Re: [Int-area] I-D Action: draft-ietf-intarea-frag-fragile-06.txt

Ron Bonica <rbonica@juniper.net> Wed, 30 January 2019 20:37 UTC

Return-Path: <rbonica@juniper.net>
X-Original-To: int-area@ietfa.amsl.com
Delivered-To: int-area@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 511551312A5 for <int-area@ietfa.amsl.com>; Wed, 30 Jan 2019 12:37:01 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.253
X-Spam-Level:
X-Spam-Status: No, score=-5.253 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-4.553, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, KHOP_DYNAMIC=2, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id r7ELeYHHKh7A for <int-area@ietfa.amsl.com>; Wed, 30 Jan 2019 12:36:59 -0800 (PST)
Received: from mx0b-00273201.pphosted.com (mx0a-00273201.pphosted.com [208.84.65.16]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A25EB130FE6 for <int-area@ietf.org>; Wed, 30 Jan 2019 12:36:59 -0800 (PST)
Received: from pps.filterd (m0108157.ppops.net [127.0.0.1]) by mx0a-00273201.pphosted.com (8.16.0.27/8.16.0.27) with SMTP id x0UKWfiE029437; Wed, 30 Jan 2019 12:36:58 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=from : to : subject : date : message-id : content-type : content-transfer-encoding : mime-version; s=PPS1017; bh=u6dcxfHx3f5j8gEKaJCXBgt//fAGCr02+3nTSFtAiEU=; b=IrZipNi10kQDVkWxPEzObV58zcKksPcdG0FkypclgdTFNyJD/EaiRxEk+4yx1KpvDKFh gnkLcyhXU+KwbytTKie1ljdCB070ltuhJmeslnQjYXAsvLVJP54iSVAFrb+ueOBl8C4d /OwvKwkdNSJv7GZe8RfIvPV/N2uJ8Bn+hY61eyEnp0MGFtz69SVGexqij1BQTipFD75U MzVHMWbfp8VDF+BGg31LpWAghwYsVK26LXKB+FfphbT+0hhGkxUPIL/6b2wKrGqqzPmk DZ07hVG8927L/+6RCk05yKfyTrJLquWcR9DthIreFPU/voMvTO2Ty5z4f+WqYadV2hth Bw==
Received: from nam04-bn3-obe.outbound.protection.outlook.com (mail-bn3nam04lp2055.outbound.protection.outlook.com [104.47.46.55]) by mx0a-00273201.pphosted.com with ESMTP id 2qbeun8g48-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NOT); Wed, 30 Jan 2019 12:36:57 -0800
Received: from BYAPR05MB4245.namprd05.prod.outlook.com (20.176.252.26) by BYAPR05MB5366.namprd05.prod.outlook.com (20.177.127.219) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1580.13; Wed, 30 Jan 2019 20:36:54 +0000
Received: from BYAPR05MB4245.namprd05.prod.outlook.com ([fe80::985d:4eee:89c2:a114]) by BYAPR05MB4245.namprd05.prod.outlook.com ([fe80::985d:4eee:89c2:a114%2]) with mapi id 15.20.1580.017; Wed, 30 Jan 2019 20:36:54 +0000
From: Ron Bonica <rbonica@juniper.net>
To: "int-area@ietf.org" <int-area@ietf.org>, Brian E Carpenter <brian.e.carpenter@gmail.com>, Tom Herbert <tom@herbertland.com>
Thread-Topic: I-D Action: draft-ietf-intarea-frag-fragile-06.txt
Thread-Index: AdS424gb8WS+DFObTyu0v70GUwwDDQ==
Date: Wed, 30 Jan 2019 20:36:53 +0000
Message-ID: <BYAPR05MB42453B9932528F9BDF3CA53CAE900@BYAPR05MB4245.namprd05.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
dlp-product: dlpe-windows
dlp-version: 11.1.0.61
dlp-reaction: no-action
x-originating-ip: [66.129.241.11]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; BYAPR05MB5366; 6:Y28QD7XEtDPilEp6itwitBN2FB9RUw6F+0qkSfPbMT1HMiUkTHel4dNvuBXAU5Te+XzMXaOoWJGBQMLG1mUjzSp2sJX1ENMj5v081fI89tabngkJpsC8bSuI+TpHgMCUcaZqGnERsifQbUCxnmhk/xLmFW1YicRBPihcum06H4WEUyzeGRFDYFOvQzhSZNGKAUYjS43uHazp3NkZ4RoWq518/Qrxp82jnx2kG3a2T8ctqd4dlVTF4tgkyMfUSBZlnuPFm1J8GsJNIXHTYtHHk6MWHNkgHfPKkM+cQyqRstHpn7aaUmc/0FVtnHiPOKJDlh1j18GZKN2eqaa5K6JcZU10ydVKYwYR5xwlhNydDdOjrWNIhzpSBYWzy4+I+2Hs5ROLbgXzzzS71qkoWAZQRskFhvCtNFUP/x1I9wDISUUpSf9CxB3OgHWsQfMWOOp1YvAb4EiLEesUxVL/Bq5dyQ==; 5:ykacqePnDv0VmIObDVXk5Lzg2nrNKMne2nMeWKxdq5AmAJ6gloFZbEWCW4xpgOXhNrNs8af1p8gVIaRx3cQC52O1jkvxasHos5KqaeoABwN5dPCHq1Ds+5w8szSJW7HFxQs2yZEiYr9q+UxV0lEBxCgkLmfNMHBRsAuWMf9/oW9YaO77//oasGqfDVV08EoB2HHgs5JFUHH2q2/8Gj2aLA==; 7:oOQgkXTq1mn2uJfZaMB0TxL81XBKhJqYGdOHwRxnwDKv2ORTE2th5Q2GoVyRguz1DEmNYwUbxu3X00gVGQ0yJsKupNbJ6a8+pqt1XeROYI3NUN+KJ6R63VTElEVivWU2Dc3wbTcHiyvrK6dpRvpN4w==
x-ms-office365-filtering-correlation-id: f1e10150-b356-4278-9f28-08d686f2abc5
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600110)(711020)(4605077)(4618075)(2017052603328)(7153060)(7193020); SRVR:BYAPR05MB5366;
x-ms-traffictypediagnostic: BYAPR05MB5366:
x-microsoft-antispam-prvs: <BYAPR05MB5366D569161A4DD14A167EC4AE900@BYAPR05MB5366.namprd05.prod.outlook.com>
x-forefront-prvs: 0933E9FD8D
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(136003)(39860400002)(376002)(366004)(396003)(346002)(189003)(199004)(66066001)(476003)(53936002)(6436002)(486006)(74316002)(105586002)(81166006)(8936002)(55016002)(102836004)(229853002)(39060400002)(81156014)(86362001)(7696005)(25786009)(2906002)(6246003)(7736002)(478600001)(110136005)(2501003)(9686003)(305945005)(8676002)(316002)(14454004)(97736004)(71190400001)(106356001)(6506007)(53546011)(99286004)(33656002)(3846002)(68736007)(26005)(186003)(6116002)(256004)(71200400001); DIR:OUT; SFP:1102; SCL:1; SRVR:BYAPR05MB5366; H:BYAPR05MB4245.namprd05.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: juniper.net does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: K6bGiFuYLmDWamcA69qxLQp/g8numCXBdvfCkUXoylfd8RGooUjCxOQKx/haP8LnvMo41L/77JTwcVA3aB1gQVVJTAvXFDRbm9OQbz+wf5jz+NJX9z0PJbAoav5Bt/ygZxdOZr0tEyCY7bz3Md0MX8Mw0NIvnFf5Z2DB8uUS8Mj1k/PvUG10p4OnkwzvhORmzEOYia9nnY8ToutSCla+ryoxbprBK7WCsAd3JzSL3Xzg6MDl+Bk+tmT393ALPd+GLcfxavdBgJZiAPpj+vZYHuG4v6cFZti7ckPRb2r78OyHoeIKFFtQYYe0TI7mQS/4pFFY/H/xPxCBXFlJ8yM5gQIj8ckcWtzAJYX7YjvY0zUMZnXIaw/nTggIngn7CKdcs7qjJWc/9iVz941I2E1z4qz6jbrWEMQn2bAjwCbng0g=
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-Network-Message-Id: f1e10150-b356-4278-9f28-08d686f2abc5
X-MS-Exchange-CrossTenant-originalarrivaltime: 30 Jan 2019 20:36:53.9715 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR05MB5366
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2019-01-30_15:, , signatures=0
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 priorityscore=1501 malwarescore=0 suspectscore=0 phishscore=0 bulkscore=0 spamscore=0 clxscore=1015 lowpriorityscore=0 mlxscore=0 impostorscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1810050000 definitions=main-1901300153
Archived-At: <https://mailarchive.ietf.org/arch/msg/int-area/VKC7ebbELsrCJrU8eLEAGdRkQ98>
Subject: Re: [Int-area] I-D Action: draft-ietf-intarea-frag-fragile-06.txt
X-BeenThere: int-area@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF Internet Area Mailing List <int-area.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/int-area>, <mailto:int-area-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/int-area/>
List-Post: <mailto:int-area@ietf.org>
List-Help: <mailto:int-area-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/int-area>, <mailto:int-area-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 30 Jan 2019 20:37:01 -0000

Inline.......

> 
> Message: 2
> Date: Wed, 30 Jan 2019 08:40:39 +1300
> From: Brian E Carpenter <brian.e.carpenter@gmail.com>
> To: int-area@ietf.org
> Subject: Re: [Int-area] I-D Action:
> 	draft-ietf-intarea-frag-fragile-06.txt
> Message-ID: <7bc33271-8cee-818a-036b-99d92d81847c@gmail.com>
> Content-Type: text/plain; charset=utf-8
> 
> Reviewing this version, I noticed the absence of one mitigation that we should
> probably be recommending.
> 
> - in section 4.4. "Stateless Load Balancers" add the remark that balancers that
> use *only* the IPv6 Source Address, IPv6 Destination Address and IPv6 Flow
> Label (when it is non-zero) work perfectly on fragmented traffic.
> 

Fair enough. This is almost identical to a comment made by Tom Herbert. I have added a few sentences to the end of Section 4.4 that address both.

> - in section 7. "Recommendations" add a subsection "To Load Balancer
> Developers and Operators" saying that load balancers (including ECMP/LAG)
> SHOULD be designed and configured to use *only* the IPv6 Source Address,
> IPv6 Destination Address and IPv6 Flow Label (when it is non-zero).
> 

Also agree. Look for that section in Version 07

> Regards
>    Brian Carpenter
> 
> 
***************************************