Re: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)

"Jakob Heitz (jheitz)" <jheitz@cisco.com> Mon, 15 February 2021 19:32 UTC

Return-Path: <jheitz@cisco.com>
X-Original-To: idr@ietfa.amsl.com
Delivered-To: idr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 047DE3A1043 for <idr@ietfa.amsl.com>; Mon, 15 Feb 2021 11:32:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.696
X-Spam-Level:
X-Spam-Status: No, score=-7.696 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=i8zpJ3cs; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=PMPkqyH2
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id eXa1JU4S9VYI for <idr@ietfa.amsl.com>; Mon, 15 Feb 2021 11:32:34 -0800 (PST)
Received: from alln-iport-4.cisco.com (alln-iport-4.cisco.com [173.37.142.91]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DBAB43A1042 for <idr@ietf.org>; Mon, 15 Feb 2021 11:32:33 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=17334; q=dns/txt; s=iport; t=1613417553; x=1614627153; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=or3TMbCTNLu/P6i8EfXJXSqQ9SH5SZZtDGJchQwePOU=; b=i8zpJ3cs/ZUINqrrSP1YwW3DGiy2AnMp9JJnX7KnuirV8v8LB6HpLQWV Jj0aIf2rh+s5HVA7401V3pxPqrz5zpZnpz6vWO0c1hYHtI2O3aqlHgKcU 0pX7j7DQ+QdRAQwy+MW4AfQ23euE71ms83ZbjFtZQLq0FOL1t7i1zYKs7 4=;
X-IPAS-Result: A0DpAQAJyipgmIQNJK1iHAEBAQEBAQcBARIBAQQEAQGCD4EjMFF9WjYxhEGDSAOOCAOBBZMlhHOCUwNUCwEBAQ0BATICBAEBhE0CF4FyAiU4EwIDAQEBAwIDAQEBAQUBAQECAQYEFAEBAQEBAQEBhjYNhkQBAQEEHQYKEwEBJQQOAQ8CAQgRBAEBKAMCAgIwFAkIAgQBDQUIE4JVAYF+VwMuAaQpAooldoEygwQBAQaFGBiCEgmBOIJ2gm9QRgEBglGDdCYcgUFBgRFDgiI1PoEEgzw0gmA0giuDMlwmVmRIAQSQNg9EgnyHP4xKkUkKgnqRA4gTgxajLZQ5nSMEhFUCBAIEBQIOAQEGgWwhgVlwFYMkUBcCDY4fDAUJCRSDOopZczcCBgoBAQMJfIsXAQE
IronPort-PHdr: 9a23:gy3z0hByf12zsxCEMPjSUyQJPHJ1sqjoPgMT9pssgq5PdaLm5Zn5IUjD/qw00g3TVJ7J9vECjefK4OjsWm0FtJCGtn1KMJlBTAQMhshemQs8SNWEBkv2IL+PDWQ6Ec1OWUUj8yS9Nk5YS9z3fE/PoTu04CJBUhn6PBB+c+LyHIOahs+r1ue0rpvUZQgAhDe0bb5oahusqgCEvcgNiowkIaE0mRY=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.81,181,1610409600"; d="scan'208,217";a="646398301"
Received: from alln-core-10.cisco.com ([173.36.13.132]) by alln-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 15 Feb 2021 19:32:32 +0000
Received: from XCH-ALN-002.cisco.com (xch-aln-002.cisco.com [173.36.7.12]) by alln-core-10.cisco.com (8.15.2/8.15.2) with ESMTPS id 11FJWWOf024079 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Mon, 15 Feb 2021 19:32:32 GMT
Received: from xhs-rtp-002.cisco.com (64.101.210.229) by XCH-ALN-002.cisco.com (173.36.7.12) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 15 Feb 2021 13:32:32 -0600
Received: from xhs-rcd-002.cisco.com (173.37.227.247) by xhs-rtp-002.cisco.com (64.101.210.229) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 15 Feb 2021 14:32:31 -0500
Received: from NAM12-BN8-obe.outbound.protection.outlook.com (72.163.14.9) by xhs-rcd-002.cisco.com (173.37.227.247) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Mon, 15 Feb 2021 13:32:31 -0600
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=PcQQYmKndhMImXPRKrNzj1NtX/eH9vBeC66Nc+aRRRMSLKEjc8A1IJz2DQ/vMaDmcT0Uo/gOfu3bKd8NP7Nsi75zMUPvaBChAw/0ps9gRtkuAhkXVVWXAL9F18m8RBmKZjxzUdg88d8BesJuidIYLgoATrE7R5RcFjFKFsyEo50jSxpS+ADx90eyMbGW/kTTb6IFw6LmbaYuZ+5wNq/odFfD+Fjjf3Lwsf8u43uLYAFHnpAAJUd+PsHd2cjY6/KoqqyXhxLKx6R1KyFzu505DphWRxdVeUHdAXSvd0kcQmyf9Wrrv4vghwg3O7KhEHLeB14YnvjYhAcVTzqsXiWdRQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=or3TMbCTNLu/P6i8EfXJXSqQ9SH5SZZtDGJchQwePOU=; b=AKtTfNKAnIYywrm5Cnz+VZsziLnO+Ae89hNjPsT2TpKN0zvC8fbx5UpedrDIIdWpX+Y/P6SzDbCZDosR3zt6zlWndLXeay0GSfu+bPvqdUllSTEOxzbc0PFDmK/iBD2+sy2ytRiXcMJyzK54Go2ZOsDDZIMGX1oT5HWbRb31uVX610qs26ivjIjest71zrjPv05RmKqsxywGhPPt2MZjhRSJ1s+VcokUrlH5HcFlyu3b1h7HUSFiocd0NPDXGqJcQ6XHQMjqzx68fLOKIkPa4hWj+tg5gX+fQfFxeNGT01eLV0TrhIp3dDhK9OQmnyIiceyqV93eRPvALzR7zQEhmw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=or3TMbCTNLu/P6i8EfXJXSqQ9SH5SZZtDGJchQwePOU=; b=PMPkqyH2b0M97XUa2KT/y+NpJJZnTlkVKCbB7s1V7xX99Owh81uW0zQbtP7ZMo2/ecUKgdhrYQ93cAC5XDnfmKED0WxaZOYyR1cHcWW6MImlwbdXoF9DExnaMYtw7elm00aFActAQu/+eVjvKig4SPLnWak7yGhtElLksm7tq3c=
Received: from BYAPR11MB3207.namprd11.prod.outlook.com (2603:10b6:a03:7c::14) by BYAPR11MB2856.namprd11.prod.outlook.com (2603:10b6:a02:bd::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3846.27; Mon, 15 Feb 2021 19:32:29 +0000
Received: from BYAPR11MB3207.namprd11.prod.outlook.com ([fe80::c951:3ae4:1aca:9daf]) by BYAPR11MB3207.namprd11.prod.outlook.com ([fe80::c951:3ae4:1aca:9daf%3]) with mapi id 15.20.3846.035; Mon, 15 Feb 2021 19:32:29 +0000
From: "Jakob Heitz (jheitz)" <jheitz@cisco.com>
To: Robert Raszuk <robert@raszuk.net>, Aijun Wang <wangaijun@tsinghua.org.cn>
CC: "idr@ietf. org" <idr@ietf.org>, Susan Hares <shares@ndzh.com>
Thread-Topic: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)
Thread-Index: AdcBYQ0U9J8QqZaoR3eHcYVTqCdI3wAA+3qA//+0awCAAFXEAIAAjJiAgAL0D4D//rW4sA==
Date: Mon, 15 Feb 2021 19:32:29 +0000
Message-ID: <BYAPR11MB32073FCC82EB800AB4EAA25FC0889@BYAPR11MB3207.namprd11.prod.outlook.com>
References: <01bf01d7016a$135cd0d0$3a167270$@ndzh.com> <B1CE12E0-7A35-4BCF-AF79-AE87E3DC714D@tsinghua.org.cn> <CAOj+MMEYt1s5+4o0VdYwU9Uyx4e26ABCSuAO9z1F-TTANyS2Qg@mail.gmail.com>
In-Reply-To: <CAOj+MMEYt1s5+4o0VdYwU9Uyx4e26ABCSuAO9z1F-TTANyS2Qg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: raszuk.net; dkim=none (message not signed) header.d=none;raszuk.net; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [2601:647:5701:46e0:c908:e7e4:1534:523e]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 3cab04ba-7061-4e40-c3cb-08d8d1e86f16
x-ms-traffictypediagnostic: BYAPR11MB2856:
x-microsoft-antispam-prvs: <BYAPR11MB2856FDB55386B7850E20BDC1C0889@BYAPR11MB2856.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8882;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: ZjfFPS2cIsJ7T2MBgp71/UfcQ+4Tkkl7ckeZTePyexd68HD6D6qi8L9D2jQUnNrxyCP19KQaDT0SspEZeCsR+nWcT7uZnHw5PbzdC0m+JUduLiK7fzV16rIN2O0cAcCyo8Hy7LHnUu22MY/tugzHK20wWj6aE8RNll7MtwZaOvHxov0zQG3yGO2Vwqrd5L3aL9+93tCPvNdNJr+MyVosm22cy76cNkEqFiM4kU/hkSm95r9VJRtkNZDDlLWYFKZUBTINgs/JC3HcUPPznPEjuanXM0C9FGMILootwqX71bjddS3+Ldx4itTVDOLvmqWMSf28qMPpoxnOIppEuEPxbwS4sCclL22LXxn4AxBJsgya0+WQa7Sj9sC8z8ZIKUdH8TVhK0T36Z3ajH0dc/iq1kgm7sQyUXHuYbKRixU0ueZv3sh4wetZ1pirO/yhhxE1vvuhLqfXqjs03vUQHss4Nvkfkm2/PNBXSAF69IJjZC2U/v0G5eD72PHh83XQNIMJvvqfwccrwqWNYc6SYQJ9hA==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BYAPR11MB3207.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(366004)(39860400002)(346002)(136003)(376002)(396003)(8936002)(71200400001)(110136005)(2906002)(52536014)(8676002)(53546011)(7696005)(316002)(33656002)(86362001)(6506007)(186003)(66574015)(5660300002)(83380400001)(66556008)(66476007)(9686003)(66946007)(55016002)(54906003)(76116006)(66446008)(4326008)(478600001)(64756008); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: 9R7g0VR/Ncemc2SmCZrgi/rOJIIwsJboY7/8RSQSUjZvNJjx2SQkwoyAVqmCVmbVwfXk/cXkoP6o+/+k0Hes99Ud8haPcv0XVQ4DFMfdKSgq+SvM/wELz4BqgrHNzAxU8eGO9Kfndq84y9RQBTjO+ysUlKBu3r607ncAPdcfvDxiMXaN5gj+ljIv2ZMwnDrPqlATlDNPlYPtA6Se8jNeloZYfWaWMx4tQnps0JJkd+jKrltLyydnXepTa5/8hFm1exHBmfGfAznLRxdGQid6MErwpqMo8JhI4ZiYvpQlEQxPc6VC1Al1saSkQtRfxU1d//dHqRpDxf/JkdYUQXEXpi6Lu1Cl/HTM9+pjeiaA9NHXkMG1WOMtfdIpDhn+pTsKn7iSEtKEfffgcZS6+0EALKxlbvxjW22OyJgkNL1SpTXqCgiwlEJubr8DGfSNEWmcNJjqOeDks+C4u/INmHVbgE+TCLVT2ziMXOWNX9k/sUjDhoC8y5I43V2icxVSQEG7E3BQ9ocdv/xWxmDjQQatUjTnOSSUXXwRgjqFrd7STN8uakUUtkc+vPQUX1S6tTm+Dv+pIHKgLyv10MrWPgG/3Vkp2sfX6wSJvIq8G1hAm0NHhNV8xb5GqNYhCKxyxz6e/GvTmZ/Zpp3+519pj3iQfIdQnKryFzVhiZfKLG6bOJJo7yiB/6XQMHE5ZGM2rWD7s+uNCUb1YZVdUWv9UYe0U01HgvEKyCCf0Vmkc9dcUSz+yNWX8hkrfy3O+WV0jPr4p+RK1go17Ch8QlRDBS60xTQmnV6IK5XPV4DpoHxw6XQXUpuoXfMzX16W1/+98sUSJSwS3tWKG7NV6u9CvpqODAqnytzPK426Doe3Vd6z71SG6+7MneCMPVTZNmuIwZYpxiIq/BqClDhht2j0z9YDAx1t/K03Fh0Z7jTYykfIgHCFVUizHTkNOkDB95TZx6ASqRkZ+V9/NejsYuIlbB5JnGhMyBPzd+4Q8US/NGn5h/EeApLPwjA27vnYArMW+aygra4qQbi5/wIl2KkKiw+jWOxoyMjVM4DcqtjpqH/ZlerVpjHUCu6By/RdLStXe8kIUFfnatigcoXFFqTOwzew8gRZC5DA849poRdgNl/uv1hmS8n0iWDTd3+CCTJaSW+/QNnMk2obLvGxOVC1ixs7FiLuPoGQBw5grU5OuKnxMLL+TdA6we71UbU3EfsIXjYbruANPEj7YahGh07hJW1ko447H3sXj0EQi1SBS3U8Ccpwx+a8ugkY7WI/0gvvX9pJh8x6KPFDusYtjqlW3N1CptTwGFbCc1TJ+XmbvLj19MZjT8svSGtJ3vJDCQLvcwrq+lOW0rs3crB8ZEnK/0sDGpPm/TUmPXDDtTY6pNvDkwFCnbydF5+Mn/RtSGJguWhO
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_BYAPR11MB32073FCC82EB800AB4EAA25FC0889BYAPR11MB3207namp_"
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BYAPR11MB3207.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 3cab04ba-7061-4e40-c3cb-08d8d1e86f16
X-MS-Exchange-CrossTenant-originalarrivaltime: 15 Feb 2021 19:32:29.7926 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: zKu6NdASG6p7NzmrfdHI+Ku9jzYiMjCbfYO0sPUFT1zlvKGh03JxJT68WLiTz41bvixyHwIoYKDCZ8HhP+7mow==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR11MB2856
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.12, xch-aln-002.cisco.com
X-Outbound-Node: alln-core-10.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/idr/zgFDKO08qKU6SLB4looqwb1-ico>
Subject: Re: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)
X-BeenThere: idr@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Inter-Domain Routing <idr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idr>, <mailto:idr-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idr/>
List-Post: <mailto:idr@ietf.org>
List-Help: <mailto:idr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idr>, <mailto:idr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 15 Feb 2021 19:32:36 -0000

There's an important difference between rd-orf and RT constraint.
RT-constraint is a POSITIVE filter.
Rd-orf is a NEGATIVE filter.
RT-constraint says :give me X.
Rd-orf says: withhold X.

What's the difference?
Suppose you are an RR and getting the same rd-orf from all your clients.
Then you can propagate the rd-orf back to the source of the routes.
Consider what happens when a new client comes up,
The new client has not (yet) sent the rd-orf.
Therefore you have to retract the rd-orf from the route source to which you propagated it.
The next router on the way to the source may be an ASBR.
It also has to retract the rd-orf it propagated.
And so on.
Then the new client sends the rd-orf.
Now you have to propagate it again.
and so on.
That's a lot of churn.
This churn does not happen with RT-constraint.

Regards,
Jakob.

From: Idr <idr-bounces@ietf.org> On Behalf Of Robert Raszuk
Sent: Sunday, February 14, 2021 3:38 PM
To: Aijun Wang <wangaijun@tsinghua.org.cn>
Cc: idr@ietf. org <idr@ietf.org>; Susan Hares <shares@ndzh.com>
Subject: Re: [Idr] WG Adoption call for draft-wang-idr-rd-orf-05.txt (2/4/2021 to 2/18/2021)

Hello Aijun,

I have been re-thinking over a weekend this entire discussion.

I think I have a suggestion for you which addresses my concerns and I believe also addresses yours (and your co-authors) requirements.

As I said number of times I still suggest we do not send RD to filter. Instead we send tuple RD+RTs and only filter VPN routes on logical AND of all (all as there can be more then one RT importing given route therefore we need to include intersection of local import RTs and RTs carried with "offending" routes).

And to make this easily transitive I recommend we just define a new SAFI for it. We can call it RTC+ or Enhanced RTC as examples. Syntax would be identical to RTC, semantics opposite. Today RTC defines RTs which PEs need. Here we would signal description of subset of those which are "excessive" to be dropped on the peer.

Sending it with ORF say RDRT-ORD (while works p2p)  I do not buy this implicit regeneration hack say at RRs, RRs doing option C or ASBRs performing option B. So sending it in new SAFI IMHO would be much cleaner.

Just a thought how we could perhaps move forward here.

Kind regards,
Robert


On Sat, Feb 13, 2021 at 3:32 AM Aijun Wang <wangaijun@tsinghua.org.cn<mailto:wangaijun@tsinghua.org.cn>> wrote:
Hi, Susan:

Thanks for your suggestions. More responses from the operators are welcome!
We think this mechanism can let the network cope with dynamically the extraordinary scenarios for VPN routes advertisement, especially the inter-AS Option B/C scenarios.
This can certainly encourage the widespread deployment of inter-AS option B/C solution(especially for EVPN/VXLAN, EVPN/SRv6) increase the VPN services coverage and revenue of the operators.

There may be some details procedures and device behaviors need to be clarified further, but this is not unsolvable, considering there are so many experts within IDR WG.

Thanks Robert, Jakob, Jim and Acee for the technical challenges to let us/IDRer understand the solution more clearly.

Aijun Wang
China Telecom