Re: [Mip6] [issue24] Mobile IPv6 and Firewalls: Problem statement
QIU Ying <qiuying@i2r.a-star.edu.sg> Tue, 06 September 2005 07:36 UTC
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1ECXzw-0005Cc-7A; Tue, 06 Sep 2005 03:36:04 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1ECXzu-0005BV-1w for mip6@megatron.ietf.org; Tue, 06 Sep 2005 03:36:02 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id DAA10806 for <mip6@ietf.org>; Tue, 6 Sep 2005 03:35:58 -0400 (EDT)
Received: from rodin.i2r.a-star.edu.sg ([192.122.139.27]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1ECY2l-0004Dg-EV for mip6@ietf.org; Tue, 06 Sep 2005 03:39:01 -0400
Received: from rodin.i2r.a-star.edu.sg (localhost [127.0.0.1]) by rodin.i2r.a-star.edu.sg (8.13.1/8.13.1) with ESMTP id j867ZhOM022055 for <mip6@ietf.org>; Tue, 6 Sep 2005 15:35:43 +0800 (SGT)
Received: from newmailhost.i2r.a-star.edu.sg ([192.122.134.76])by rodin.i2r.a-star.edu.sg (8.13.1/8.13.1) with ESMTP id j867Zgnd022037for <mip6@ietf.org>; Tue, 6 Sep 2005 15:35:42 +0800 (SGT)
Received: from SwitchFirst ([192.168.137.164])by mailhost.lit.org.sg (Sun Java System Messaging Server 6.1 HotFix 0.06(built Nov 11 2004)) with SMTP id <0IMD009BHX3MFH80@mailhost.lit.org.sg> formip6@ietf.org; Tue, 06 Sep 2005 15:35:46 +0800 (SGT)
Date: Tue, 06 Sep 2005 15:37:01 +0800
From: QIU Ying <qiuying@i2r.a-star.edu.sg>
Subject: Re: [Mip6] [issue24] Mobile IPv6 and Firewalls: Problem statement
To: "Tschofenig, Hannes" <hannes.tschofenig@siemens.com>, mip6@ietf.org, tracker-mip6@mip4.org
Message-id: <026101c5b2b5$c564a7e0$a489a8c0@SwitchFirst>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
Content-type: text/plain; format="flowed"; charset="iso-8859-1"; reply-type="original"
Content-transfer-encoding: 7bit
X-Priority: 3
X-MSMail-priority: Normal
References: <ECDC9C7BC7809340842C0E7FCF48C39363CFBA@MCHP7IEA.ww002.siemens.n et>
X-imss-version: 2.031
X-imss-result: Passed
X-imss-scores: Clean:99.90000 C:2 M:3 S:5 R:5
X-imss-settings: Baseline:5 C:4 M:4 S:4 R:4 (1.5000 1.5000)
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 612a16ba5c5f570bfc42b3ac5606ac53
Content-Transfer-Encoding: 7bit
Cc: Robert Deng <deng@i2r.a-star.edu.sg>, Feng Bao <baofeng@i2r.a-star.edu.sg>
X-BeenThere: mip6@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: mip6.ietf.org
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/mip6>, <mailto:mip6-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:mip6@ietf.org>
List-Help: <mailto:mip6-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/mip6>, <mailto:mip6-request@ietf.org?subject=subscribe>
Sender: mip6-bounces@ietf.org
Errors-To: mip6-bounces@ietf.org
Hi, Hannes My 2 cents are below. ----- Original Message ----- From: "Tschofenig, Hannes" hannes.tschofenig@siemens.com >hi all, > >browsing through your draft i got the impression that you do not talk >about firewalls in transit networks either. >i understood spencer in such a way that he pointed to firewalls that are >between the home, visited, and correspondent networks. If I'm not wrong and HMIP is accepted, could we think HMIP is the transit network between home/correspondent network and mobile nodes because MN anchors to a AR that is a subnet under MAP? >a few questions arise: >- is the treatment of firewalls in a transit networks (not in the home, >visited or cn's network) somewhat special (and does it raise additional >requirements)? Yes, I am sure somewhat special process is need. The main reason is that the source and destination addresses of packets are variers. How to config the firewall rules or how to identify a packet? >- are firewalls in a transit networks stateful packet filtering >firewalls? Yes. I think so because stateful packet filtering firewalls is the most popular, and the most important, it is deploied in IP level. >- are additional aspects with firewalls in transit networks specific to >a solution or generic. come back to the first question. Regards Qiu Ying > Hi, Spencer > > Your comments points out the important issues and > consideration on the > mobile firewall environment. > > >The stated goal for this document is to enable further discussion; > >I didn't see any thought given to firewalls in transit networks > >between the home, visited, and correspondent networks, and > >I'll bet transit networks will have something like firewalls > in place, > > Yes, it is true. The draft of mobile firewall > (http://www.ietf.org/internet-drafts/draft-qiu-mip6-mobile-fir > ewall-01.txt) > is one of the thoughts in transit networks between the home, > visited, and > correspondent networks. The draft discusses a scheme how a > administrator (in > home) dynamically monitors or controls the communication of > roaming mobile > nodes (sub-network in visited domain) with the correspondent nodes. > > The concept of mobile firewall is: when a mobile node (MN) > roams into a > foreign network managed by a mobility anchor point (MAP), the > home agent > (HA) will authorize the MAP to serve as a security proxy. The HA will > negotiate with the MAP on the security association and then > transfer to the > MAP the defined security rules that will be applied on all > communications to > the MN. According to HMIPv6 protocol, all packets to MN will > go through MAP. > Therefore, the MAP has the ability of filtering packets. The > MAP could also > send the MN's traffic logs to the HA. The MN's administrator could > dynamically monitor the MN's activities by retrieving the > MN's traffic logs > through the HA. If necessary, the MN's administrator could update the > security rules so that the MN's activities could be > controlled dynamically. > All the operations are transparent to the MN, and the MN will > be served in > the way specified by its administrator no matter where it roams. > > This scheme meets the scenario described in section 5.1 of > draft-ietf-mip6-firewall. > > > >Although BEHAVE explicitly declares firewalls to be out of scope, > >it seems that what's needed is something like BRIDE of BEHAVE, > >developing BCP recommendations for firewall types. > > We are trying to make some contribution on this issue. In the > first phase, > we are developing a practice on said scheme. > > Regards and Thanks > Qiu Ying > > > > Date: Thu, 01 Sep 2005 20:23:42 +0000 > > From: admin <tracker-mip6@mip4.org> > > Subject: [Mip6] [issue24] Mobile IPv6 and Firewalls: > Problem statement > > To: mip6@ietf.org > > Message-ID: <1125606222.54.0.311064999811.issue24@mip4.org> > > Content-Type: text/plain; charset=utf-8 > > > > > > New submission from admin <roundup-admin@mip4.org>: > > > > Review comments by Spencer Dawkins (Gen-ART) > > > > Background for those on the CC list, who may be unaware of GenART: > > GenART is the Area Review Team for the General Area of the IETF. We > > advise the General Area Director (i.e. the IETF/IESG chair) by > > providing more in depth reviews than he could do himself of > documents > > that come up for final decision in IESG telechat. I was selected > > as the GenART member to review this document. Below is my review, > > which was written specifically with an eye to the GenART > process, but > > since I believe that it will be useful to have these comments more > > widely distributed, others outside the GenART group are > being copied. > > > > Intended status: Informational > > > > Summary - this document is very close to being ready for > publication as > > Informational. > > > > I don't believe that Gen-ART reviews for Informational > documents need to > > say much more than this, but, since I'm typing... > > > > - The document is clearly written and well-organized. Other > reviewers > > might push back on the breezy English style, but I like it. > > > > - The first time there's a clue that firewalls are problematic for > > NON-mobile users is in the Conclusion: > > > > Current firewalls may not only prevent route optimization but may > > also prevent regular TCP and UDP sessions from being > established in > > some cases. This document describes some of the issues > between the > > Mobile IPv6 protocol and current firewall technologies. > > > > It might be nice to call this issue out earlier in the > draft, so that > > it's more obvious what ADDITIONAL problems happen when you > go mobile. > > Firewalls that drop ESP by default, for instance, are > problematic for > > non-mobile users - stuff like that. > > > > - The stated goal for this document is to enable futher > discussion; I > > didn't see any thought given to firewalls in transit > networks between > > the home, visited, and correspondent networks, and I'll bet transit > > networks will have something like firewalls in place, in at > least some > > environments. Even a statement that says "we don't think > firewalls in > > transit networks will add any requirements for further > work" would be > > useful. > > > > - The assumption that issues called out in this draft will > be solved in > > MIP6 is stated at the end of the abstract. Although BEHAVE > explicitly > > declares firewalls to be out of scope, it seems that what's > needed is > > something like BRIDE of BEHAVE, developing BCP recommendations for > > firewall types, just as BEHAVE is doing for NAT types... > > > > Thanks, > > > > Spencer > > > > ---------- > > category: Editorial > > draft: draft-ietf-mip6-firewalls > > messages: 90 > > nosy: admin > > priority: Should fix > > status: No discussion > > title: Mobile IPv6 and Firewalls: Problem statement > > > > > > > > _______________________________________________ > Mip6 mailing list > Mip6@ietf.org > https://www1.ietf.org/mailman/listinfo/mip6 > _______________________________________________ Mip6 mailing list Mip6@ietf.org https://www1.ietf.org/mailman/listinfo/mip6
- AW: [Mip6] [issue24] Mobile IPv6 and Firewalls: P… Tschofenig, Hannes
- Re: [Mip6] [issue24] Mobile IPv6 and Firewalls: P… QIU Ying
- AW: [Mip6] [issue24] Mobile IPv6 and Firewalls: P… Tschofenig, Hannes
- [Mip6] Registration Type Change Disallowed questi… suraj
- Re: [Mip6] Registration Type Change Disallowed qu… Charles E. Perkins
- Re: [Mip6] Registration Type Change Disallowed qu… Jari Arkko