Re: [Idr] Adoption and IPR call for draft-wang-idr-vpn-prefix-orf-03.txt (8/16 to 8/30)

Susan Hares <shares@ndzh.com> Mon, 29 August 2022 08:30 UTC

Return-Path: <shares@ndzh.com>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A5B8DC1524C6 for <idr@ietfa.amsl.com>; Mon, 29 Aug 2022 01:30:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.907
X-Spam-Level:
X-Spam-Status: No, score=-6.907 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hn0gKFevEQb3 for <idr@ietfa.amsl.com>; Mon, 29 Aug 2022 01:30:38 -0700 (PDT)
Received: from NAM12-DM6-obe.outbound.protection.outlook.com (mail-dm6nam12on2066.outbound.protection.outlook.com [40.107.243.66]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E08EEC1524CC for <idr@ietf.org>; Mon, 29 Aug 2022 01:29:54 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=AW4Bk6VcaVmbPbXPLRMG8JWmfIZUscUDIoWH4L9UPn5kP3LKWy+f/txMO5qpbXeOW11QpkKR2kUTbQtxAo+KvN2FtiX+g9be12MzDaYmUQ2+wuNNIenCplaJQ9WaIebcaFUpxoub+4vw/qXZe0QvYZ5LSiJjEfodejq/riT/rLKM/npvx6N0okuv3a9ikE59269B0P9E3iBY84WRANtJKkQLTXOGS9e2kisOQBhMCTArUvIXqAGDZth5oJgpnriUzwnTvg2ZM25CFlcKOQo/jwSS0Ew2oZCaASkV6xKViAxeESPB0W3tTaPvkBR4TLkhh4g7QLtC9CEKaL5PWeHANg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=borDRmDxCooSThXT0z6lUbRQAi9cHBpavDIweCssUBQ=; b=USRljsimmpkfPjZLz3b8yqprbgYIflzvkLUHwTl/EjXMscDWtK0asN9UYzs1BcA+jyXiwMEDYzorED1/CrmNHOkT2iHH3Abk72rNBQsr1QYx/GLa9ScWzW0gUs91atVoEIySrT3j0UYYg8cQ0ZSqjxa+/Cx0OepJxom4FdI1kM71w+V2bDAHoX8vA4fznPma2Gi+vVvZ7kLbeb0EXLsGW0Ty8nQe2B+MXzwXXFphFY/lhpsBJp02kvuRPZrJseN3EQuzYNtS0Aqinbp5fAecv/Sm1BwX9Tk8st1GPE+xvSVlA8XHT80bsQwgmpkhflBrjc2YmjzU/Z4CyLar6rSzSQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 104.47.57.47) smtp.rcpttodomain=cisco.com smtp.mailfrom=ndzh.com; dmarc=bestguesspass action=none header.from=ndzh.com; dkim=none (message not signed); arc=none (0)
Received: from DS7PR05CA0037.namprd05.prod.outlook.com (2603:10b6:8:2f::24) by MN2PR08MB5854.namprd08.prod.outlook.com (2603:10b6:208:11b::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5566.19; Mon, 29 Aug 2022 08:29:52 +0000
Received: from DM6NAM12FT031.eop-nam12.prod.protection.outlook.com (2603:10b6:8:2f:cafe::91) by DS7PR05CA0037.outlook.office365.com (2603:10b6:8:2f::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5588.3 via Frontend Transport; Mon, 29 Aug 2022 08:29:52 +0000
X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 104.47.57.47) smtp.mailfrom=ndzh.com; dkim=none (message not signed) header.d=none;dmarc=bestguesspass action=none header.from=ndzh.com;
Received-SPF: Pass (protection.outlook.com: domain of ndzh.com designates 104.47.57.47 as permitted sender) receiver=protection.outlook.com; client-ip=104.47.57.47; helo=NAM02-SN1-obe.outbound.protection.outlook.com; pr=C
Received: from obx-outbound.inkyphishfence.com (50.17.62.222) by DM6NAM12FT031.mail.protection.outlook.com (10.13.179.19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5588.3 via Frontend Transport; Mon, 29 Aug 2022 08:29:52 +0000
Received: from NAM02-SN1-obe.outbound.protection.outlook.com (mail-sn1anam02lp2047.outbound.protection.outlook.com [104.47.57.47]) by obx-inbound.inkyphishfence.com (Postfix) with ESMTPS id 42601FEA9A; Mon, 29 Aug 2022 08:29:51 +0000 (UTC)
Received: from BYAPR08MB4872.namprd08.prod.outlook.com (2603:10b6:a03:70::17) by BN6PR08MB2721.namprd08.prod.outlook.com (2603:10b6:404:ba::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5566.15; Mon, 29 Aug 2022 08:29:48 +0000
Received: from BYAPR08MB4872.namprd08.prod.outlook.com ([fe80::947b:e334:a655:d8]) by BYAPR08MB4872.namprd08.prod.outlook.com ([fe80::947b:e334:a655:d8%4]) with mapi id 15.20.5566.021; Mon, 29 Aug 2022 08:29:48 +0000
From: Susan Hares <shares@ndzh.com>
To: Robert Raszuk <robert@raszuk.net>, Aijun Wang <wangaijun@tsinghua.org.cn>
CC: "Acee Lindem (acee)" <acee@cisco.com>, "idr@ietf. org" <idr@ietf.org>
Thread-Topic: [Idr] Adoption and IPR call for draft-wang-idr-vpn-prefix-orf-03.txt (8/16 to 8/30)
Thread-Index: AQHYuPNbd/KJKvnuvEK7E3UTUr+5Hq3BBXOAgAAOCwCAAAgrAIAARiEAgABTcYCAAAhVgIAABhQAgAAGTgCAA8ZuUA==
Date: Mon, 29 Aug 2022 08:29:47 +0000
Message-ID: <BYAPR08MB4872E197715724FC1E853725B3769@BYAPR08MB4872.namprd08.prod.outlook.com>
References: <CAOj+MMELVifgg4Yj38kyncDGYzS5fJG-43_kRc7YLwJiTPANUA@mail.gmail.com> <23D1B383-F794-402E-AB1B-D966F8F3375B@tsinghua.org.cn> <CAOj+MMGs9gU=xC0UG4Xaiv5feo2U6VFXkdAxmk6arN_bxe_mSg@mail.gmail.com>
In-Reply-To: <CAOj+MMGs9gU=xC0UG4Xaiv5feo2U6VFXkdAxmk6arN_bxe_mSg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
X-MS-Office365-Filtering-Correlation-Id: c3cd6ff9-6808-4b41-51db-08da8998a4f3
x-ms-traffictypediagnostic: BN6PR08MB2721:EE_|DM6NAM12FT031:EE_|MN2PR08MB5854:EE_
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam-Untrusted: BCL:0;
X-Microsoft-Antispam-Message-Info-Original: qTkA1FQgUQvYaizDR2399RUDdWmk+ma4KQ2Wq3azK317+SllsoJf8XrMpaILsyNRp+NQA4jpqgRAQoPKBclVSL+yaWXTKUOPx0XH5q4uZZZhqpuBw8UwjxMq7W2Vcbq8VvsantDP6icNwiGcsKtW+0jB/ZzDdDtFEPJc7uDd+EtqS9Qwcu7kZxzQDWy9AwmCP2Xp/G115/vhxgDYy0nRW59GnWk1SjUW9/9Z0QlYncRu0LMz8LLSZT8clfvOnsGonMkEF52u7NpgXjHr+1Lo8Bh/D0pIOShUuYsC6DBo6fi9xvDvrSp3k/3PCpAS0JNvweBt3urZPkeZTZWJLt1Inr4Vpc2cRh0vAn5c5oT/CcD+sxc+0e3LffrWxpqezP4EHnM993ASoMJMZWbh/shVzDT1xJuXUHfDPLnux8onER+KxS4KpTWV02Z88oJ4J58ioaDgcethwj1xNGSY3CmSXoZXx17UN16n9+QYaGRO/B1863cYb9A8cE8uxtmg/M8IO6blxd9o8BuOfjzikFq+GMad1YJAjX/moXMxTqvp5pY5ZBVFhp54UmBFU2yDqNWA3nu7YwR6V4R97sTjQvJBZG1bEQ6SxHPQ9huJMVBwNpyNv/+vpfvbEqDoXRsX2FVacSpavUYKnh26u4l4KM2MH3me/Z9nrGUl7cwfRlaQBACiz5OQndP4cYf/jyj/nOj1JrCZ3WlhaoqbwFqNz6j42urt9RmBBvfgwLpsht48jVzaqqMmLfBdUoG7BImvTT4W0L8jV8G3bftgQlHOZGHQp519LYLQ9BX7PdnfXFyhszMSfW/qKbj1291WfFw5nNB8CuacD+Q1EmKZ0DopG2eq2w==
X-Forefront-Antispam-Report-Untrusted: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BYAPR08MB4872.namprd08.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(366004)(396003)(376002)(346002)(39830400003)(136003)(166002)(55016003)(122000001)(38070700005)(86362001)(54906003)(110136005)(64756008)(66946007)(8676002)(76116006)(4326008)(66446008)(66476007)(66556008)(41300700001)(8936002)(478600001)(5660300002)(38100700002)(52536014)(316002)(71200400001)(186003)(33656002)(26005)(7696005)(6506007)(83380400001)(2906002)(53546011)(9686003); DIR:OUT; SFP:1101;
Content-Type: multipart/alternative; boundary="_000_BYAPR08MB4872E197715724FC1E853725B3769BYAPR08MB4872namp_"
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN6PR08MB2721
X-Inky-Outbound-Processed: True
X-EOPAttributedMessage: 0
X-MS-Exchange-SkipListedInternetSender: ip=[104.47.57.47]; domain=NAM02-SN1-obe.outbound.protection.outlook.com
X-MS-Exchange-ExternalOriginalInternetSender: ip=[104.47.57.47]; domain=NAM02-SN1-obe.outbound.protection.outlook.com
X-MS-Exchange-Transport-CrossTenantHeadersStripped: DM6NAM12FT031.eop-nam12.prod.protection.outlook.com
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id-Prvs: fe94a914-966c-4e7d-66b8-08da8998a272
X-IPW-GroupMember: False
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: X3Uwgq2lCRk9DpoqiYe2T+FlPhqLjRqqOvKgkZVtJQLaCDmShvO4jzNHYS2uAPJkhb5FyYEgVATIYfHnsmnG+g2mEmTC0GVxfdefhz7tSJVRqOPEtFLvPklf8iaCDJY/z+3eb4NbP1L6qhN8O+4M6mEki5LNbtSDLAbLqFBJIL/Q4VafEkgE/jlt0NxI1t/4eIb65RM1/rISsz00aAwoU2mwQ0e0QALIrchabfM77fEnwTIWs8NNqcYu5NDSkG9CD2hEbZQFxOsvAon7jPoYfdLdMeVMoBpt+V1/ulpf7W3VrutMY7rGwpJMpG1MvZ+dxGkYbw4R/ZZcVJAzgRXEkk4LaBOTz7/k6BJQBMTa5OgIvzeicIV+IcvDe/jQ1T9JWIvZAd2TB98tUGVd2kZu7+66f1K3zhuyif1wCsuJKcjlxA13Ht0/zm+uxnW1/oF61HMzT4NfH1N3CBbBtsGNu6hpxs46SKBBaRo+USCvPdEbmby/DxQzouV250ZABZNrKa0b8bkWKdyUlX0QRvFRPJ7SagIOiouwtpuruuIdT/3KEAxvLYWLYNWt2bciGDYxktcYvI3gUgvy7sNmfeOXdTJvCkgYGCtT+eLl+1rW4aBf8eLhvtd5ivbME6n8jDJ9HIB/3jDFVvz9afN9aZ1fIcfp16r5CcOEIwnGh+qYx/irSG0wdhPPDkPH/LPQUWsx7Y/cbSnJq9/we3gUTvFxuVY56VSF3jhcpath/eG9anvyyqPzldcQrPJXxyY350kjn/Lmlt0UTg0Fe9WnKccBLdfa4UBNm3Q0sg7fphFBN1RkbT3+M9iE/BxJW9NKzzNUbmtge8/PbUwJoDTJZTrrdw2zKTyOeXIcDbTIJBo+YzX3PIwRGEOrElS1nBc7qDxF7wYxTkNs84/Lz/oH3Kx3mqUHUXTzRi3JEh6kH2hJ7rpkmmo+kMlcq7lxGB73mR29
X-Forefront-Antispam-Report: CIP:50.17.62.222; CTRY:US; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:NAM02-SN1-obe.outbound.protection.outlook.com; PTR:mail-sn1anam02lp2047.outbound.protection.outlook.com; CAT:NONE; SFS:(13230016)(39830400003)(346002)(396003)(376002)(136003)(36840700001)(46966006)(6506007)(9686003)(33964004)(7696005)(53546011)(86362001)(26005)(33656002)(83380400001)(336012)(186003)(156005)(41300700001)(47076005)(478600001)(52536014)(55016003)(70586007)(82310400005)(40480700001)(316002)(32850700003)(54906003)(110136005)(70206006)(8676002)(7636003)(4326008)(5660300002)(36860700001)(8936002)(2906002); DIR:OUT; SFP:1101;
X-OriginatorOrg: ndzh.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 29 Aug 2022 08:29:52.0696 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: c3cd6ff9-6808-4b41-51db-08da8998a4f3
X-MS-Exchange-CrossTenant-Id: d6c573f1-34ce-4e5a-8411-94cc752db3e5
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=d6c573f1-34ce-4e5a-8411-94cc752db3e5; Ip=[50.17.62.222]; Helo=[obx-outbound.inkyphishfence.com]
X-MS-Exchange-CrossTenant-AuthSource: DM6NAM12FT031.eop-nam12.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR08MB5854
Archived-At: <https://mailarchive.ietf.org/arch/msg/idr/veCUqbzV_is5SteRSB9PJfFRAmg>
Subject: Re: [Idr] Adoption and IPR call for draft-wang-idr-vpn-prefix-orf-03.txt (8/16 to 8/30)
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Aug 2022 08:30:42 -0000

Robert:

You might consider that Aijun and others do not have the ability to quickly take the rogue PE out of the network.

Asking Aijun why they do not take the Rogue PE out of the network – may be useful.

Sue

From: Robert Raszuk <robert@raszuk.net>
Sent: Friday, August 26, 2022 6:48 PM
To: Aijun Wang <wangaijun@tsinghua.org.cn>
Cc: Acee Lindem (acee) <acee@cisco.com>; idr@ietf. org <idr@ietf.org>; Susan Hares <shares@ndzh.com>
Subject: Re: [Idr] Adoption and IPR call for draft-wang-idr-vpn-prefix-orf-03.txt (8/16 to 8/30)

I admit there will be no single solution for one problem. The role of IETF is to standardize a single solution to real problems. At least we should aim for that. Your problem description is this: &quo
External (robert@raszuk.net<mailto:robert@raszuk.net>)
  Report This Email<https://protection.inkyphishfence.com/report?id=bmV0b3JnMTA1ODY5MTIvc2hhcmVzQG5kemguY29tLzJhMmRlYjExYTcwZjdmNjk5YWIzYzkxMTYzOGUxODRmLzE2NjE1NTQxMTAuNjU=#key=08ce0f4fadae26c9cd9a43ad278cf804>  FAQ<https://www.inky.com/banner-faq>  GoDaddy Advanced Email Security, Powered by INKY<https://www.inky.com/protection-by-inky>


I admit there will be no single solution for one problem.

The role of IETF is to standardize a single solution to real problems. At least we should aim for that.

Your problem description is this:  "rogue PE"

Well to me this is not sufficiently precise to convince anyone that there is a problem to start with. At least I am happy to see that you are no longer stating that the problem you are trying to protect from is "rogue CE" (as clearly PE-CE prefix limit will effectively mitigate it at its source).

Bottom line is this - if we assume that any PE can arbitrarily misbehave and inject bogus stuff in the routing control plane then we have a much larger problem. And IMO the right solution to such a problem would be to take such "rogue PE" out of the network ASAP. Not to cherry pick who's VPN to cut first, second, third on RRs in the path.

Rgs,
R.