Re: [Idr] Possible to set up priority for Tunnels established by draft-ietf-idr-tunnel-encaps-09 ?

Eric C Rosen <erosen@juniper.net> Tue, 10 July 2018 15:13 UTC

Return-Path: <erosen@juniper.net>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D3DEF130E24; Tue, 10 Jul 2018 08:13:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id S3oiiL8Ej8Mk; Tue, 10 Jul 2018 08:13:29 -0700 (PDT)
Received: from mx0b-00273201.pphosted.com (mx0b-00273201.pphosted.com [67.231.152.164]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AC667130DC4; Tue, 10 Jul 2018 08:13:29 -0700 (PDT)
Received: from pps.filterd (m0108163.ppops.net [127.0.0.1]) by mx0b-00273201.pphosted.com (8.16.0.22/8.16.0.22) with SMTP id w6AF9iQY020004; Tue, 10 Jul 2018 08:13:22 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=subject : to : references : from : message-id : date : mime-version : in-reply-to : content-type; s=PPS1017; bh=N5rGDp6RT4g6Ld7zXnJjR4sHZzbZHwxjQwR2meVWs+s=; b=Zcf6/BH/c+nu82TULwvtnVjBzBGQHsq82Sctk3VTpPgNfMNF5DBcX4CViXNSMcQNdxGj qXAhFoLCC2jT+pMTmF8xC40vA5fid7lHUdmivnZsM1VxeWkz9vXH8j/A6ofhZeY/Ud7n E1a1OlZH1Bx1qNIlK1FczD07ZdrPt0QZwloxIfZyPBD5EOSQ/6dv/+GF2fnuzsyV21EJ J5BMEsCQiNh04wprTDD3hh6+1ozK48DIusqGSx54apF1miF/88NPebVCLkWmhumYilAT VajYpFPkQBFbiuumJqdMJ4jeHR/MKjxxhY5WH/vethoZTCNVdrnEst29jOd1rETmXHUn Pw==
Received: from nam02-sn1-obe.outbound.protection.outlook.com (mail-sn1nam02lp0024.outbound.protection.outlook.com [216.32.180.24]) by mx0b-00273201.pphosted.com with ESMTP id 2k4tum0hj8-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Tue, 10 Jul 2018 08:13:22 -0700
Received: from [172.29.35.4] (66.129.241.10) by MWHPR0501MB3866.namprd05.prod.outlook.com (2603:10b6:301:7b::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.952.7; Tue, 10 Jul 2018 15:13:09 +0000
To: Linda Dunbar <linda.dunbar@huawei.com>, Jeff Tantsura <jefftant.ietf@gmail.com>, "idr@ietf.org" <idr@ietf.org>, "draft-ietf-idr-tunnel-encaps@ietf.org" <draft-ietf-idr-tunnel-encaps@ietf.org>
References: <78D707C9-6DC2-459F-81E4-A53B46F1F019@gmail.com> <4A95BA014132FF49AE685FAB4B9F17F66B0A8BCC@sjceml521-mbs.china.huawei.com>
From: Eric C Rosen <erosen@juniper.net>
Message-ID: <e0782033-0031-163f-de07-c055b4322efd@juniper.net>
Date: Tue, 10 Jul 2018 11:13:05 -0400
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.9.0
MIME-Version: 1.0
In-Reply-To: <4A95BA014132FF49AE685FAB4B9F17F66B0A8BCC@sjceml521-mbs.china.huawei.com>
Content-Type: multipart/alternative; boundary="------------80F6F99B07E14A813365BAF6"
Content-Language: en-US
X-Originating-IP: [66.129.241.10]
X-ClientProxiedBy: CO2PR04CA0112.namprd04.prod.outlook.com (2603:10b6:104:7::14) To MWHPR0501MB3866.namprd05.prod.outlook.com (2603:10b6:301:7b::20)
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: c15a5579-02cf-450f-55c7-08d5e677a645
X-MS-Office365-Filtering-HT: Tenant
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652040)(8989117)(5600053)(711020)(48565401081)(2017052603328)(7153060)(7193020); SRVR:MWHPR0501MB3866;
X-Microsoft-Exchange-Diagnostics: 1; MWHPR0501MB3866; 3:V64fMXnZP28dWcG05rHAg9nVAwAtM+n6QpRooTLmyAII5KYIRj11xI/fuQ4rmu/JTu/YEfdIXpfHaM8fmTS1tf+CRyZ2pLok2cwfpxH+57JufyjC/QTLJj0dZ8Z4cQ+F0lUfDxTirHYVy9bhtn3sItCyXI/sOlojVuQafrJcfVcWQBJqur5xekI48GKjQQ7oAeoKuy25OELJuBKrTl2tIR38G0RG2OMndcHo5TIFYtCKialowCbmAb/o8HHotB8+; 25:eaqIBVr/bB6Cj4Hbyz8tPJLs7nCEWmJeaNiDlvxXIgooZRPKIijD841dCj1HaY2RjHEge0okOcSMWI5zI+0KN5aF2E2pY8G3xLxIp0x7Ri27IwZU3w8z9KnBNUFOHZrm5YKT22WiwINZwL7GJWrpp/ZXEj0PEAZdnJMSSWozTgy8w1ZoO8SIOUSwN/bGoLC511AbQZO45gaOEiEGouivLmsx33hEM9bNuuLck7P4bUVfZdwfgK4yqVpWopL7vK2zdJEoELFek3yIyL56LYC32YY6NzFZ8Ymyy6TBBqG1vlU1QN1oRCVFti+bQL8Km2O6YvX1dIQZ+ddeM6MvWsv9wg==; 31:tNKsfmwesET7mh5+Hd82T+hRSXNEmYycmO+DbwFTYXHC+WRUA0ZJxIvWq6ipSKRhXMn7CzVLIJZKq3+h0HxVX333fLPDvFXvlJsbUZ8ovLnvbE4mlroCUb7HuJnBiBRdiGmv8N9DksABdcBwPVu+w/Xv2nu0Ovmph+91p/oSwX1U36jtE9GhIeDpLep3UJjr5mDV0aFguFqfms+lLXxbUpyq0bNTL/yiEtPEJ+Eqr6c=
X-MS-TrafficTypeDiagnostic: MWHPR0501MB3866:
X-Microsoft-Exchange-Diagnostics: 1; MWHPR0501MB3866; 20:3idPe0fuJQenYzVRiJzIAKtkbGaHcqU+tdVYABXra55Yu61HDTYEiOR6Iv0DWqUm7gSJXX3IdAUfJSdtckOlUXLRkRVXvV1KkoZsKYE47b9ntD1ympIOnKD7DdAuwRW40sUmbKa0FLwlGW85cJQX+a4qcyddm6FlXLAIS4eUpW4ImjRtDEeoX7ACZfcytiri9DtU2MDeKNtQ2zYGWiUFrz6FSGnk5xX+QLOfNYjZ8sULBugin2OCJ7ZqpVtguzJyuoVqfoTK83ZhbXslYxNd7baVS2ipVQvJOf1oucNLTyqQB896/63C2aKO772dnWCz0SAU4bLhIKTB/aKZ6ASjcelIFFZbiVRscKnhQp4DrDnjvlwWOlx7fnxkiWe5djCNm1S6AYKuefiiY2OhrF6J/W52iQlE8GpfaktPLoS2OLlh7AIFu99O2NR5k/CYk7TpKkAEkdT4PZGOqzC7TtWUwc7WBs/s0imIBZk65jSKtx6a7S/f1vIpOIB5TWdYeizMEXvQZPxtlEBZpLoEwm9rIEUqC0RmUMsCkgiagzvvkk1TilS+yPl8KhTwjsQ4ZzSRspO2pDfjkK3jZVrxh+x7Oimo0wysjZ8Lzc1xCGVS+GU=
X-Microsoft-Antispam-PRVS: <MWHPR0501MB38669F59336C27C27C15CBB7D45B0@MWHPR0501MB3866.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(192374486261705)(50582790962513)(788757137089);
X-MS-Exchange-SenderADCheck: 1
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(8121501046)(5005006)(3231311)(944501410)(52105095)(10201501046)(93006095)(93001095)(3002001)(6055026)(149027)(150027)(6041310)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123560045)(20161123564045)(20161123558120)(20161123562045)(6072148)(201708071742011)(7699016); SRVR:MWHPR0501MB3866; BCL:0; PCL:0; RULEID:; SRVR:MWHPR0501MB3866;
X-Microsoft-Exchange-Diagnostics: 1; MWHPR0501MB3866; 4:hT2CuxJ6DNV8ry9USLWtWNTd+c1s2aRToWac62SQYVqNYwtaF4Wi0Br5LMFxXARnbK7vTdHy0n/QFpVTm1ACTWZcW+Qx7HtNZAZz1pz7vyFj+xiX3ElRirFrtDCoUw0xCQGV+EDTLBSOB1xLcCHoPFeNq2x9PJF6l+Hy7TlA1ALr2PuSNzn2ShysfXHZiFN2mV/J6WVkE8u2jCTYOHoM7i74MLDq3Hifj6fthLWsffbKS3HyF3ccco51bIPXKDVvtq5cxte4KDhVvT8UNQpIMWZHOiWxE+NYEf5hZwDOAox5NLVkSgbbnGI1PrSYDGpsFv3lAzpmpGSuDQQOU3qG1HkV7Q352PLENwr6Is8JHq2Y3URmosuximvlrOrTrqBL
X-Forefront-PRVS: 0729050452
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(6049001)(39860400002)(136003)(396003)(346002)(376002)(366004)(199004)(189003)(81156014)(65826007)(68736007)(110136005)(446003)(6116002)(2616005)(956004)(476003)(11346002)(5660300001)(25786009)(316002)(3846002)(6666003)(8936002)(16586007)(58126008)(52116002)(77096007)(53936002)(97736004)(76176011)(81166006)(39060400002)(8676002)(2906002)(16526019)(6246003)(7736002)(33964004)(65806001)(66066001)(478600001)(65956001)(16576012)(53546011)(229853002)(86362001)(386003)(2201001)(14444005)(54896002)(2501003)(64126003)(6486002)(36756003)(486006)(105586002)(84326002)(31686004)(31696002)(3260700006)(37036004)(26005)(106356001); DIR:OUT; SFP:1102; SCL:1; SRVR:MWHPR0501MB3866; H:[172.29.35.4]; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
Received-SPF: None (protection.outlook.com: juniper.net does not designate permitted sender hosts)
X-Microsoft-Exchange-Diagnostics: 1; MWHPR0501MB3866; 23:QG/nw3scvJGgXaBz4zM8ICuquBqVjEZnZXCiJlfw770m3yxJyDGsDui+PCYTWeLc4/ecUU9d8jeTO3mLwcwpN5S4Oyz+zjU9R5khwTPbKr0rYjYtBipJNQX7d+qEtaC2rPMBA8jJxVgiA3YImpewArvou8CpBc2wm+bP2gsqXCnlM39XhSfurWyM3dhRwewk7M0hQtNIhsk0GKuUny7XvvH0jUHUyqoKAHJqyzDbn/hmdO+O2CqEt365dFpmGgzKFVqEYTU4+C91gC1PXWEuANV2kglfFhsrkOzf+uopuvFdGCi9a01EIwHI6seTyCcGlQGDgznPyl2LGpANK9jtFvWTZG8FbCaOxC2on3HARp1SDo5hBaAc0nl/ZEPi42x0rMAUHg9JqIE4NgiAz8JCDpnRktmrcyRhl7l2WlFjPxbzEOT5K9ui5qf2XaUjkaQjrA2FhjDCCug4VPZuEn1mjIsQdpdNm4N9TQsMhzATVYubK0fUvRpqsd18FTtjOoSv+UNlRYS3k6gdZsis0iLPwBf5evgcdelFN+ZXogsorLeVqZYL1w1Hozst2h8zRHGARY1bhUTfRGhM4ZPxNoqUrXnjCA2pEONmiEiqnlH4SE7tFhx4bABBZTzdPlj6FjKd8ujx9uIMUzk8/HeLO/APe/O4IKQYjHEBg7QQl4SToTekmrEcHzrzQ4MUUCnjkwkQ4ql2k3PIQc7YM0I7k+MgjrLpXuKbUN46M8kYK1MJgSlRArrQ/6g3FW5bVAU4Uu+7/6DCAGX/awKCb6EWKx9Xt7uEjUfYUDXJCWnr21h3i8ACjHwL6PcXmMJh53f+KV1TG4ZPNrv3mAvWd5ANKf+NDZ3TF10gTHeTy/R3ATvcf9yQ5aV6UKSCZY8v4dBi3EPi0T/ibpX8b+mWcW3z8MfVMxI54vHn890r4sgzXGREAdhCnLe0iJr+BlW2NqxN4N+D6jc6a5pJTgtvPKBEf0cnzvghHbZgq19FLvz63eYcDZa8pS/p51ljyHvB+ujkEsZy60MB83fU5vsizuPBvdFaoljSYDS8zzDadLxqAl4qdFHAqvtp6xjvHTYWzKzfMbA6F25uFY8ZS9YG2MUiHrYG1L+o9ByTivxxdOwx/HG6ut8duQpRd6HnP8sbgWVmkrZb8OXCNCddQQC1LYcjTFqbVSDDfwto5ssvmL6clAz+xaTeDisA6os+dgCj+2/Gs2rjTbZS96yCSnvnsfj4KWVvxtfFTWP1EvCo9F+WUCm2+2W7RgNOn6s5RHgAMmQIXR6QfoGk5kImm6JIhsC+gC70XLxGFyUV78Nd+zYiMB0RR0gZuLmP6JiWLZRtPwqaHwA9PxRoPWwMVd2MuEVGD9/GXwsMYYWmgCLgjL5lysBV1w/0LDCels0YbiuTQaBhhMR0NXlA3OP7+7QNZHwpobtiSg==
X-Microsoft-Antispam-Message-Info: 8zI/SgL2sHEolXL3M63LWIF8PKosCrv4rLL8eQkpjN4OdSjytjWhBmsLwvFGolyq0UABvGjNRez2H2ds5ARLMC4x4t2uNsgeTipI8Quqj5bbEnhGDM0M18hae9NhHxCH/4PHS054vIf+XlZ8fEnQ0h7RXPryRxW6ploFBuh7Qm8vOpO1QNOQdMuwb1YteD0+2DMDWDt0UAqhqg495AHX2eFM/Tt38nJ7XReu8/iNO//NaIFoJIJ2g7TmbjBwNIWvrMcCZVqlWsPzKqFyKCiGT4MZF1Zm8sI1mxSUbs7oMaADOgt4i7dsmHkOIlT009aawvuuwb4AfIdqF6UhrmLA7ZIOt8gYgZgWT0jWDKWitJM=
X-Microsoft-Exchange-Diagnostics: 1; MWHPR0501MB3866; 6:UwC7xvlJTYhOsDDh0E1LYLZlgWJMDrkieRLWazQpe+le5oX7C7UkAW1CVJYY39pJ00Hq8MoxwQgxfn/T8SEc+Qe+5oWUYIfioia4EQVhPnn4VR6d4FtSOTlWjIVW7YEeqqAYSud3NkViMLPA+IK6kLjqRp5l1X2qll0tTz2JHhKOlNEXLalYmT1hQiBuAhxYHld95HyhwALhDYl6LqcaBNJi+rtpm1GE34sHbb7czsiFPy6arf1GbuYrq9jpKLl9P9ohb7Hf5FknJovh6q2n3t7M2WMH07tNlD9sqxEWHORHzKpc8dUle0vojLaC5f9KSah3Iq0SeLY0VcwOD1Jzmgc3sCCrDFarDTwtRgkCQ//Hy3B0mkhWwKBEms0CDvM2GIpD5YLk5oNtC85rvpVRyW5jW5tMSrh+j2zpHcBrO0u4JimpyhanDc1YprNEgdKMdFw0+hKqUPxpPBsc1DWB8w==; 5:dsIkWpcibNfZS2DlgEYImoSvZaJQWuQWlH15mT/WAMNb31zCS7BxbfOsFEQtWsFXUyoryiyYEoBn3lW1QbCUOzd+x6hKUmNPITZxibKp0dhRg1OXEGR/BxPJMHgjbkMrGNbOGL+uYpZ9LiemSvePAeAQ+a4bp3Ucr9EB30YsxDU=; 24:7ND9QbZ+ITnN35/9M6aX6bPGyHat3T5ZOIdBrVHIXshHi+6thO6ZlPb0WVTWvNc2KQxsn5LA+yib1NAaCu3vN6XyERXB4S6LDQukfjhi83s=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; MWHPR0501MB3866; 7:kwlGGzbhbqvYaSbIZcXEQgQN9LlXYoML/pfj/HzO7suUmCa/Wo/lmAtWi4pSyuP0s5rq15CAuvq1iuS6ygVa1ElpaGPbA7/hPoz7KlgSFjZCMon8LU6SSZacmz/ywyDiLyLdmDmBtM3T8DXVBDoCeI7QmPFfwBPumoYDU74cRliwOxdOfguBbroUXRnfke9qCOQgNVfO7Ocio5q2lJy2aWDJxbBnfacJydulu+Ev5GXT0ntCZgJsRPpO38RDRA29
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 10 Jul 2018 15:13:09.8476 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: c15a5579-02cf-450f-55c7-08d5e677a645
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR0501MB3866
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2018-07-10_06:, , signatures=0
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1011 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1806210000 definitions=main-1807100162
Archived-At: <https://mailarchive.ietf.org/arch/msg/idr/fjY2TNwmORZaSos8-sMSIVTe1OE>
Subject: Re: [Idr] Possible to set up priority for Tunnels established by draft-ietf-idr-tunnel-encaps-09 ?
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Jul 2018 15:13:33 -0000

On 7/9/2018 4:28 PM, Linda Dunbar wrote:
> We would like to use RR as controller to distribute more detailed 
> tunnel information, such as IPsec configuration & keys because in 
> managed large scale Overlay deployment (SD-WAN), it doesn’t scale to 
> allow all CPEs to negotiate IPsec keys. 

When first working on RFC 5566, I proposed a number of sub-TLVs that 
could be used to convey information about how to set up the IPsec 
Security Associations.  None of thes survived review by the security 
experts.  Setting up the Security Associations is the job of IKEv2. If 
you want to replace IKEv2 with BGP, you'll need a thorough security 
analysis of your proposed mechanism.

One might think it is okay to have BGP UPDATEs carry secret keys , as 
long as the UPDATEs only travel on sessions that are protected by 
IPsec.  I wouldn't necessarily assume that, as BGP UPDATEs have been 
known to leak (intentionally or unintentionally) beyond their intended 
scope.