Re: [Mip6] [issue24] Mobile IPv6 and Firewalls: Problem statement

QIU Ying <qiuying@i2r.a-star.edu.sg> Tue, 06 September 2005 07:36 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1ECXzw-0005Cc-7A; Tue, 06 Sep 2005 03:36:04 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1ECXzu-0005BV-1w for mip6@megatron.ietf.org; Tue, 06 Sep 2005 03:36:02 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id DAA10806 for <mip6@ietf.org>; Tue, 6 Sep 2005 03:35:58 -0400 (EDT)
Received: from rodin.i2r.a-star.edu.sg ([192.122.139.27]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1ECY2l-0004Dg-EV for mip6@ietf.org; Tue, 06 Sep 2005 03:39:01 -0400
Received: from rodin.i2r.a-star.edu.sg (localhost [127.0.0.1]) by rodin.i2r.a-star.edu.sg (8.13.1/8.13.1) with ESMTP id j867ZhOM022055 for <mip6@ietf.org>; Tue, 6 Sep 2005 15:35:43 +0800 (SGT)
Received: from newmailhost.i2r.a-star.edu.sg ([192.122.134.76])by rodin.i2r.a-star.edu.sg (8.13.1/8.13.1) with ESMTP id j867Zgnd022037for <mip6@ietf.org>; Tue, 6 Sep 2005 15:35:42 +0800 (SGT)
Received: from SwitchFirst ([192.168.137.164])by mailhost.lit.org.sg (Sun Java System Messaging Server 6.1 HotFix 0.06(built Nov 11 2004)) with SMTP id <0IMD009BHX3MFH80@mailhost.lit.org.sg> formip6@ietf.org; Tue, 06 Sep 2005 15:35:46 +0800 (SGT)
Date: Tue, 06 Sep 2005 15:37:01 +0800
From: QIU Ying <qiuying@i2r.a-star.edu.sg>
Subject: Re: [Mip6] [issue24] Mobile IPv6 and Firewalls: Problem statement
To: "Tschofenig, Hannes" <hannes.tschofenig@siemens.com>, mip6@ietf.org, tracker-mip6@mip4.org
Message-id: <026101c5b2b5$c564a7e0$a489a8c0@SwitchFirst>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
Content-type: text/plain; format="flowed"; charset="iso-8859-1"; reply-type="original"
Content-transfer-encoding: 7bit
X-Priority: 3
X-MSMail-priority: Normal
References: <ECDC9C7BC7809340842C0E7FCF48C39363CFBA@MCHP7IEA.ww002.siemens.n et>
X-imss-version: 2.031
X-imss-result: Passed
X-imss-scores: Clean:99.90000 C:2 M:3 S:5 R:5
X-imss-settings: Baseline:5 C:4 M:4 S:4 R:4 (1.5000 1.5000)
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 612a16ba5c5f570bfc42b3ac5606ac53
Content-Transfer-Encoding: 7bit
Cc: Robert Deng <deng@i2r.a-star.edu.sg>, Feng Bao <baofeng@i2r.a-star.edu.sg>
X-BeenThere: mip6@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: mip6.ietf.org
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/mip6>, <mailto:mip6-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:mip6@ietf.org>
List-Help: <mailto:mip6-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/mip6>, <mailto:mip6-request@ietf.org?subject=subscribe>
Sender: mip6-bounces@ietf.org
Errors-To: mip6-bounces@ietf.org

Hi, Hannes

My 2 cents are below.

----- Original Message ----- 
From: "Tschofenig, Hannes" hannes.tschofenig@siemens.com

>hi all,
>
>browsing through your draft i got the impression that you do not talk
>about firewalls in transit networks either.
>i understood spencer in such a way that he pointed to firewalls that are
>between the home, visited, and correspondent networks.

If I'm not wrong and HMIP is accepted, could we think HMIP is the transit 
network between home/correspondent network and mobile nodes because MN 
anchors to a AR that is a subnet under MAP?

>a few questions arise:
>- is the treatment of firewalls in a transit networks (not in the home,
>visited or cn's network) somewhat special (and does it raise additional
>requirements)?

Yes, I am sure somewhat special process is need. The main reason is that the 
source and destination addresses of packets are variers.  How to config the 
firewall rules or how to identify a packet?

>- are firewalls in a transit networks stateful packet filtering
>firewalls?

Yes. I think so because stateful packet filtering firewalls is the most 
popular, and the most  important,  it is deploied in IP level.

>- are additional aspects with firewalls in transit networks specific to
>a solution or generic.

come back to the first question.

Regards
Qiu Ying



> Hi, Spencer
>
> Your comments points out the important issues and
> consideration on the
> mobile firewall environment.
>
> >The stated goal for this document is to enable further discussion;
> >I didn't see any thought given to firewalls in transit networks
> >between the home, visited, and correspondent networks, and
> >I'll bet transit networks will have something like firewalls
> in place,
>
> Yes, it is true. The draft of mobile firewall
> (http://www.ietf.org/internet-drafts/draft-qiu-mip6-mobile-fir
> ewall-01.txt)
> is one of the thoughts in transit networks between the home,
> visited, and
> correspondent networks. The draft discusses a scheme how a
> administrator (in
> home) dynamically monitors or controls the communication of
> roaming mobile
> nodes (sub-network in visited domain) with the correspondent nodes.
>
> The concept of mobile firewall is: when a mobile node (MN)
> roams into a
> foreign network managed by a mobility anchor point (MAP), the
> home agent
> (HA) will authorize the MAP to serve as a security proxy. The HA will
> negotiate with the MAP on the security association and then
> transfer to the
> MAP the defined security rules that will be applied on all
> communications to
> the MN. According to HMIPv6 protocol, all packets to MN will
> go through MAP.
> Therefore, the MAP has the ability of filtering packets. The
> MAP could also
> send the MN's traffic logs to the HA. The MN's administrator could
> dynamically monitor the MN's activities by retrieving the
> MN's traffic logs
> through the HA. If necessary, the MN's administrator could update the
> security rules so that the MN's activities could be
> controlled dynamically.
> All the operations are transparent to the MN, and the MN will
> be served in
> the way specified by its administrator no matter where it roams.
>
> This scheme meets the scenario described in section 5.1 of
> draft-ietf-mip6-firewall.
>
>
> >Although BEHAVE explicitly declares firewalls to be out of scope,
> >it seems that what's needed is something like BRIDE of BEHAVE,
> >developing BCP recommendations for firewall types.
>
> We are trying to make some contribution on this issue. In the
> first phase,
> we are developing a practice on said scheme.
>
> Regards and Thanks
> Qiu Ying
>
>
> > Date: Thu, 01 Sep 2005 20:23:42 +0000
> > From: admin <tracker-mip6@mip4.org>
> > Subject: [Mip6] [issue24] Mobile IPv6 and Firewalls:
> Problem statement
> > To: mip6@ietf.org
> > Message-ID: <1125606222.54.0.311064999811.issue24@mip4.org>
> > Content-Type: text/plain; charset=utf-8
> >
> >
> > New submission from admin <roundup-admin@mip4.org>:
> >
> > Review comments by Spencer Dawkins (Gen-ART)
> >
> > Background for those on the CC list, who may be unaware of GenART:
> > GenART is the Area Review Team for the General Area of the IETF.  We
> > advise the General Area Director (i.e. the IETF/IESG chair) by
> > providing more in depth reviews than he could do himself of
> documents
> > that come up for final decision in IESG telechat.  I was selected
> > as the GenART member to review this document.  Below is my review,
> > which was written specifically with an eye to the GenART
> process, but
> > since I believe that it will be useful to have these comments more
> > widely distributed, others outside the GenART group are
> being copied.
> >
> > Intended status: Informational
> >
> > Summary - this document is very close to being ready for
> publication as
> > Informational.
> >
> > I don't believe that Gen-ART reviews for Informational
> documents need to
> > say much more than this, but, since I'm typing...
> >
> > - The document is clearly written and well-organized. Other
> reviewers
> > might push back on the breezy English style, but I like it.
> >
> > - The first time there's a clue that firewalls are problematic for
> > NON-mobile users is in the Conclusion:
> >
> >   Current firewalls may not only prevent route optimization but may
> >   also prevent regular TCP and UDP sessions from being
> established in
> >   some cases.  This document describes some of the issues
> between the
> >   Mobile IPv6 protocol and current firewall technologies.
> >
> > It might be nice to call this issue out earlier in the
> draft, so that
> > it's more obvious what ADDITIONAL problems happen when you
> go mobile.
> > Firewalls that drop ESP by default, for instance, are
> problematic for
> > non-mobile users - stuff like that.
> >
> > - The stated goal for this document is to enable futher
> discussion; I
> > didn't see any thought given to firewalls in transit
> networks between
> > the home, visited, and correspondent networks, and I'll bet transit
> > networks will have something like firewalls in place, in at
> least some
> > environments. Even a statement that says "we don't think
> firewalls in
> > transit networks will add any requirements for further
> work" would be
> > useful.
> >
> > - The assumption that issues called out in this draft will
> be solved in
> > MIP6 is stated at the end of the abstract. Although BEHAVE
> explicitly
> > declares firewalls to be out of scope, it seems that what's
> needed is
> > something like BRIDE of BEHAVE, developing BCP recommendations for
> > firewall types, just as BEHAVE is doing for NAT types...
> >
> > Thanks,
> >
> > Spencer
> >
> > ----------
> > category: Editorial
> > draft: draft-ietf-mip6-firewalls
> > messages: 90
> > nosy: admin
> > priority: Should fix
> > status: No discussion
> > title: Mobile IPv6 and Firewalls: Problem statement
> >
>
>
>
>
>
> _______________________________________________
> Mip6 mailing list
> Mip6@ietf.org
> https://www1.ietf.org/mailman/listinfo/mip6
> 


_______________________________________________
Mip6 mailing list
Mip6@ietf.org
https://www1.ietf.org/mailman/listinfo/mip6