Re: 6man w.g. last call for <draft-ietf-6man-grand>

"Pascal Thubert (pthubert)" <pthubert@cisco.com> Thu, 23 July 2020 07:47 UTC

Return-Path: <pthubert@cisco.com>
X-Original-To: ipv6@ietfa.amsl.com
Delivered-To: ipv6@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D1A8A3A076C for <ipv6@ietfa.amsl.com>; Thu, 23 Jul 2020 00:47:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.62
X-Spam-Level:
X-Spam-Status: No, score=-9.62 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=L9zjSZZK; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=EVe3JgLb
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id c7ag8ukjWsnp for <ipv6@ietfa.amsl.com>; Thu, 23 Jul 2020 00:47:28 -0700 (PDT)
Received: from alln-iport-2.cisco.com (alln-iport-2.cisco.com [173.37.142.89]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 230233A08CF for <ipv6@ietf.org>; Thu, 23 Jul 2020 00:47:28 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=2332; q=dns/txt; s=iport; t=1595490448; x=1596700048; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=b1K46bmCYlPFuQDfAIb2cbW4uxdeu+5ut8dtOHBM7vQ=; b=L9zjSZZKe6OlssBAnJMO5l0Vj6f3ykyzl+N6pM/95K5wK6+ah8oZZZ2F 9ksnJy7QuSClgrq/xUwLY6D2Poh5FxhKdJN5iQbXlL3wYq4O8xSpPnrAr BwzDUAmqkDK7FABWRt6uALYeI0mAQTUn5PCy7b6fzdAXwavte3+o8h7hS g=;
IronPort-PHdr: 9a23:epWdORyBqNZ3eePXCy+N+z0EezQntrPoPwUc9psgjfdUf7+++4j5ZRWDt/pohV7NG47c7qEMh+nXtvXmXmoNqdaEvWsZeZNBHxkClY0NngMmDcLEbC+zLPPjYyEgWsgXUlhj8iK0NEFUHID1YFiB6nG35CQZTxP4Mwc9L+/pG4nU2sKw0e36+5DabwhSwjSnZrYnJxStpgKXvc4T0oY=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0BKAAChPxlf/4wNJK1gHAEBAQEBAQcBARIBAQQEAQFAgTYHAQELAYFRUQdvWC8shDODRgOEWIh3igOOXIEugSUDVQsBAQEMAQEYCwoCBAEBhEwCF4F+AiQ0CQ4CAwEBCwEBBQEBAQIBBgRthVwMhXEBAQEBAgEBARALBhEMAQEsCwEECwIBCA4KAgImAgICHwYLFRACBA4FIoMEAYJLAw4gAQ6iHgKBOYhhdoEygwEBAQWFJQ0Lgg4DBoEOKgGCaYNVg2iCSxqBQT+BOByCTT6CGkIBAYFfgxYzgi2PRYJaPaIrTgqCXZRzhHMDHoJ7iUCTFp8PkgECBAIEBQIOAQEFgVM6gVdwFTsqAYI+UBcCDY4eg3GFFIVCdDcCBgEHAQEDCXyPAQEB
X-IronPort-AV: E=Sophos;i="5.75,385,1589241600"; d="scan'208";a="534168130"
Received: from alln-core-7.cisco.com ([173.36.13.140]) by alln-iport-2.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 23 Jul 2020 07:47:27 +0000
Received: from XCH-RCD-005.cisco.com (xch-rcd-005.cisco.com [173.37.102.15]) by alln-core-7.cisco.com (8.15.2/8.15.2) with ESMTPS id 06N7lRDd019735 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Thu, 23 Jul 2020 07:47:27 GMT
Received: from xhs-aln-001.cisco.com (173.37.135.118) by XCH-RCD-005.cisco.com (173.37.102.15) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 23 Jul 2020 02:47:26 -0500
Received: from xhs-rcd-002.cisco.com (173.37.227.247) by xhs-aln-001.cisco.com (173.37.135.118) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Thu, 23 Jul 2020 02:47:25 -0500
Received: from NAM12-MW2-obe.outbound.protection.outlook.com (72.163.14.9) by xhs-rcd-002.cisco.com (173.37.227.247) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Thu, 23 Jul 2020 02:47:25 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=nWMwTwYe8N1NFFqfZmNXQH1TsjdLbpMHOGbkk0P8Qz/fcwg33yhVtoZs7iriGw/RFr+j7UTRyij9lTFEE1mhWPCBIVFHzj7P8FzSJRovKj7IH5ikWaz2PnwTY+BGk2WflZgBYzF+7q4KxiIR+6BvSpvbo4zwCRxbfxVcxh5vFHpgQSxOaDZKyQ7HsiiC+j7qG+Wkfk2vaDukYLjG1b9oXJ8p4LR4IEq1oJTgTrzdum9VcjLidmqNlnHadIKDR8wplX//c/esk+wdIZWCrEvZv56+UL3ddO8R8vN5Fl+wx0jTvetQT8LWgeFoL6j+3HxoOzkawg6tIW+pY36fsT9U3w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=b1K46bmCYlPFuQDfAIb2cbW4uxdeu+5ut8dtOHBM7vQ=; b=h0MJ90REAvNKe8TLgsTCS7/JMlbYf0fn91IoYCxsqwKDdn4QczwmMC2bLZRRv5IV0mK9O9Cfy9gY3drpz7naF2QvhQhf9oFW+y1u0nEutodx5gS9CBJp2PmA+qru9UozP98NyKZQ3zkS7C/i9BVTZdPKGGszvgOTLtwBkl4eIs5LCOxs3qU0wT55u3MSu7+v34dw0fKfaPtlJjiOfAKAX8uSLkiBiu6nKl3/oukwBx7gGA/HBagf4wtJim9Y/z3go3Ki8xuIPKBzbgYnu1v6icIiKadWuPzmzCqeqbinwLQ/Y1Awqk5vh0rCAKbYYAR0paaDFtvQ2o53G6b//395mw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=b1K46bmCYlPFuQDfAIb2cbW4uxdeu+5ut8dtOHBM7vQ=; b=EVe3JgLbQjaypNCykA8JNT4RLy8zhV9yFyNSylbwscQj8/rtFC0Ot4FhFoog0eJEJ57JcPXbCjjAQrr4KW+Qy43Pdhwl9joU5CPOutnpOQ5VoxgrIdmXEOPDREa9Lh67VvjnrIyLyBRelWhzD7lQRNua1S4acAY5a08vEjA9Vy4=
Received: from MN2PR11MB3565.namprd11.prod.outlook.com (2603:10b6:208:ea::31) by MN2PR11MB3645.namprd11.prod.outlook.com (2603:10b6:208:f8::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3216.21; Thu, 23 Jul 2020 07:47:24 +0000
Received: from MN2PR11MB3565.namprd11.prod.outlook.com ([fe80::a53e:5801:92cc:3204]) by MN2PR11MB3565.namprd11.prod.outlook.com ([fe80::a53e:5801:92cc:3204%5]) with mapi id 15.20.3216.023; Thu, 23 Jul 2020 07:47:24 +0000
From: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
To: Jen Linkova <furry13@gmail.com>
CC: Mark Smith <markzzzsmith@gmail.com>, Jen Linkova <furry@google.com>, Bob Hinden <bob.hinden@gmail.com>, IPv6 List <ipv6@ietf.org>
Subject: Re: 6man w.g. last call for <draft-ietf-6man-grand>
Thread-Topic: 6man w.g. last call for <draft-ietf-6man-grand>
Thread-Index: AQHWWsvnrQ8Xi/qEv0uuTC0oiKoZmqkJHL0AgAAUHICABlbFAIAAsEKAgAQKgYCAACWVAIAAB+OAgABlj4A=
Date: Thu, 23 Jul 2020 07:47:24 +0000
Message-ID: <4364CFFC-A501-48FA-ABC5-AA1DC984A945@cisco.com>
References: <CAFU7BAQXYmig703yKsDLK-pb7KEd-PuiFQspWbhaZv-kzusAkw@mail.gmail.com>
In-Reply-To: <CAFU7BAQXYmig703yKsDLK-pb7KEd-PuiFQspWbhaZv-kzusAkw@mail.gmail.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: gmail.com; dkim=none (message not signed) header.d=none;gmail.com; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [2a01:cb1d:4ec:2200:2966:398:7610:4c7e]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 35611821-c27b-4cb9-7215-08d82edca3b4
x-ms-traffictypediagnostic: MN2PR11MB3645:
x-microsoft-antispam-prvs: <MN2PR11MB36450632A609276822A77F87D8760@MN2PR11MB3645.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:8273;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: A8CNE/q8GK3zUIwHmcSCsTyK6pEhHumeHXfmjOnm8hsJ/o8aHxo4NEhlziEWGZHZ9Xq4gNHgA9fYZqJD8Lh8UWFgVBlK1KcqN4ttDcN2Xico1Oqj7tlTTkO1KcfOEXaMnCCAM85IKCY0eT3acaI2pVX2yBjwnY6wVnrMF6XNTV2alJPIE6wWg5PuFBMErKsq1DziAVPA7R90OC6Id/e6a63MGM75xLbEb8LEsbTUdYgTZB4DWZ/4Hbu9Jo0K75rh4nhxWFE0VjgExnKkI0AIQwSIW2ndYwnNq6WUG+QCk+vebD5i8ki6CFJXD9d29Dwlnc4fPBOC9J2jZJM9eOOHBHc/iqVyyyTyeTvUIMN+d91E4A9qdJGyXHQKTxetYay7R5KfPC6Xa4vA7VOfrYEhFw==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR11MB3565.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(376002)(366004)(136003)(39860400002)(346002)(396003)(2616005)(6506007)(86362001)(478600001)(66476007)(4326008)(5660300002)(966005)(64756008)(33656002)(6916009)(36756003)(8676002)(6512007)(6486002)(66446008)(8936002)(54906003)(316002)(76116006)(91956017)(71200400001)(66574015)(4743002)(2906002)(66556008)(186003)(66946007)(83380400001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: 7KUX8JXnpgrVm4uPc5hZyAp76gvV/0PIYckjW1oZePnQ7/YS/JYruB1LRKLFZAT4TJZjamSShzJpvYXT36QG9pkquK9VfmxZng+YGbVRqXRtIP4pbDljFjmI3l75F0k+vIR3/IF5cjmV6OSqCU5tQmBgK2LTeO6cD1HWQlXaTmQdFrUyivT0pFZ0ZRv4Nm+Vtd6EdUu/SDmAffRDMQ9goWrZ0FQmMsDGT+o/tJSouFlH0NIXJATuHNla8wv/rxhtrTqKG67+I8UXks4Vs9tszOGJoZpXGEPZkqKvSrE3iKsWWm1UfOSAG//3kyU+1ZHhQFmpKUmRInLco0dH7trk1oN9aBdjW4ScjKCmQ90RODw6vxJUhkZOa/H1jfWXW99uSOJtKaue6vV/4BlBrM+f8FzfxVm8fXMDjfBdhewfRWXaRo0SvSqrdBm4AbkA6iw+gsZFEaLBHvOV87teHP3YN6aOUe2dBmZZM876z89Af9Y+YKHas60ybqjvvoGW2olD9eGpewXV0E4B2mvs70PGMA3aRQVUCsRSWeNs7zdqkw1/qqXbccxeXKtSi6j07EXD
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <F66FACEA9855DC4D88FF7C4D328DC0F7@cisco.onmicrosoft.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MN2PR11MB3565.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 35611821-c27b-4cb9-7215-08d82edca3b4
X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Jul 2020 07:47:24.5740 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: g5EYyiBDieTq7kUfQmUY8GslVr0nIRrITKD9xfv6PZ0beSBoQsjMdZCijbAZQ6z6qaB57VaYEySkiHNBig3Zng==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB3645
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.37.102.15, xch-rcd-005.cisco.com
X-Outbound-Node: alln-core-7.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/ipv6/Qrg8Kgspt-03tFWjXdrRljGTR2c>
X-BeenThere: ipv6@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "IPv6 Maintenance Working Group \(6man\)" <ipv6.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ipv6>, <mailto:ipv6-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ipv6/>
List-Post: <mailto:ipv6@ietf.org>
List-Help: <mailto:ipv6-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ipv6>, <mailto:ipv6-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 Jul 2020 07:47:30 -0000

> Le 23 juil. 2020 à 03:44, Jen Linkova <furry13@gmail.com> a écrit :
> 
> On Thu, Jul 23, 2020 at 11:15 AM Jen Linkova <furry13@gmail.com> wrote:
>>> - helping mitigate ND cache exhaustion DoS attack by preloading the
>>> cache with addresses
>> 
>> I'm not sure I fully understand how it would help...Could you please elaborate?
>> The attack is trying to create a lot of INCOMPLETE entries by sending
>> packets to non-existing addresses.
>> Unless we require that routers rely on GRAND only and never even try
>> to create a new entry upon receiving a packet to an address never seen
>> before, the router behaviour would still be the same.

I hope it is clear by now that grand does not change the nature of the NCE, that is a cache. We cannot trust the ND cache to defeat a DoS attack. You can only do that when a hard state is proactively maintained for each address.

This means deploying an RFC 8505-only network. This is still allows both centralized (DHCP) and autoconf (SLAAC), address allocation is orthogonal to neighbor state management.

Keep safe,

Pascal


> 
> I stand corrected. Yeah, it might help as it makes it more likely that
> an address which does not exist in the cache does not exist on the
> network either.
> So resolving such addresses could be deprioritized even more.
> Funny enough the draft does say it already ;))
> 
> -- 
> SY, Jen Linkova aka Furry
> 
> --------------------------------------------------------------------
> IETF IPv6 working group mailing list
> ipv6@ietf.org
> Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6
> --------------------------------------------------------------------