Re: [MMUSIC] 1 Week WGLC for draft-ietf-mmusic-rtsp-nat-evaluation-06

Ari Keränen <ari.keranen@ericsson.com> Thu, 23 May 2013 18:17 UTC

Return-Path: <ari.keranen@ericsson.com>
X-Original-To: mmusic@ietfa.amsl.com
Delivered-To: mmusic@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1138121F96ED for <mmusic@ietfa.amsl.com>; Thu, 23 May 2013 11:17:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.099
X-Spam-Level:
X-Spam-Status: No, score=-6.099 tagged_above=-999 required=5 tests=[AWL=-0.150, BAYES_00=-2.599, HELO_EQ_SE=0.35, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zLBJm3VSuige for <mmusic@ietfa.amsl.com>; Thu, 23 May 2013 11:16:53 -0700 (PDT)
Received: from mailgw1.ericsson.se (mailgw1.ericsson.se [193.180.251.45]) by ietfa.amsl.com (Postfix) with ESMTP id CAEBC21F95E4 for <mmusic@ietf.org>; Thu, 23 May 2013 10:58:43 -0700 (PDT)
X-AuditID: c1b4fb2d-b7fe36d000007102-ad-519e58d27f98
Received: from esessmw0197.eemea.ericsson.se (Unknown_Domain [153.88.253.125]) by mailgw1.ericsson.se (Symantec Mail Security) with SMTP id 52.28.28930.2D85E915; Thu, 23 May 2013 19:58:42 +0200 (CEST)
Received: from mail.lmf.ericsson.se (153.88.115.8) by esessmw0197.eemea.ericsson.se (153.88.115.88) with Microsoft SMTP Server id 8.3.279.1; Thu, 23 May 2013 19:58:42 +0200
Received: from nomadiclab.lmf.ericsson.se (nomadiclab.lmf.ericsson.se [131.160.33.3]) by mail.lmf.ericsson.se (Postfix) with ESMTP id DD364237A; Thu, 23 May 2013 20:58:41 +0300 (EEST)
Received: from nomadiclab.lmf.ericsson.se (localhost [127.0.0.1]) by nomadiclab.lmf.ericsson.se (Postfix) with ESMTP id 89B15550E0; Thu, 23 May 2013 20:58:40 +0300 (EEST)
Received: from tri62.nomadiclab.com (localhost [127.0.0.1]) by nomadiclab.lmf.ericsson.se (Postfix) with ESMTP id 220CA55098; Thu, 23 May 2013 20:58:40 +0300 (EEST)
Message-ID: <519E58D1.6080600@ericsson.com>
Date: Thu, 23 May 2013 20:58:41 +0300
From: =?ISO-8859-1?Q?Ari_Ker=E4nen?= <ari.keranen@ericsson.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:17.0) Gecko/20130509 Thunderbird/17.0.6
MIME-Version: 1.0
To: Magnus Westerlund <magnus.westerlund@ericsson.com>
References: <518BB81A.8090608@cisco.com> <51965190.10900@ericsson.com> <519E2BF8.7040500@ericsson.com>
In-Reply-To: <519E2BF8.7040500@ericsson.com>
Content-Type: text/plain; charset="ISO-8859-1"; format=flowed
Content-Transfer-Encoding: 8bit
X-Virus-Scanned: ClamAV using ClamSMTP
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrKLMWRmVeSWpSXmKPExsUyM+Jvre6liHmBBjeeaVrc7X3BZDF1+WMW ByaPJUt+Mnl8ufyZLYApissmJTUnsyy1SN8ugSvj6eYfTAUTuCv+71jK3sD4nKOLkZNDQsBE Ytr1JUwQtpjEhXvr2UBsIYFTjBJtK5S7GLmA7A2MEsfun2OESOxmlLjwOAQisY5RYuqyRUwQ iRWMEh07rEBsXgFtiZcfusEmsQioSlxY9A6shk3AXuLmhOvsILaoQLLE5KkrWCDqBSVOznwC ZosImEk8nLAfrJdZIFTiz8U1YLawgJ9E36GdULvSJHbOPMQKYnMK6EgcXnqbEaLeVuLCnOss ELa8RPPW2cwQn6lJXD23iRmiV1Xi6r9XjBMYRWchWT0LSfssJO0LGJlXMbLnJmbmpJcbbmIE Bv3BLb91dzCeOidyiFGag0VJnLdXe2qgkEB6YklqdmpqQWpRfFFpTmrxIUYmDk6pBkY17oBf 4e6Pn+w2sJixtN9FdnLd5xfut54cVflopSPFOC3vff/sK1MOdh9nerzB5toE78zQCyrFU1Ln zty+ou+yjoTObIUWi/Pvjl9ysXsYVbtocd7f2W/7ud7b35hx6czH/z0Jx0V0F5ZJhXfLyq1+ Gvz0//vHS+dtWMm3R8+myPF8ThD7fb9VSizFGYmGWsxFxYkA3EpJ9EgCAAA=
Cc: mmusic <mmusic@ietf.org>, draft-ietf-mmusic-rtsp-nat-evaluation@tools.ietf.org
Subject: Re: [MMUSIC] 1 Week WGLC for draft-ietf-mmusic-rtsp-nat-evaluation-06
X-BeenThere: mmusic@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Multiparty Multimedia Session Control Working Group <mmusic.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mmusic>, <mailto:mmusic-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/mmusic>
List-Post: <mailto:mmusic@ietf.org>
List-Help: <mailto:mmusic-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mmusic>, <mailto:mmusic-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 23 May 2013 18:17:08 -0000

On 5/23/13 5:47 PM, Magnus Westerlund wrote:
> On 2013-05-17 17:49, Ari Keränen wrote:
>
>>
>>
>> 4.9.1.  [TURN] Introduction
>>
>>     On the external side this is
>>     limited to the source address/port pair of the first packet arriving
>>     on the binding.  After the first packet has arrived the mapping is
>>     "locked down" to that address.  Packets from any other source on this
>>     address will be discarded.
>>
>> This doesn't sound right. This behavior was changed (eventually into
>> using permissions) somewhere back in draft-rosenberg-midcom-turn-06. See
>> http://tools.ietf.org/html/rfc5766#section-2.3 for up-to-date behavior.
>> Check also steps 5 & 7 in the next section and section 4.9.4 for more
>> lock down text.
>
> I changed this to:
>
> To prevent DoS attacks on either recipient, the packets forwarded are
> restricted to the specific source address. On the client side it is
> restricted to the source setting up the allocation. On the external side
> this is limited to the source address/port pair that have been given
> permission by the TURN client creating the allocation. Packets from any
> other source on this address will be discarded.
>
> I will shortly submit an updated draft.

Looks good to me. However, also the following sections had some "lock 
down" text that should be updated (see details on my original mail above).


Cheers,
Ari