Re: [Idr] New Version Notification for draft-wang-idr-rd-orf-03.txt

Gyan Mishra <hayabusagsm@gmail.com> Wed, 26 August 2020 22:42 UTC

Return-Path: <hayabusagsm@gmail.com>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D13A3A09DF for <idr@ietfa.amsl.com>; Wed, 26 Aug 2020 15:42:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.087
X-Spam-Level:
X-Spam-Status: No, score=-2.087 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_REMOTE_IMAGE=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rXHl3erG-4FB for <idr@ietfa.amsl.com>; Wed, 26 Aug 2020 15:42:38 -0700 (PDT)
Received: from mail-ua1-x92c.google.com (mail-ua1-x92c.google.com [IPv6:2607:f8b0:4864:20::92c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 56D063A09B3 for <idr@ietf.org>; Wed, 26 Aug 2020 15:42:38 -0700 (PDT)
Received: by mail-ua1-x92c.google.com with SMTP id g11so1088249ual.2 for <idr@ietf.org>; Wed, 26 Aug 2020 15:42:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=ODcpt9DGODwIN5jcUswpeoMDDRsDBGXoVhwj3MbIFCQ=; b=OSh0L/GXajCpX0XrXNoRp4fDVe8j2GjhUndLJvAWQkgdRR/s2RQC/2Tp5khpDt9ybZ USBxnNKFIXDEWVZn4o3QxXv/vU4qvorRW9pS/lMdR+EZDh+ADJmnZVVawriPUCJU5I/q jdWi9RDHYtLtYvi3K7tYKThFbH1zrmmoa0NT45S4Z1zMiy8rzxqq8E8QTTQp5bHHjCDu m12z87+DgblKsExycdbqm17Yp2cqn16A2nfW3I9YsOn4Owvra3TIRteWg8/QiOCSUE/s +mLBuA6ceqkq6jp0vOY3V3wlCw6riamsIf2H0enwJdD59mym1QAwKce84VYwd7mQcDAL H8PA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=ODcpt9DGODwIN5jcUswpeoMDDRsDBGXoVhwj3MbIFCQ=; b=Ob0JpASUl+0ORdD7aJnaVySTnhLnk9W3Mt+nmRimOGst8VKru3JA5/xXSPuATygujl UJlYwCw8Scj4kCZc8WV8zaYvOdXGFh/oXFtq6EcN9xmlX7u8stcmVsq6cfRlbhtFqx1N 4EQG6Z6bi5g8txAuZZgj74KaMO6SC53etTI/uTDyApBPM7jNH5ytFnRqeHdenSgUZ4zX vVD8bHRjshQxd7astFFJhavPsaLx6iZHBA4R9vJ8kq5yHZNNOhLZPoL35Pe/fhR+wlcp uRyS/pW9utgvxU7aoMSstnQRgLb9V+Oe5W656pQyEPUyMiqplyun99KcDoG09QoW+AzC Qm0w==
X-Gm-Message-State: AOAM530hd/hMAJV9gXurOozkXnOvPK2MOSdXAbAzmai1LBVWDnsK38Ry 0cD69tH01YUdRVxZ4ptoXIwh5PoR41p2oX2L/54=
X-Google-Smtp-Source: ABdhPJw83iyffNBI5ZEVY+vfcw7N/OqtdHaMYCG2ob3jitA20oGP8uFWNQpmKGHmLmg4M2w5t+3oHSPW7KvzyBQDhvE=
X-Received: by 2002:ab0:6f11:: with SMTP id r17mr10602467uah.118.1598481757232; Wed, 26 Aug 2020 15:42:37 -0700 (PDT)
MIME-Version: 1.0
References: <tencent_EA7B36E1CC8F28E736B6F6623DB239F57907@qq.com> <CAOj+MME8i2D1BP8A1fRcye0D+VySMi==wzr_uhmCBm2ydSonLQ@mail.gmail.com> <CABNhwV1fnVtKwCaQ7SrdK8fzdHD7BbGijWZCuQ2MxG8XbVghow@mail.gmail.com> <CAOj+MMGQqC8zkyRfouz_8z0355GvbFw1JW8aAY5vE6B6zXHT4w@mail.gmail.com> <CAOj+MMHH2oAnnVhJLGinzvhUv7Pg+p2iFyCWL7TXNxOUcHkYSw@mail.gmail.com>
In-Reply-To: <CAOj+MMHH2oAnnVhJLGinzvhUv7Pg+p2iFyCWL7TXNxOUcHkYSw@mail.gmail.com>
From: Gyan Mishra <hayabusagsm@gmail.com>
Date: Wed, 26 Aug 2020 18:42:26 -0400
Message-ID: <CABNhwV0v1aRJQkDR6D2bStpscarBDPVR3_B=Z849PcpTkaQj1Q@mail.gmail.com>
To: Robert Raszuk <robert@raszuk.net>
Cc: "UTTARO, JAMES" <ju1738@att.com>, Wei Wang <weiwang94@foxmail.com>, idr <idr@ietf.org>, "wangw36@chinatelecom.cn" <wangw36@chinatelecom.cn>
Content-Type: multipart/alternative; boundary="00000000000051e3fa05adcf8950"
Archived-At: <https://mailarchive.ietf.org/arch/msg/idr/RQDnq3KdZoejIuTCbzfFasewDWQ>
Subject: Re: [Idr] New Version Notification for draft-wang-idr-rd-orf-03.txt
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 26 Aug 2020 22:42:40 -0000

Agreed that AB is a nice hybrid of A VRF data plane isolation security with
the scalability of single VPN session which was the drawback for optA.

We will add some verbiage around AB as that is as you suggested much more
common as it resolved the pitfalls of both A and B.

Thanks

Gyan

On Wed, Aug 26, 2020 at 12:19 PM Robert Raszuk <robert@raszuk.net> wrote:

>
> Just to add one point I forgot to mention - You can also enable and use
> Inter-as option "*AB"*
>
> Protection as good as in option A with inherent native scalability of
> option B. Has been supported and deployed for years ...
>
> Thx,
> R.
>
> REF:
> https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/mp_ias_and_csc/configuration/xe-16/mp-ias-and-csc-xe-16-book/mpls-vpn-inter-as-option-ab.html
>
>
> On Wed, Aug 26, 2020 at 6:08 PM Robert Raszuk <robert@raszuk.net> wrote:
>
>>
>> > Gyan> The primary use case is for inter as opt a or b flood of routes
>> and there it is very difficult to control
>> > in either scenario as it is going between administrative domains.
>>
>> For inter-as option A you should use prefix limit between VRFs.
>>
>> For inter-as option B & C it is very seldom to see opening up anyone's
>> network across different admin domains. Lot's of things can break. The only
>> deployments I have seen for option B & C were across multiple domains under
>> the *same* administration.
>>
>> However if you are concerned about B & C I would rather ask your vendor
>> to provide perfix limit on a per RD basis for VPNv4/v6 or EVPN sessions -
>> no best path run needed. Very simple implementation extension and you are
>> protected without any bgp protocol extensions.
>>
>> Thx,
>> R.
>>
>>
>>
>>
>>
>>
>>
>>
>
> --

<http://www.verizon.com/>

*Gyan Mishra*

*Network Solutions A**rchitect *



*M 301 502-134713101 Columbia Pike *Silver Spring, MD