Re: ISMS working group and charter problems

"Steven M. Bellovin" <smb@cs.columbia.edu> Tue, 06 September 2005 22:28 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1EClvp-0005tA-IS; Tue, 06 Sep 2005 18:28:45 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1EClvY-0005q2-9H for ietf@megatron.ietf.org; Tue, 06 Sep 2005 18:28:43 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA05862 for <ietf@ietf.org>; Tue, 6 Sep 2005 18:28:25 -0400 (EDT)
Received: from machshav.com ([147.28.0.16]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1EClya-0005dN-Lx for ietf@ietf.org; Tue, 06 Sep 2005 18:31:38 -0400
Received: by machshav.com (Postfix, from userid 512) id 8A0D8FB262; Tue, 6 Sep 2005 18:28:17 -0400 (EDT)
Received: from berkshire.machshav.com (localhost [127.0.0.1]) by machshav.com (Postfix) with ESMTP id 7CD8AFB240; Tue, 6 Sep 2005 18:28:16 -0400 (EDT)
Received: from cs.columbia.edu (localhost [127.0.0.1]) by berkshire.machshav.com (Postfix) with ESMTP id 4B7CC3BFD6F; Tue, 6 Sep 2005 18:28:15 -0400 (EDT)
X-Mailer: exmh version 2.6.3 04/04/2003 with nmh-1.0.4
X-Exmh-Isig-CompType: repl
X-Exmh-Isig-Folder: listbox
From: "Steven M. Bellovin" <smb@cs.columbia.edu>
To: Daniel Senie <dts@senie.com>
In-Reply-To: Your message of "Tue, 06 Sep 2005 18:16:19 EDT." <6.2.3.4.2.20050906181309.07350830@mail.amaranth.net>
Mime-Version: 1.0
Content-Type: text/plain
Date: Tue, 06 Sep 2005 18:28:15 -0400
Message-Id: <20050906222815.4B7CC3BFD6F@berkshire.machshav.com>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: bb8f917bb6b8da28fc948aeffb74aa17
Cc: ietf@ietf.org
Subject: Re: ISMS working group and charter problems
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
Sender: ietf-bounces@ietf.org
Errors-To: ietf-bounces@ietf.org

In message <6.2.3.4.2.20050906181309.07350830@mail.amaranth.net>, Daniel Senie 
writes:
>At 06:00 PM 9/6/2005, you wrote:
>> >> The IETF has been doing extensive work on NAT traversal, have a look
>> >> and see if you can reuse some existing mechanism.
>>
>> > All mechanisms used with the possible exception of an additional SNMP
>> > table will be re-used from existing IETF work (mostly SSH with help
>> > from the fact that it's based on TCP).
>>
>>Perhaps then it's time we consider mandating a "NAT-Traversal" section to
>>standards track documents much like IANA and Security considerations have
>>become common place to this day. Anything that's not covered by the BEHAVE
>>work already done should be covered there, as the IETF seems to have indeed
>>accepted the proliferation and widespread acceptance of NAT functionality.
>
>Actually, a "Firewall Considerations" section would make sense. That 
>section might indeed be a good place to discuss NAT issues, if any, 
>but firewall interactions with protocols exist in many cases where 
>NAT is in use. Though many have expressed their hope that NAT does 
>not persist in the IPv6 world, there should be no doubt in anyone's 
>mind that firewalls will be with us permanently. 
>

Indeed.  In Hal Burch's dissertation, he concluded that 

	at least 93% of hosts attached to the Internet are behind
	a ltering device of some type. Because this excludes hosts
	behind rewalls that block all incoming connection attempts,
	the true percentage is even higher than 93%. Clearly,
	rewalls are an important consideration when designing
	protocols and developing models for the Internet.

More of his measurements concluded that at least 56% of hosts are
behind a firewall that blocks by default.

_______________________________________________
Ietf mailing list
Ietf@ietf.org
https://www1.ietf.org/mailman/listinfo/ietf