; dkim=pass header.d=workonline.africa; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=workonline.africa; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=7IIsPzckzhMMl5Y0khBJARfefxWATIAR3Rg87plpkdI=; b=gmIr9DSSw5O7ktvGr1SMsHsDsDsFT/SEa58akhXpeeqvFp4QRo2owL0Bww4A8LB2OnlQ1rByC43VU+tM2c4g4dODW/XyQEqJ1WJ4vO84Y6rp1c5hb2HU2It4r0zfyYrBuA3NWpvmqZB2EGaJ1jrQXZoTi4TWJo64HWARatpTZO0=
Authentication-Results: dmarc.ietf.org; dkim=none (message not signed) header.d=none;dmarc.ietf.org; dmarc=none action=none header.from=workonline.africa;
Received: from DB8P190MB0746.EURP190.PROD.OUTLOOK.COM (2603:10a6:10:12a::24) by DBAP190MB0951.EURP190.PROD.OUTLOOK.COM (2603:10a6:10:1a3::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3955.18; Sat, 20 Mar 2021 07:54:51 +0000
Received: from DB8P190MB0746.EURP190.PROD.OUTLOOK.COM ([fe80::30ad:1e5a:51e1:870]) by DB8P190MB0746.EURP190.PROD.OUTLOOK.COM ([fe80::30ad:1e5a:51e1:870%3]) with mapi id 15.20.3955.024; Sat, 20 Mar 2021 07:54:50 +0000
Date: Sat, 20 Mar 2021 09:54:41 +0200
From: Ben Maddison <benm@workonline.africa>
To: "Jakob Heitz (jheitz)" <jheitz=40cisco.com@dmarc.ietf.org>
Cc: Gyan Mishra <hayabusagsm@gmail.com>, "idr@ietf.org" <idr@ietf.org>
Message-ID: <20210320075441.t2lw5rqggt6t2r3e@benm-laptop>
References: <012b01d7170f$7ec90310$7c5b0930$@tsinghua.org.cn> <BYAPR11MB3207D4E973EE9ED170687E1EC06F9@BYAPR11MB3207.namprd11.prod.outlook.com> <015601d7171a$036be470$0a43ad50$@tsinghua.org.cn> <CAH1iCiqy3uu0SF2i9TyTRwCdt2d2Ud9+nUCtRG+vc2E-gwfLPQ@mail.gmail.com> <20210319162953.GR29692@pfrc.org> <BYAPR11MB3207F7BC05E7F10C09373E6EC0689@BYAPR11MB3207.namprd11.prod.outlook.com> <20210319214341.GT29692@pfrc.org> <BYAPR11MB3207F5FB11E2881774AD1767C0689@BYAPR11MB3207.namprd11.prod.outlook.com> <CABNhwV01GZPoJwdbyOWuzD==+XNtqD5cyOMmtDgQF4kKOqhxwA@mail.gmail.com> <BYAPR11MB3207730D5E49ACB5FF5C8EA3C0679@BYAPR11MB3207.namprd11.prod.outlook.com>
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="pnkipalldwat6snt"
Content-Disposition: inline
In-Reply-To: <BYAPR11MB3207730D5E49ACB5FF5C8EA3C0679@BYAPR11MB3207.namprd11.prod.outlook.com>
X-Originating-IP: [105.233.97.54]
X-ClientProxiedBy: CT2P275CA0011.ZAFP275.PROD.OUTLOOK.COM (2603:1086:100:b::23) To DB8P190MB0746.EURP190.PROD.OUTLOOK.COM (2603:10a6:10:12a::24)
MIME-Version: 1.0
X-MS-Exchange-MessageSentRepresentingType: 1
Received: from localhost (105.233.97.54) by CT2P275CA0011.ZAFP275.PROD.OUTLOOK.COM (2603:1086:100:b::23) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3955.18 via Frontend Transport; Sat, 20 Mar 2021 07:54:49 +0000
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: facd4925-2c7a-430e-4ef6-08d8eb75705a
X-MS-TrafficTypeDiagnostic: DBAP190MB0951:
X-Microsoft-Antispam-PRVS: <DBAP190MB0951E0463A46B881AFA5201FC0679@DBAP190MB0951.EURP190.PROD.OUTLOOK.COM>
X-MS-Oob-TLC-OOBClassifiers: OLM:10000;
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: fy5Fv+xd0SHh9HSNP4qve9qm50Sv2aUziYNiVmLXux2SKlw4guuvrwJgdbCIXvIxGaPuzn6YpvnWsI0d8Uksxi81i1+MA2GCKl8va4ihgAcWVXRqyQJz057w67Jaq6xdudeUlkCvALtMejzMgfGvumXSazb2Catf8uLPuB0s7KxuLlrnydSEW4UtrjFSLeFtxHmbCh7F4bBg29ZbLUAFCPtA9pD41gOemzjQ0DdyMJmJbwfMl4OjkI1JX5fLYla1GVQjIMY4BNFLXOep4fXfE/aljfvVHn2svaSLix3hutIzMQVxahCsDDZMYekiqrIaDadC+JYg2CyhtZfbXm6nf9P7Sgi5IaxzPJk0n4vG95jduUsoGUHL8pZeWTDOAKOhQItVPUR4Pd1yseH4MblxVgksVMexs3g+9EjXJJb74PxjGdfXQhG3r9lg2y7mNhf+Y8b7Va2uQA3+yNX4UWvXHuxbMpUc19vlaJ/DBSNaziRohXyIUy5vFz59H0LHLM77ww2vTW61SCLB5Id8PwvhxrQKqTUdt+Cfkg2YOsJEKR4bBtORW78vayDmQBkgzTmLT6OP0bb8r+vCBDqD/R49GmwUUmGzEwiIWYgsW+OXICkX68CW7VTN7bHC1FDEOOACHqFqByx/bnahwysPc0pJ3xKx96qxEqseW2f/qUQAHgDpTZJEdAfqFPJS38wYwdhTje730DQzd29ue67yFLh2Ww==
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB8P190MB0746.EURP190.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(7916004)(366004)(346002)(39830400003)(396003)(136003)(376002)(21480400003)(956004)(1076003)(8936002)(38100700001)(5660300002)(83380400001)(316002)(478600001)(26005)(16526019)(86362001)(66574015)(33716001)(54906003)(6496006)(186003)(66946007)(2906002)(4326008)(9686003)(6486002)(6666004)(44144004)(52116002)(66556008)(8676002)(66476007)(46492009)(2700100001); DIR:OUT; SFP:1101;
X-MS-Exchange-AntiSpam-MessageData: vL1fMNPYkYZiGk0dUOMTUrBYBKVNpt05vbYrFCVJW6bJSNPQ0/T8iSVFcuItixtq5t1u3eIAQSOJz5ASfIC5BkPcZaQaL/C2+TiwhvS7C+t6bjCMpGiI8o/0U1y+R+tUH9rNQq1FwC4/34nvuzfVcaBJttzA8bGK6MyX8bEGtJ3YxV968WDno6R5a5+vkPXE/PE8zswK0x5UroXxX4fqYgqzYDFJayTG63UmwcRcicwIKwliiMvB0Wp1TV0Z6C3qBSk9F8N4Sewp+pU5c/KUEIqH/TuKkLbgil4agVhghjpqHpVDR03/XMots/ViXIKTA5iyG8/hdCWXtgFnSrbSwyKJvX20UJVuflvuMUv2TnQX6mf7r2oJCJtQ90tbCaOiVgJ059XQG3f4PsZo+LLteg92UXbB6gmTzk5MGidUzENEcG0jrW1uarrCpOrpaju5TUj62fBfVXUQyxumZVEvrK3bI5Nu/MwO7oGG+U2rm1uNLhB52byIkNKHY1q6nxI0cJV2qxPH915f1qC1Q94Eg/u4zZfNBZu/ln4KJErkv6wBNbkdCESHxOEwMuKQCWCBl/EIa8ya9RoP/I+dPLAJluNiyA9tWBijeQf7W8NPneXkVJUN4eaoRtYMSvtgRQEiVAEyF8OOR86sRks/Pkgh9X84Kc3S6cRlQTdkUidyZ4c4fiUhICq0kr2Md+DxqOzyfpQziCR+0KYCg9ovBtM1aS3RKNpAzRJOUSE+PzV0IjoTx6Bb0WsJUeM4FxlAMnc3b2S/vN7g0qUxmjHmwOhVvl0cXnPfLaP8Q3mAgb+AeAnskeVNINhQnjgsIHIZy0fiIBBTToU7fRCa14jDs2WhBl7RTmCeSU56KuXYMnS+odfJBH+dyQa1Bo+etN2gNOXSvyGC8GBiOHSUe34r3h+T1npqTNFEi/GtG8hlxgv3wwZKM/9Zk92aV32dRAesl7UHj15ZQwCIsVk+WE+0p1df+y3j387IX3wc3wuDkkgTBF9BQ0LR8qxaki3rWkp7riXXeAWjgPoAXQHgrN27xWAlMm2elDFOlpm1lX+sF/xGCwHBTMah2PHtnLrgnw2OIhlZ1awmM5ea4RvHqPkUoROC+SSPeXVDFqe3LOjsFFpaySpmWw57pyb8QAeulV0KMQHbOmMatPOW3JejGJzlZnCWVrSx8QiwNXP2o5FaPjTLE2NvHbP5p6N2EaJbeKGFOAAthiCNvvxqNhlCZnfwOOWf3ly5vy8hfxDsoXUjuTvY/CgQ2ZAYVn59y1UIDxk5cL8vT/ODVRWBZJiajUoiiVbXA4bvVbjecTL1fdgYBv8TzCQ0ZsjE1mCBEWhm1YF/0vwK
X-OriginatorOrg: workonline.africa
X-MS-Exchange-CrossTenant-Network-Message-Id: facd4925-2c7a-430e-4ef6-08d8eb75705a
X-MS-Exchange-CrossTenant-AuthSource: DB8P190MB0746.EURP190.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Mar 2021 07:54:50.6351 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: b4e811d5-95e8-453a-b640-0fba8d3b9ef7
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: PMFRUz1j+y4uw3+HCFE1lvKJQZGd9tQsccNiHG1Byy9Gt/y04yasBi/2o5PUVCk5Mw1IKjblSR35QjkzM5adQQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DBAP190MB0951
Archived-At: <https://mailarchive.ietf.org/arch/msg/idr/QxZS5U5RbcldhXHlBk5bEpOZGAc>
Subject: Re: [Idr] WKLC transitivity considerations (was Re: Adoption call for draft-heitz-idr-wklc-02 (3/9 to 3/23))
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 20 Mar 2021 07:55:00 -0000

Hi Jakob,

On 03/20, Jakob Heitz (jheitz) wrote:
> A local configuration is required to make an eBGP session NOT
> an administration boundary. This configuration should be
> applied at both the sender and at the receiver.
> Without configuration, every eBGP session is also treated
> as an administration boundary.
> 
I fear this may end up being a bit too binary.
Depending on the semantics that end up in WKLCs, a pair of operators may
need to treat a session as a boundary with respect to WKLC-A, but not
with respect to WKLC-B.
Without knowing exactly what semantics may be defined in the future,
it's rather hard to know whether this will be important or not.

> An iBGP session is no boundary.
> 
CE-PE via iBGP in an IP-VPN?
This probably needs to be a configurable default too.

> The transitivity bits should not be used for LC matching if the LC begins
> with the WLC distinguisher bits 111101.
> Such LCs should not exist in the public internet, because ASNs beginning
> with those bits have not been assigned.
> 
Has the assumption that these don't exist in the wild wild DFZ been
checked?

One of the motivations for the shape of LCs was to give operators an
alternative to defining semantics in private/unallocated ASN namespaces,
so these *shouldn't* have appeared.
But I wouldn't put money on the fact that some bright spark hasn't gone
and polluted this range already.

Cheers,

Ben