Re: ISMS working group and charter problems

Eliot Lear <lear@cisco.com> Tue, 06 September 2005 19:11 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1ECirG-00006E-DQ; Tue, 06 Sep 2005 15:11:50 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1ECirE-00005m-35; Tue, 06 Sep 2005 15:11:48 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA14771; Tue, 6 Sep 2005 15:11:46 -0400 (EDT)
Received: from sj-iport-2-in.cisco.com ([171.71.176.71] helo=sj-iport-2.cisco.com) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1ECiuE-0005z0-PJ; Tue, 06 Sep 2005 15:14:56 -0400
Received: from sj-core-2.cisco.com ([171.71.177.254]) by sj-iport-2.cisco.com with ESMTP; 06 Sep 2005 12:11:37 -0700
Received: from imail.cisco.com (imail.cisco.com [128.107.200.91]) by sj-core-2.cisco.com (8.12.10/8.12.6) with ESMTP id j86JBSQM016265; Tue, 6 Sep 2005 12:11:29 -0700 (PDT)
Received: from [212.254.247.4] (ams-clip-vpn-dhcp4272.cisco.com [10.61.80.175]) by imail.cisco.com (8.12.11/8.12.10) with ESMTP id j86J6lPm030589; Tue, 6 Sep 2005 12:06:48 -0700
Message-ID: <431DE9E2.5060202@cisco.com>
Date: Tue, 06 Sep 2005 21:11:30 +0200
From: Eliot Lear <lear@cisco.com>
User-Agent: Mozilla Thunderbird 1.0.6 (Macintosh/20050716)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: Pekka Savola <pekkas@netcore.fi>
References: <431DD3BD.9090108@cisco.com> <431DD94C.8070907@dcrocker.net> <6.2.3.4.2.20050906141658.07a04e08@mail.amaranth.net> <431DE1C9.8000207@cisco.com> <Pine.LNX.4.61.0509062143070.19070@netcore.fi>
In-Reply-To: <Pine.LNX.4.61.0509062143070.19070@netcore.fi>
X-Enigmail-Version: 0.92.0.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
DKIM-Signature: a=rsa-sha1; q=dns; l=678; t=1126033609; x=1126465809; c=nowsp; s=nebraska; h=Subject:From:Date:Content-Type:Content-Transfer-Encoding; d=cisco.com; i=lear@cisco.com; z=Subject:Re=3A=20ISMS=20working=20group=20and=20charter=20problems| From:Eliot=20Lear=20<lear@cisco.com>| Date:Tue,=2006=20Sep=202005=2021=3A11=3A30=20+0200| Content-Type:text/plain=3B=20charset=3DISO-8859-1| Content-Transfer-Encoding:7bit; b=lbD27WBERQ7KKezmdCGKNBpjdMuVPfDUvES883T0D7Nl3273jRCjTlj1mwjDLbGYJQXG0bm2 vBla8c8SE3mE7RCOETX5jVVAngd295n/HyMjCmwc9sNNVbv/xc8TMHKDAwOGBW3BK8ymn1AEr12 IxgksOY3aMxoIfu4AfoY87QM=
Authentication-Results: imail.cisco.com; header.From=lear@cisco.com; dkim=pass ( message from cisco.com verified; );
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 7d33c50f3756db14428398e2bdedd581
Content-Transfer-Encoding: 7bit
Cc: IETF Discussion <ietf@ietf.org>, iesg@ietf.org
Subject: Re: ISMS working group and charter problems
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
Sender: ietf-bounces@ietf.org
Errors-To: ietf-bounces@ietf.org

Hi Pekka,

Pekka Savola wrote:
> Are you saying some of the following:
> 
>  1) ISMS specs should specify that the monitored hosts can/should
> certainly keep open a TCP session so the network management (in both
> ways) can happen over that session.  (This seems pretty trivial..)
> 
>  2) We should specify how network management hosts could reside behind a
> firewalls which block the management ports (I don't think this is needed
> or should be done).

Depending on what you mean by "network management hosts" it could be (1)
or (2) ;-)  I'm saying if there is a device that wishes to to be managed
through a firewall, allow it to open a connection on a specified port
(just so that firewalls can block it).  Remember, your laptop does this
today with HTTP on port 80 or HTTPS on port 443 (worse because you can't
even inspect).

Eliot

_______________________________________________
Ietf mailing list
Ietf@ietf.org
https://www1.ietf.org/mailman/listinfo/ietf