RE: Confirmation to advance: draft-ietf-6man-ipv6only-flag-05

"Manfredi (US), Albert E" <albert.e.manfredi@boeing.com> Tue, 28 May 2019 00:17 UTC

Return-Path: <albert.e.manfredi@boeing.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 296FE1200C4 for <ipv6@ietfa.amsl.com>; Mon, 27 May 2019 17:17:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.199
X-Spam-Level:
X-Spam-Status: No, score=-4.199 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yeLWjor_I3Iw for <ipv6@ietfa.amsl.com>; Mon, 27 May 2019 17:17:54 -0700 (PDT)
Received: from clt-mbsout-02.mbs.boeing.net (clt-mbsout-02.mbs.boeing.net [130.76.144.163]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 78352120092 for <ipv6@ietf.org>; Mon, 27 May 2019 17:17:54 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by clt-mbsout-02.mbs.boeing.net (8.14.4/8.14.4/DOWNSTREAM_MBSOUT) with SMTP id x4S0HquT012010; Mon, 27 May 2019 20:17:52 -0400
Received: from XCH16-01-10.nos.boeing.com (xch16-01-10.nos.boeing.com [144.115.66.5]) by clt-mbsout-02.mbs.boeing.net (8.14.4/8.14.4/UPSTREAM_MBSOUT) with ESMTP id x4S0HiKu010933 (version=TLSv1/SSLv3 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=FAIL); Mon, 27 May 2019 20:17:44 -0400
Received: from XCH16-01-11.nos.boeing.com (144.115.66.39) by XCH16-01-10.nos.boeing.com (144.115.66.5) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384) id 15.1.1713.5; Mon, 27 May 2019 17:17:42 -0700
Received: from XCH16-01-11.nos.boeing.com ([fe80::c57c:39bc:4c0a:384b]) by XCH16-01-11.nos.boeing.com ([fe80::c57c:39bc:4c0a:384b%4]) with mapi id 15.01.1713.004; Mon, 27 May 2019 17:17:42 -0700
From: "Manfredi (US), Albert E" <albert.e.manfredi@boeing.com>
To: Mark Andrews <marka@isc.org>
CC: 6man WG <ipv6@ietf.org>
Subject: RE: Confirmation to advance: draft-ietf-6man-ipv6only-flag-05
Thread-Topic: Confirmation to advance: draft-ietf-6man-ipv6only-flag-05
Thread-Index: AQHVFJR7iwLqa8273kePmmwHPi642aZ/z4aAgAAdU4CAABQxgIAACUYAgAAC94CAAAXrAP//lblQ
Date: Tue, 28 May 2019 00:17:42 +0000
Message-ID: <e751f6ae57d94fc1b0eeccc5ade659e2@boeing.com>
References: <F8BFFCAD-E58E-4736-8A1C-56579B6F6032@employees.org> <232c1a43-0fd9-4eae-737b-260a3906f72a@gmail.com> <663F6C0B-7B8A-4088-B9C0-B2867B0C3EB8@gmail.com> <CAN-Dau3VJN7qNHAW-yStMrDRCa4vsDs2ObkAxswnYbcHde2t_w@mail.gmail.com> <m1hPqHO-0000J8C@stereo.hq.phicoh.net> <CAN-Dau3R=4JbcbK7tWkJKYzVjq7DvAAEjVsbCLbZdYYO8OJ0YA@mail.gmail.com> <m1hQ7Dm-0000M3C@stereo.hq.phicoh.net> <CAN-Dau040j6U+1CCn0QJiVMy2nVShHqqSFdCkM-FbMAH-2wjRA@mail.gmail.com> <m1hQCYr-0000KBC@stereo.hq.phicoh.net> <561d9dc3-c769-c774-8f65-f975ac2a10a0@gont.com.ar> <m1hT1DZ-0000HEC@stereo.hq.phicoh.net> <ce07ade8-5105-055f-4798-f4ef20a2393c@si6networks.com> <CAN-Dau02MYCrKx2BgyuYJeHBdoz6SHCnp+-byM+LMM8af0S+rA@mail.gmail.com> <40e99171-6dda-29e3-6152-da5ca5219ed9@foobar.org> <CAN-Dau0ALqfAA-Dz56oHAfOtY7E2obx5E7TgoeH357Mckp3t9g@mail.gmail.com> <093ba8e2-6f0a-4c91-9df1-cda33fffea97@foobar.org> <CAN-Dau3kVqb+ZEHB7iPGeRuq1Mu8UHR3FEZv8SgmiqZexaFhuA@mail.gmail.com> <12db9629-f92a-e12a-5ff1-7db2c5d2137e@foobar.org> <374F009B -98E1-40D0-AC0D-1C82CBE378BD@steffann.nl> <CAN-Dau0EGN+bLZCTA-A4ksd40KprhKn-HkL4gotG=v-=kD0zrg@mail.gmail.com> <F6F0C9DC-545E-4FE5-BB4C-55BB29022E84@steffann.nl> <C764119E-6CEA-4EEC-864C-2B8D66008D27@isc.org>
In-Reply-To: <C764119E-6CEA-4EEC-864C-2B8D66008D27@isc.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [144.115.204.6]
x-tm-snts-smtp: 356D10E4D4D41C53B00B924A8A9F8175383C7DBF473B37387FB65C8584DDA9CB2000:8
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-TM-AS-GCONF: 00
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/5_RUkGNMJ-i-S7MRsl6nDfZLGSs>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 May 2019 00:17:56 -0000

-----Original Message-----
From: ipv6 <ipv6-bounces@ietf.org> On Behalf Of Mark Andrews

> Actually their isn’t a alternative solution.  There are several things trying to be achieved.
>
> 1) remove ALL IPv4 traffic from the network.

I agree with Sander that we shouldn’t need to invent a new mechanism, only to be eventually left with this legacy wasted flag, taking up what could be precious spare space.

You, the netadmin, cannot even hope to remove all IPv4 from the network. The best you can do is to remove all IPv4 services from the network nodes you, the netadmin, control. Flag or no flag. Unless you post cops at every building entrance, and confiscate IPv4 equipment.

> 2) stopping hosts attempting to send IPv4 traffic onto the network.

Layer 2 filtering, at network nodes managed by netadmin. Hosts that use private switches and peripherals can’t be stopped anyway.

> 3) being able to turn off IPv4 on the router interface.

Netadmin can trivially do that, and no IPv4 client remaining would even be able to find the MAC address of such routers.

> 4) needs to work on a BYOD network.

No flag can achieve that. I bring my own switch and peripheral device, use these only in my office, IPv4 address statically configured.

> 5) eventually being able to turn off ALL IPv4 packet processing in the router.

Easy to do, anytime.

> If you have a solution that achieves all these goals without signalling via IPv6 I’d like to see it.  Filtering can’t achieve 2.  RFC2563 can’t achieve 1 and 5.

Layer 2 filtering (800 and 806), consequently, no ARP to or from network nodes, provide no A records from DNS, you, the netadmin, have done all that needs doing.

Honestly, the rest is the hosts' problem. For example, those hosts that fuss over battery life. Not a netadmin problem. Let the vendors figure it out.

Bert