Re: Generic anycast addresses...
joel jaeggli <joelja@bogus.com> Fri, 31 May 2019 16:35 UTC
Return-Path: <joelja@bogus.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9E38B1202DD for <ipv6@ietfa.amsl.com>; Fri, 31 May 2019 09:35:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.898
X-Spam-Level:
X-Spam-Status: No, score=-6.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Sp6r1RIfrwFF for <ipv6@ietfa.amsl.com>; Fri, 31 May 2019 09:35:14 -0700 (PDT)
Received: from nagasaki.bogus.com (nagasaki.bogus.com [IPv6:2001:418:1::81]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8DBF31202C3 for <6man@ietf.org>; Fri, 31 May 2019 09:35:10 -0700 (PDT)
Received: from mb.local (c-73-202-177-209.hsd1.ca.comcast.net [73.202.177.209]) (authenticated bits=0) by nagasaki.bogus.com (8.15.2/8.15.2) with ESMTPA id x4VGZ88F030845; Fri, 31 May 2019 16:35:08 GMT (envelope-from joelja@bogus.com)
X-Authentication-Warning: nagasaki.bogus.com: Host c-73-202-177-209.hsd1.ca.comcast.net [73.202.177.209] claimed to be mb.local
Subject: Re: Generic anycast addresses...
To: Mark Smith <markzzzsmith@gmail.com>, Sander Steffann <sander@steffann.nl>
Cc: Michael Richardson <mcr+ietf@sandelman.ca>, "6man@ietf.org" <6man@ietf.org>, Dave Thaler <dthaler@microsoft.com>
References: <7A9560FC-0393-45DF-8389-B868455AC6DD@fugue.com> <20190530005734.7d2alod2zoaemmhc@faui48f.informatik.uni-erlangen.de> <D6E27B45-437F-45BE-A305-47DD460BCE02@fugue.com> <26144.1559226966@localhost> <1DD451A7-D898-4105-974C-53776A3DA9F2@fugue.com> <20190530152902.l2nmyhadr4e4kt7x@faui48f.informatik.uni-erlangen.de> <0FF19D6D-1A45-41EF-BE34-CC35B5E51E1E@steffann.nl> <D91629F6-73AC-4A80-80EF-16644F73DA36@fugue.com> <701687d4-842c-6a16-3c97-349125324e3f@gmail.com> <D648647D-60E1-4DCE-B0BE-11002E0AE5A4@fugue.com> <20190530220838.g2hshonsjxmfnd55@faui48f.informatik.uni-erlangen.de> <632BE7EC-26A6-44E9-9CCD-F0AE143D4256@fugue.com> <AF1967FC-526D-47FB-98BE-F9B949F26796@steffann.nl> <CAO42Z2yY=z-wKCUaCYZqJLHfT+LdyDOWz9bLG8QTh9C8sJCx3g@mail.gmail.com>
From: joel jaeggli <joelja@bogus.com>
Openpgp: preference=signencrypt
Autocrypt: addr=joelja@bogus.com; prefer-encrypt=mutual; keydata= mQGiBD832SIRBADVEfzsfIX+fuN2XUPyyEXP4Mq8dqpjmcy+XTIHzZLVKzxmP+17zJYTj9MR dMA5vuZRsRpzFoeDMOJyHVVyaQeSwEApO3FJOej+CNAXpaTLYgobL1XcsQXMTbeNT5x9ZK+R ZQtoC8Vunv6UTygY+kHUHvNijhVtJtCcAW0NE2fiWwCgjKPAldaGNbPg6SKvSTFipsPPqoUE ALKjZApjCG/3Yi4kHgzCQw65mfE9u8O7bZcrvmzzRgmwShyQjrRNgxhwl2q9+e8Uo6kuk56q 0Q4On6y873W6EtBRYLTU5MiIK3mspi5YYpIi/F2XTkcW6Dx/C/ZQQ8WddAyX6QLAXHYMus86 x7tzjGM3HVlvJpWTb4CqcDOcvZakA/9aJhMEffleJx+6xrjZTUYvAQDYUSRWNmc+ehyAuh/B KH0DKqhkLlm0SBdsnKvQHXbdjhu9m9K4E6aR/s117QK60jZo1XNrVKJ1oM3X+2DNmDBl/K33 e/tPSC8byvD77doezHvWvE5n50KIEZezVgMkYWDSPWb0nefdXLY5+rgfmrQfSm9lbCBKYWVn Z2xpIDxqb2VsamFAYm9ndXMuY29tPohjBBMRAgAjAhsDBgsJCAcDAgQVAggDBBYCAwECHgEC F4AFAk3mKPcCGQEACgkQ8AA1q7Z/VrJ6vgCfYITQSd0+WXcYjEoj8+tNys5egPcAn3OUUHVt JElVkSSARJ4XWjRYqKiauQQNBD8320MQEACTNxol/GIZW4CGUnyIlr+13Dqx8aHZfbd96UQE Ys9mZkBxwP2V7D00tOETcY5apr9tr9oHf5p4xA2l2oE8KR4xbF6+0XIpeYzRcl5d0iUaSMwm HcX3J/+XyZegJqTG7zMEK72c1tPVrra9DRNZP+rhKFLJJornDiQJFQVhtQE37WA1kmC6rlyR KHA2RMYS3IugAgJfuy5pZn/5jKCv+ZxIv7tnk7GUQWwfPdr4PokPCBxSXUYch98Rcq3dbCio 8FPmrfI6K2Z9NMa/gXGpF3ynmxDJLY31aPgbUiv9VllZoeMkotbXHW1zrsXte/1MEgFrlkiQ WDJ/dHjlCdlFASfaPvVXxdiUgH7LV3cW+BOY2z4VVwhYM6/kTDoLKWZ3opBeN9KcAHPRFCkA fxwAu8PNgi74lMjcFzu66U8vVM37YqSYpXsi+mlwZDhzCJ8qm9FDwaH2bB1LJ7m41F098B29 SRG3s/XXgTCSt0js/yUp9EXRPQpME99GvwiBNFN9p9e45ZqS85Wll6GqHh+Jyvq0ODWH6XOz uop3UUqw6I2Q8rG7e/uxKWcFnt1q48uhdTHA0TfnYC5HpHf/tAuR+ui6s16xrENgFgeeu4b/ q/jA4N1ZuJU7IbnO5f28YTlJOef/HywY3OXBsrdhEXKLIc5xRj6NC4WphyQ9MQrx8cS1bwAD BQ//WNM1WUlr6tIn8/7SIqqHRg3UmzVNu4u+r9rK9LJkYRLA4xKb/TrqDhP9oyO7Oz2S5CsF wjiPc1vzGzfRgIOArPJrejM4BzHQ03tl1qb/5YNDaB1QzfPv6dT9OkhMMuth0tcmH5sjfbiF Nc41aKU5w4FFkTv3XmrXciz4+PWbAYGB7pYbhGmsx//9C2bS56Bu1QkFeSCzN5AvWAmJfyPU yMXFKDe21DlImMdkrn/K838Lm8o0CLOKbJBX8K0pE4rGEf20FLfmHx/bLZRcWhTm8cB/vHNd 8GhwFlvHylj6+5QtR0Tc0hBcOG8SZktjE/hEiYi+dAZCrwT9i8Hjulnx/vu+Knt40+5CB2hk L1VQwdGWLYO4FGqWwwv0Y8XhWOudLYCZQWrgOsIzYezahC5b9iobFx8dgAElXNPTxI/dymrI d/6foyBrGnzzOnV/gfWfQp7N1rbrh0mQXRhwwwQIjlmbUyz8fTlaTcAo8ocXTVUb6WY7U5nr ufzKsFceR/olFnvZKKhbGVG6VvqNLS1r5lcRR1J7GVZM+Sb2ZNKgnwiUf8yxKfWg84NUPt/b etviJ73LVPdjV1PNZgcxfPRO3XL6Y9FaBP9oB4f58ujuhzOLUt+6I0KuzY8H5RBBaIrJJptl DEOnxFn1J7Q0uxQ2BzqfZdKTwJS4OCjm+OsLd8GIRgQYEQIABgUCPzfbQwAKCRDwADWrtn9W soUzAJ4zatxnKYcGdyoFojBc1Y2jqaHZsQCbB25DmeFRx14xxuxdAXb0wsKf35w=
Message-ID: <aa405734-b2dd-c21f-7377-2faaa24165e6@bogus.com>
Date: Fri, 31 May 2019 09:34:53 -0700
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:60.0) Gecko/20100101 Thunderbird/60.7.0
MIME-Version: 1.0
In-Reply-To: <CAO42Z2yY=z-wKCUaCYZqJLHfT+LdyDOWz9bLG8QTh9C8sJCx3g@mail.gmail.com>
Content-Type: multipart/signed; micalg="pgp-sha1"; protocol="application/pgp-signature"; boundary="DvHvfxbKf5PLrGL2oCNVOjU5jqdHFqwYG"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/43x4A5s1dDEuXJPREL_A7qrqqaE>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 31 May 2019 16:35:16 -0000
On 5/30/19 16:21, Mark Smith wrote: > > > On Fri., 31 May 2019, 08:54 Sander Steffann, <sander@steffann.nl > <mailto:sander@steffann.nl>> wrote: > > Hi Ted, > > >> To me, a non-fuzzy boundary is one where you do something like ACL on > >> a set of links completely isolating some area of the network. Fuzzy > >> could vbe absence of default route causing ULA to stop. Not sure if > >> these are good examples of any actual definition, but both ae > possible with > >> ULA. > >> > >> I'd mostly be concerned about non-fuzzy boundaries wrt. security, > >> so not sure if i'd always want to avoid non-fuzzy boundaries. > > > > The question is, what’s different about the proposed application > versus typical ULA usage? > > I like the scope aspect of Mark's draft. ULA is always organisation > or site scoped, and should be filtered as such. Anycast that have a > different scope should have different boundaries. Anycast addresses > that have ISP scope can cross from the customer's network to the > ISP's network, while there should be a boundary between that > customer's ULA addresses and that ISP's ULA addresses (let's assume > they both use ULA for this example). > > > An example use case for a Network Service Provider scope is anycast DNS > resolvers. > > You can't use ULA because customers don't send their ULA prefixes to > you, and you don't really want them to, as that makes your ISP network > part of their network. > > Ideally you don't want to use GUA DNS resolver anycast addresses because > that makes the DNS resolver vulnerable to DoS attacks from the Internet. It is straight forward enough to use a gua prefix which you do not announce to the internet as a whole. we do this with internal anycast(s), address space used for point-to-point links management networks and so forth. > When I first ran up anycast DNS resolvers, I ideally wanted to use IPv4 > addresses that had these property of globally unique, not globally > reachable, yet reachable from all customers' networks. Internet DoS > attacks on DNS resolvers were common at the time. > > RFC1918 didn't suit, nor did normal RIR public address space, because > APNIC expected it to be globally reachable. IX space suites, but we > weren't an IX. We could have probably lobbied harder for it, however we > needed to get them going.. > > > This is also part of my realisation that the forwarding scopes of our > unicast address spaces are quite coarse - global (GUA), organisation > (ULA) and link (Link-Local), and that's it. We have really bad historical experiences with attempts to define scopes. > The much more fine grained multicast scopes used with anycast addresses > would be much more flexible for anycast scenarios. > > I think reintroducing the Site-Locals as a unicast address space, just > to create Site-Local scope anycast addresses, isn't really properly > solving the problem in a general enough way. > > People will also use them for unicast addressing because they're more > similar to RFC1918s that ULAs - and we also have problems with people > not making ULA unique, despite the word Unique in the name. > > > No mention of generating unique ULAs, so people are being trained to use > ULAs that are not unique: > > https://github.com/leblancd/kube-v6/blob/master/README.md#set-up-node-ip-addresses > > A CPE vendor got this wrong too in the past: > > Residential IPv6 CPE - What Not To Do and Other Observations > https://www.ausnog.net/sites/default/files/ausnog-05/presentations/ausnog-05-d02p02-mark-smith.pdf > > > Regards, > Mark. > > > Cheers, > Sander > > -------------------------------------------------------------------- > IETF IPv6 working group mailing list > ipv6@ietf.org <mailto:ipv6@ietf.org> > Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6 > -------------------------------------------------------------------- > > > -------------------------------------------------------------------- > IETF IPv6 working group mailing list > ipv6@ietf.org > Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6 > -------------------------------------------------------------------- >
- Generic anycast addresses... Ted Lemon
- RE: Generic anycast addresses... Dave Thaler
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... George Michaelson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Bob Hinden
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... George Michaelson
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... George Michaelson
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... JORDI PALET MARTINEZ
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Sander Steffann
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Sander Steffann
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Fred Baker
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... STARK, BARBARA H
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Brian E Carpenter
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Sander Steffann
- Re: Generic anycast addresses... George Michaelson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Brian E Carpenter
- Re: Generic anycast addresses... Brian E Carpenter
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Fred Baker
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mikael Abrahamsson
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Mikael Abrahamsson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... joel jaeggli
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Fred Baker
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Nick Hilliard
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Joel Jaeggli
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Ole Troan
- Re: Generic anycast addresses... Brian E Carpenter
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Sander Steffann
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Nick Hilliard
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... joel jaeggli
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Mikael Abrahamsson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Mikael Abrahamsson
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Christian Huitema
- Re: Generic anycast addresses... Toerless Eckert
- Re: Generic anycast addresses... Michael Richardson
- Re: Generic anycast addresses... Brian E Carpenter
- Re: Generic anycast addresses... Mikael Abrahamsson
- Re: Generic anycast addresses... Sander Steffann
- Re: Generic anycast addresses... Christian Huitema
- Anycast to unicast resolution (was: Re: Generic a… Toerless Eckert
- Re: Anycast to unicast resolution (was: Re: Gener… Christian Huitema
- Re: Anycast to unicast resolution (was: Re: Gener… Brian Haberman
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Alexandre Petrescu
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Bob Hinden
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Bob Hinden
- Re: Generic anycast addresses... Ted Lemon
- Re: Generic anycast addresses... Mark Smith
- Re: Generic anycast addresses... Erik Kline
- Re: Generic anycast addresses... Mark Smith