Re: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)

"Jakob Heitz (jheitz)" <jheitz@cisco.com> Thu, 11 February 2021 20:19 UTC

Return-Path: <jheitz@cisco.com>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1A52E3A1903 for <idr@ietfa.amsl.com>; Thu, 11 Feb 2021 12:19:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.619
X-Spam-Level:
X-Spam-Status: No, score=-9.619 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=QDxIIykc; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=YXojGkvx
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YwN1DP8cUYOa for <idr@ietfa.amsl.com>; Thu, 11 Feb 2021 12:19:16 -0800 (PST)
Received: from alln-iport-3.cisco.com (alln-iport-3.cisco.com [173.37.142.90]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9368B3A1900 for <idr@ietf.org>; Thu, 11 Feb 2021 12:19:16 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=18926; q=dns/txt; s=iport; t=1613074756; x=1614284356; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=3NLjwKISb1mr9wis/E5MPVPMX0HEeoRn7tKuO5TsHY8=; b=QDxIIykcsVbVdAPuZOKKMY8wAxXhal0OCw98NSVEXX9FfJ3PCYmcfBXC vI5JaTUG3Ij+CASzrsRWIss6fmgq3THVPl0CJrcmrgi6l4AshwXpk8Ntj 2UVlvHxtU2QoG4ZnJMk7nEAGLoDodNluB3Dc1inHDTe3LMkU/LeR5idR9 w=;
X-IPAS-Result: A0CIAABbjiVg/4UNJK1iGwEBAQEBAQEBBQEBARIBAQEDAwEBAYF+AwEBAQsBgSIwIy4Hdlo2MYRBg0gDjhMDlCmEc4JTA1QLAQEBDQEBLQIEAQGESwIXgXACJTcGDgIDAQEBAwIDAQEBAQUBAQECAQYEcYVhDYZDAQEBBB0GChMBATcBDwIBCBEEAQEoAwICAjAUCQgCBAENBQgTglaBflcDLgGmLwKKJXaBMoMEAQEGhRMYghIJgTgBgnWEBAGCT4N0JhuBQUGBVIIhNT6BBIM8NIJgNIIrggaBBAEnQz8oHQcFA0EVCgQBNxMHAQuQJx4KgyeHP4xKkUkKgnqZFoMWoyyUOJ0pD4RCAgICAgQFAg4BAQaBaySBV3AVgyRQFwINhD2JYgwFEhSDOopYAXM3AgYBCQEBAwl8ixcBAQ
IronPort-PHdr: 9a23:qEca6hZeuWTHC+0QMNmmcXn/LSx94ef9IxIV55w7irlHbqWk+dH4MVfC4el21QWXD5nA6vRLi/ff9af6VioL58XJvHMDdclKUBkIwYUTkhc7CcGIQUv8MLbxbiM8EcgDMT0t/3yyPUVPXsqrYVrUry6u9j8UFRXiPExyPOuzEYiBx8iy3vq5rpvUZQgAjTGhYLR0eROxqwiZtsQfjYZ4bKgrzR6cqXpTcOMQzmRtdl8=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.81,171,1610409600"; d="scan'208,217";a="644602744"
Received: from alln-core-11.cisco.com ([173.36.13.133]) by alln-iport-3.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 11 Feb 2021 20:19:15 +0000
Received: from XCH-RCD-002.cisco.com (xch-rcd-002.cisco.com [173.37.102.12]) by alln-core-11.cisco.com (8.15.2/8.15.2) with ESMTPS id 11BKJELH008997 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Thu, 11 Feb 2021 20:19:15 GMT
Received: from xfe-aln-002.cisco.com (173.37.135.122) by XCH-RCD-002.cisco.com (173.37.102.12) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 11 Feb 2021 14:19:14 -0600
Received: from xhs-rcd-003.cisco.com (173.37.227.248) by xfe-aln-002.cisco.com (173.37.135.122) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.2.792.3; Thu, 11 Feb 2021 14:19:14 -0600
Received: from NAM11-BN8-obe.outbound.protection.outlook.com (72.163.14.9) by xhs-rcd-003.cisco.com (173.37.227.248) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Thu, 11 Feb 2021 14:19:14 -0600
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=cMTwoN4ugEvvjqdIv9p619wyZNQQs941hRlhowMQG2qMt8tURRr13gby4XmpKIesjMoMFrh8OMMj8amF+hp8ro1QPr0fOvrBwiCMk1nc4jubGNvQMV2X7mjph0I3iSBUVbOWs7b18PRWBkSfeKRS5vAAcbp26UuO1MkKpJDRpPd0U1Nvlb1EdoaVkIDoDJxYsJi5d/i/4Fcs8o4iRojJ31sYN9JwT39jL4thdAG2E8JOCVDRIGU8gimRigD6wTda78Zf91szh+M8Xhw0ooiz9cO3QEdytRS/dnfRyJCtmT94MI+5Gu+3ZhgE3PWPexOn+pxpSFe4fIED+ILnV0s2Dw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=3NLjwKISb1mr9wis/E5MPVPMX0HEeoRn7tKuO5TsHY8=; b=XPILFhKZ91yciuXOLG75MrGj3kk4wU4BVw1EPFxccP48jfOI8X8UZ490IE7lhNkiPplUSZtiE0AGWygVEUHEudP4OXp/+uzp+4iqKnZGfAUeAn8ddgoGRLIDSg797N65nYhce0J0EFPJKgggVV7df0tM79h7kkMIQIOA/zJx9Iat9eYdE14isI/nJ3iTp5d/N9G5SG7W7/vvsk//W8uL2fZ17IA+giqJVoCBFVF3hLPOCL78LMSgkKA2dJa3v9Djb+Rzrsz/S//LTAZC9qfKmHWEclsMlQfgq8D0D4rfBwMsYmSdDb1P5bHnF7x+48YM3N0lX/Vv/JODL+VJKi8yAw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=3NLjwKISb1mr9wis/E5MPVPMX0HEeoRn7tKuO5TsHY8=; b=YXojGkvxXV+RdGDGQ9jo19OLcSzfGHuFvC2Sl+cbKOo3nfjBfPL5bVVB3i0X3KYSxDU/f0dVG9hY49Zkmt81fKSjq4pzV6CrhzgsymE94/VqkJq2YEW/9wKI7SSz2FYv4McZJ0bQYxzzDlnCiXsdWGfRzfxD5dBJlgWalmsTmKA=
Received: from BYAPR11MB3207.namprd11.prod.outlook.com (2603:10b6:a03:7c::14) by BYAPR11MB2616.namprd11.prod.outlook.com (2603:10b6:a02:c6::25) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3846.29; Thu, 11 Feb 2021 20:19:12 +0000
Received: from BYAPR11MB3207.namprd11.prod.outlook.com ([fe80::c951:3ae4:1aca:9daf]) by BYAPR11MB3207.namprd11.prod.outlook.com ([fe80::c951:3ae4:1aca:9daf%3]) with mapi id 15.20.3825.034; Thu, 11 Feb 2021 20:19:12 +0000
From: "Jakob Heitz (jheitz)" <jheitz@cisco.com>
To: Aijun Wang <wangaijun@tsinghua.org.cn>, Robert Raszuk <robert@raszuk.net>
CC: Susan Hares <shares@ndzh.com>, "idr@ietf.org" <idr@ietf.org>, "Acee Lindem (acee)" <acee@cisco.com>
Thread-Topic: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)
Thread-Index: Adb7C8Tapzr6LUQXS7CFnBh8kC9NpgErJwcAAA2IX4AABtfh4AADGMsAABAsvAAABQFagAABoDAAAAYO6gAAAJ++AAABFeiAAAg1DPA=
Date: Thu, 11 Feb 2021 20:19:12 +0000
Message-ID: <BYAPR11MB3207C614CDD8AA49935B8A66C08C9@BYAPR11MB3207.namprd11.prod.outlook.com>
References: <CAOj+MMEwF3JL6+CCmV2S1bB2OjU_iMGCj=waYhJAZAaMK=LRYQ@mail.gmail.com> <F2F3F1FC-B2B7-46BB-AE73-9EC15BC96A1A@tsinghua.org.cn>
In-Reply-To: <F2F3F1FC-B2B7-46BB-AE73-9EC15BC96A1A@tsinghua.org.cn>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: tsinghua.org.cn; dkim=none (message not signed) header.d=none;tsinghua.org.cn; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [2601:647:5701:46e0:a466:79fe:7183:c553]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 7523fccc-613d-44a5-a549-08d8ceca4c27
x-ms-traffictypediagnostic: BYAPR11MB2616:
x-ms-exchange-transport-forked: True
x-microsoft-antispam-prvs: <BYAPR11MB26163C8EA4D8865419B5167EC08C9@BYAPR11MB2616.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:7219;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: JdHc2WAZa0oLXgf5nOetWqL18Ca9R29RcssVdmsX3en3qO5CxLryk5t6R+HDo+k5DRfJsDX1fUlFHPOOnKNcnTgMVJDILCGBD9WWtR3Ye8459WgkEg8zKy1tKFEZsOzIXqS2s0U1Jiu6v1ZqdFfTDPLDW5BeU16fV/PlueZdx4fg3L5+BcyiYpazJtSspfLS1glMBImpfLF0HfRQH/UnH3/cLVDlVipq+bsoRxHVNaKplsUngw8ZkVWVaxfC3O17fe8S16tpkXm5yr8uvsABzHdUO8LVNvaDyL8uobaBZBRcxyLf9JGLQVS7a9UjQJhnqOp7EtpAcmOBrMtplhL5vNt6wUc9xTqzwGBMBmWUeAGKjIGsOODtmiC1JBtD883XIGcqN+ti2EtvBZqxFt79eJgKxVLr5BsXYCZIWK8F4wdPRtkcjRQvE7zE4s0K6rNbApM35SI5bY37I33WXdpmXP0MkKaZnAwVrPZmmL8zIMXyUf4GPKXJLqeaG9e0hNNojP/HOhW4HnkHGhpTEjRhTQ==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BYAPR11MB3207.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(346002)(376002)(396003)(136003)(366004)(39860400002)(316002)(5660300002)(86362001)(33656002)(83380400001)(76116006)(66946007)(66476007)(478600001)(52536014)(66446008)(71200400001)(4326008)(53546011)(66556008)(6506007)(7696005)(9686003)(8936002)(64756008)(8676002)(55016002)(186003)(54906003)(107886003)(2906002)(110136005); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: X5LTaWGC96CQkSizBa+QUp1KDoecQXtuCUYGsKh9QocUIqqk3bdsrlK3wuaE2uuuK2hlNN16qBvSiAcgXuQ4nucFOFrhfqiycRbuGy7SWRovRsxJKj3DYGHy4+r2J3p3tw/XhEEVTGS7zXk3WDfWQL2almW9ZBssuYcVEuVJ4HO1Kr957liapFtsDY+MtB0ZTQOn4NlScvCEJzGX9pXN+JpeCT2eV2jD9J5g/8tqLd1sWWIAqglOv3Ylw5mZtp7RfUaCMG2685Kkm4ZH7xseW1mPqPOIjHWdT9IfNRz4ofzKVtHNRyXkHXtiOBQ9KjH8eGRqtb+IUsxiAvaZmGjVJOALYEm5kns1Nu2IGgGYUQ+tbAdKIh6YZIOcemWmCm4vjVlNN910EfzI0Y415ZSS1wRaSa51QEWuzEXtFRQqeKugd1oVCCMGzsaDmgSKziE2VBv2G5ThdYiehP55qIONguS+ls4HZWaL5xvm7OZ2/56bBpuqI9lc8QlMldxoAw7KErYRzzJNVIjdOtVaFDPG8DN0MmUbFde3y0/dGUGqgUcumhwrFcbf/HgUha+ximx5FglTKkI/FRA9mNhyfs+xDDqEZ+m2lhlrgS5lymONygY3INw9T27M2aXT3dhVrh8i/9IdjqV9LpvVJgLqJjHW/jFTjdPPkQc5mUkK5H+2pPyxV8gOMhAA2hNf1AP3xZSHGJEC8NoYkZjlSUJdvWS7A1WJowIzO2WoGJ7mTZVzTqzMQEhDp5gQ3S280QVp90EKRwqOChWWhbLwAu7vHfCOHvkARDl+lAyOv46k0MwQ7E3OCmTt1ZTRLsB5OeD+sxsWQn1haeafHNa7KqpgUSuBy2m0IS/nnSjyf/w8nMZaFcW2aybY2pc/I1AxQcNCFFJ4Hw0ap0VcgT506/R3E0yc7/Ub3EnhD5HUFOkBnxvjg71KHVRL+h2Qo8TNd7bXKGXkNX0+VFakl11i7OXRruXtC0/fVyV5vkArnjhMreeZwLqycjCPzWE4emxApl30H9gVsp6jf8NarlsVqWpZy9kV/udBKQo6SBCL13OfPX/VvMWDbEKGrQIiOmJHId26c4d7gMJ1L74dw26fVuOgkiKmJoScHaxc/VRDN29r1VyK/Cejdoex4QYGebjk3ak484uuJt9OoJJ0UxkolF7CLyQytXwXVUI6I2yheeabA8qieHMgNnMDKJI8b+lEihBt064g59juqyT1UdMcWzggxQNwrj4w38dZaCsQJ80NPdDfqvOZFd1NoBXvg60yZ4AMAe12YYipMvme3wjXZF1KtkhjUX1hEBh4hxzXy9QiA6N8E9zYeveScr4FH7H69bRbza37hDqePijfy9FRocFoV9hkj4G/FiAxCPOfdoiPxH6vutitEwjNN2iKhXLGg7z2G/35
Content-Type: multipart/alternative; boundary="_000_BYAPR11MB3207C614CDD8AA49935B8A66C08C9BYAPR11MB3207namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BYAPR11MB3207.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 7523fccc-613d-44a5-a549-08d8ceca4c27
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Feb 2021 20:19:12.8038 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: lR71UIPr5TE0sqj1qcYbjakHeM421RY1UVA7WXyuhdDGdm3Fgyv9/y9wbLuQbGpEppyUa5i5bemncuhPhQRonw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR11MB2616
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.12, xch-rcd-002.cisco.com
X-Outbound-Node: alln-core-11.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/idr/UiEriPCYOYLSHgnZ0HoK-RxrHB0>
Subject: Re: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 11 Feb 2021 20:19:19 -0000

You are trying to have a VRF that is receiving routes to notify a VRF that is sending routes that it is sending too many routes.
The receiving VRF and the sending VRF are separated by several or many intermediate BGP speakers.
Bouncing ORFs back through these intermediate speakers is not a reliable way to achieve this notification.
This is because each intermediate speaker has multiple downstream speakers.
One speaker needs to receive the ORF from all of its downstream speakers before it can bounce the ORF upstream.
Thus, it's unlikely that the ORF will make it all the way to the source of the routes.
You are asking for something like a reverse BGP.
That can't scale.
The way that we find out whether a far away speaker got our route correctly is with looking glasses.
Looking glasses aren't implemented by BGP, because BGP operators don't want to store that kind of information.

Regards,
Jakob.

From: Aijun Wang <wangaijun@tsinghua.org.cn>
Sent: Thursday, February 11, 2021 8:12 AM
To: Robert Raszuk <robert@raszuk.net>
Cc: Jakob Heitz (jheitz) <jheitz@cisco.com>; Susan Hares <shares@ndzh.com>; idr@ietf.org; Acee Lindem (acee) <acee@cisco.com>
Subject: Re: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)

Hi, Robert:
Aijun Wang
China Telecom


On Feb 11, 2021, at 23:40, Robert Raszuk <robert@raszuk.net<mailto:robert@raszuk.net>> wrote:


Now if all of the above is not done or done with mistakes and you indeed experience to many routes to be handled by data plane you stop locally importing those routes to local VRFs by VRF shutdown. The good thing here is that this will be noticed by all attached customers as their dynamic routing will propagate withdraws.
[WAJ] The BGP session is shared by several VPNs and cannot be shutdown in such situations. Procedures that you expect would not happen.


Where did I say to shutdown BGP session ?

I said VRF shutdown ... nothing to do with BGP sessions shutdown.

[WAJ] Don’t you think VRF shutdown has the more broader influences? RD-ORF influences only the newly advertised VPN routes. VRF shutdown will influence the existing VPN routes and its existing forwarding traffic.


- - -

Let me provide the analogy here ...

You are presenting a solution on what to do when we fly low and start hitting the top of the trees.

WG tells you that flying low is bad practice and should not take place providing what to do to mitigate it well - in the analogy train your ground crew not to overload the plane.

You say - Oh well we have different idea instead - when we throw away during the flight some passengers we can keep flying (on the edge of safety).
[WAJ] Just deny the onboard of new passengers, not throwing the existing passengers.


That's here we are with this.

- - -

Quite honestly when we started to deploy 2547 back in nearly 2000s we were preparing much more user friendly solution (a flavor of CSC - not CSC as defined in the RFC) where SP network would only deal with next hops and never with customer routes ... yet customer would have the same type of service. Quite honestly we have had even OSPF reflector ready for it. Problem was that at that time SPs said oh we want to take millions of customer routes - no problem. We just buy bigger RRs and bigger routers. So you can guess what happened with such idea - got shelved as if deployed would result in revenue loss :).

[WAJ] RD-ORF mechanism can encourage the provider to deploy inter-as VPN solutions because it gives them the granular control over the VPN routes propagation between ASBRs or RRs, which can certainly broader the VPN service coverage and the revenue.


Best,
R.