Re: Generic anycast addresses...
Mark Smith <markzzzsmith@gmail.com> Fri, 31 May 2019 22:28 UTC
Return-Path: <markzzzsmith@gmail.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 53567120122 for <ipv6@ietfa.amsl.com>; Fri, 31 May 2019 15:28:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.499
X-Spam-Level:
X-Spam-Status: No, score=-0.499 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, FROM_LOCAL_NOVOWEL=0.5, HK_RANDOM_ENVFROM=0.001, HK_RANDOM_FROM=0.999, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id I-BjSOvxFbt2 for <ipv6@ietfa.amsl.com>; Fri, 31 May 2019 15:27:59 -0700 (PDT)
Received: from mail-ot1-x32e.google.com (mail-ot1-x32e.google.com [IPv6:2607:f8b0:4864:20::32e]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 64ED91200EF for <6man@ietf.org>; Fri, 31 May 2019 15:27:59 -0700 (PDT)
Received: by mail-ot1-x32e.google.com with SMTP id t24so10721413otl.12 for <6man@ietf.org>; Fri, 31 May 2019 15:27:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=QCae4HhgUdG2Ueq3sV6iCnN9z0imyRcyvThT3WrGwGc=; b=rdMiBu/de83nC97zRgREmQeV1TIZLWPS7g6KkKMlcz0ynntzoAE3emCVCnW3ilWbRM XfjuZtA3F5Fbzkv7Oc/+ruLO3MNmDhLV1bv4yeJUS2Kv5gDzPxIJ7JPrEAK3As9eEGi9 lkazHf1cVKupJko1itStcSWMkZokatrCwfcG4snEM0qWD7kR19vGyA7do9dqNkncCknJ 1AIF/1ZuMDPkJlMFF9gU4IXpfzA2lXPxkVLuuyrImrjS1McdgjW516EgjPLuGgTNTT/N L86pqo7BhaBeEbooY2z2hRVzlgB5VH7jRYrNz93eRHR9JW1yf25m1+9eTVoagn65PVlj NlLA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=QCae4HhgUdG2Ueq3sV6iCnN9z0imyRcyvThT3WrGwGc=; b=ocAhdvM9sp+0+EwAKIvZ7Ue2mJVChcRcyojGh9GTEzXVg3k3jknD+TsxTLWmX+og9V /zjZqOalaFwu8LxKm+T6cCpQtVdkrEW3ryphYprPQuBXdTEhH2PWg7ZGDi+dChYVFeQ2 xT+/tKv7Zq61KTzS1l1e+FGiXQ1LbUbLQLGgJYUvoG2LTciWCfj1xZobo7twyA5yVL90 GAP8GaH++mUJAkm2UendWoZpBpHfruvs1LQ7bUrbIosuDUoyXW8cX+cMIKmTPMLv+Afe zQ1WV4qQCdsERCCwoO3ZZgRiQwA/t1+vhN/44E3FV/K50spx2oXFGMaUMplhlzlNTKSN i9Fg==
X-Gm-Message-State: APjAAAWULsbMzQctljFIvKurCjbeMT2WGDE7chWnbdHszslMV/uXMc6f evXilMvHkluUiHsKJrnFoqFau5kiPfSfiLSnY+g=
X-Google-Smtp-Source: APXvYqy4U+ZKxiGoiiiQcPW8E+OcYBpO+PRwqkAmDFluLRKg61u//K77PxE1jEP7B4HSr7fl5pYqNk2WAPuNBotG2aM=
X-Received: by 2002:a05:6830:1150:: with SMTP id x16mr2462860otq.74.1559341678685; Fri, 31 May 2019 15:27:58 -0700 (PDT)
MIME-Version: 1.0
References: <7A9560FC-0393-45DF-8389-B868455AC6DD@fugue.com> <20190530005734.7d2alod2zoaemmhc@faui48f.informatik.uni-erlangen.de> <D6E27B45-437F-45BE-A305-47DD460BCE02@fugue.com> <26144.1559226966@localhost> <1DD451A7-D898-4105-974C-53776A3DA9F2@fugue.com> <20190530152902.l2nmyhadr4e4kt7x@faui48f.informatik.uni-erlangen.de> <0FF19D6D-1A45-41EF-BE34-CC35B5E51E1E@steffann.nl> <D91629F6-73AC-4A80-80EF-16644F73DA36@fugue.com> <701687d4-842c-6a16-3c97-349125324e3f@gmail.com> <D648647D-60E1-4DCE-B0BE-11002E0AE5A4@fugue.com> <20190530220838.g2hshonsjxmfnd55@faui48f.informatik.uni-erlangen.de> <632BE7EC-26A6-44E9-9CCD-F0AE143D4256@fugue.com> <AF1967FC-526D-47FB-98BE-F9B949F26796@steffann.nl> <CAO42Z2yY=z-wKCUaCYZqJLHfT+LdyDOWz9bLG8QTh9C8sJCx3g@mail.gmail.com> <aa405734-b2dd-c21f-7377-2faaa24165e6@bogus.com>
In-Reply-To: <aa405734-b2dd-c21f-7377-2faaa24165e6@bogus.com>
From: Mark Smith <markzzzsmith@gmail.com>
Date: Sat, 01 Jun 2019 08:27:31 +1000
Message-ID: <CAO42Z2yHJJ5TsuhP2C2i+XpUcMG=3dBNo6u9SSOw-KRpzywVkA@mail.gmail.com>
Subject: Re: Generic anycast addresses...
To: joel jaeggli <joelja@bogus.com>
Cc: Sander Steffann <sander@steffann.nl>, Michael Richardson <mcr+ietf@sandelman.ca>, "6man@ietf.org" <6man@ietf.org>, Dave Thaler <dthaler@microsoft.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/1xnLmIh_DBzZnTs-K0Ll1M6hjpM>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 31 May 2019 22:28:01 -0000
On Sat, 1 Jun 2019 at 02:35, joel jaeggli <joelja@bogus.com> wrote: > > On 5/30/19 16:21, Mark Smith wrote: > > > > > > On Fri., 31 May 2019, 08:54 Sander Steffann, <sander@steffann.nl > > <mailto:sander@steffann.nl>> wrote: > > > > Hi Ted, > > > > >> To me, a non-fuzzy boundary is one where you do something like ACL on > > >> a set of links completely isolating some area of the network. Fuzzy > > >> could vbe absence of default route causing ULA to stop. Not sure if > > >> these are good examples of any actual definition, but both ae > > possible with > > >> ULA. > > >> > > >> I'd mostly be concerned about non-fuzzy boundaries wrt. security, > > >> so not sure if i'd always want to avoid non-fuzzy boundaries. > > > > > > The question is, what’s different about the proposed application > > versus typical ULA usage? > > > > I like the scope aspect of Mark's draft. ULA is always organisation > > or site scoped, and should be filtered as such. Anycast that have a > > different scope should have different boundaries. Anycast addresses > > that have ISP scope can cross from the customer's network to the > > ISP's network, while there should be a boundary between that > > customer's ULA addresses and that ISP's ULA addresses (let's assume > > they both use ULA for this example). > > > > > > An example use case for a Network Service Provider scope is anycast DNS > > resolvers. > > > > You can't use ULA because customers don't send their ULA prefixes to > > you, and you don't really want them to, as that makes your ISP network > > part of their network. > > > > Ideally you don't want to use GUA DNS resolver anycast addresses because > > that makes the DNS resolver vulnerable to DoS attacks from the Internet. > > It is straight forward enough to use a gua prefix which you do not > announce to the internet as a whole. we do this with internal > anycast(s), address space used for point-to-point links management > networks and so forth. > Sounds like it isn't a requirement to advertise RIR space globally anymore so that RIRs can check if you're using it. However, this is just one example of how a scoped formal anycast address space could be used. There are others I'm working on in the draft. > > > When I first ran up anycast DNS resolvers, I ideally wanted to use IPv4 > > addresses that had these property of globally unique, not globally > > reachable, yet reachable from all customers' networks. Internet DoS > > attacks on DNS resolvers were common at the time. > > > > RFC1918 didn't suit, nor did normal RIR public address space, because > > APNIC expected it to be globally reachable. IX space suites, but we > > weren't an IX. We could have probably lobbied harder for it, however we > > needed to get them going.. > > > > > > This is also part of my realisation that the forwarding scopes of our > > unicast address spaces are quite coarse - global (GUA), organisation > > (ULA) and link (Link-Local), and that's it. > > We have really bad historical experiences with attempts to define scopes. > Can you elaborate? Multicast scopes don't seem to have caused any issues, and I think it is because they're much more fine grained than the total of 3 coarse unicast ones. Multicast scopes better fit the domains people want. > > The much more fine grained multicast scopes used with anycast addresses > > would be much more flexible for anycast scenarios. > > > > I think reintroducing the Site-Locals as a unicast address space, just > > to create Site-Local scope anycast addresses, isn't really properly > > solving the problem in a general enough way. > > > > People will also use them for unicast addressing because they're more > > similar to RFC1918s that ULAs - and we also have problems with people > > not making ULA unique, despite the word Unique in the name. > > > > > > No mention of generating unique ULAs, so people are being trained to use > > ULAs that are not unique: > > > > https://github.com/leblancd/kube-v6/blob/master/README.md#set-up-node-ip-addresses > > > > A CPE vendor got this wrong too in the past: > > > > Residential IPv6 CPE - What Not To Do and Other Observations > > https://www.ausnog.net/sites/default/files/ausnog-05/presentations/ausnog-05-d02p02-mark-smith.pdf > > > > > > Regards, > > Mark. > > > > > > Cheers, > > Sander > > > > -------------------------------------------------------------------- > > IETF IPv6 working group mailing list > > ipv6@ietf.org <mailto:ipv6@ietf.org> > > Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6 > > -------------------------------------------------------------------- > > > > > > -------------------------------------------------------------------- > > IETF IPv6 working group mailing list > > ipv6@ietf.org > > Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6 > > -------------------------------------------------------------------- > > > >
- Generic anycast addresses... Ted Lemon
- RE: Generic anycast addresses... Dave Thaler
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... George Michaelson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Bob Hinden
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... George Michaelson
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... George Michaelson
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... JORDI PALET MARTINEZ
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Sander Steffann
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Sander Steffann
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Fred Baker
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... STARK, BARBARA H
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Brian E Carpenter
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Sander Steffann
- Re: Generic anycast addresses... George Michaelson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Brian E Carpenter
- Re: Generic anycast addresses... Brian E Carpenter
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Fred Baker
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mikael Abrahamsson
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Mikael Abrahamsson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... joel jaeggli
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Fred Baker
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Nick Hilliard
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Joel Jaeggli
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Ole Troan
- Re: Generic anycast addresses... Brian E Carpenter
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Sander Steffann
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Nick Hilliard
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... joel jaeggli
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mikael Abrahamsson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Mikael Abrahamsson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Christian Huitema
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Brian E Carpenter
- Re: Generic anycast addresses... Mikael Abrahamsson
- Re: Generic anycast addresses... Sander Steffann
- Re: Generic anycast addresses... Christian Huitema
- Anycast to unicast resolution (was: Re: Generic a… Toerless Eckert
- Re: Anycast to unicast resolution (was: Re: Gener… Christian Huitema
- Re: Anycast to unicast resolution (was: Re: Gener… Brian Haberman
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Alexandre Petrescu
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Bob Hinden
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Bob Hinden
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Erik Kline
- Re: Generic anycast addresses... Mark Smith