Re: [nat66] Comments on draft-mrw-nat66-12

Fred Baker <fred@cisco.com> Wed, 16 March 2011 04:58 UTC

Return-Path: <fred@cisco.com>
X-Original-To: nat66@core3.amsl.com
Delivered-To: nat66@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id E9F213A677E for <nat66@core3.amsl.com>; Tue, 15 Mar 2011 21:58:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -110.447
X-Spam-Level:
X-Spam-Status: No, score=-110.447 tagged_above=-999 required=5 tests=[AWL=0.152, BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id E9rYp0tSOr7e for <nat66@core3.amsl.com>; Tue, 15 Mar 2011 21:58:26 -0700 (PDT)
Received: from sj-iport-1.cisco.com (sj-iport-1.cisco.com [171.71.176.70]) by core3.amsl.com (Postfix) with ESMTP id 62DE63A6774 for <nat66@ietf.org>; Tue, 15 Mar 2011 21:58:26 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=fred@cisco.com; l=412; q=dns/txt; s=iport; t=1300251592; x=1301461192; h=subject:mime-version:from:in-reply-to:date:cc:message-id: references:to:content-transfer-encoding; bh=MxxAatIn5AiejeLNDvMSwLWfUsvBAjjMIB3KE0236cM=; b=Dt1l1T/KUxvEFYTn1v3X1SYm75X7KL313NgSs9IRWeQRuwHTu9JZHfvs Eb/Pe6+wCsWy5AX3yGJJSgTDT9Go0DCwdRASl7wvj4v0q5cVy2dX7YnrC xzUl9lP401/MFX8Q7/sTXwRVeJp0OUR3le/e4Hrnm758P1f48hFDOUxbi Q=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AvsEAHPgf02tJV2Y/2dsb2JhbACmDXekH5xShWIEhTCHL4NO
X-IronPort-AV: E=Sophos;i="4.63,192,1299456000"; d="scan'208";a="414823312"
Received: from rcdn-core-1.cisco.com ([173.37.93.152]) by sj-iport-1.cisco.com with ESMTP; 16 Mar 2011 04:59:52 +0000
Received: from stealth-10-32-244-221.cisco.com (stealth-10-32-244-221.cisco.com [10.32.244.221]) by rcdn-core-1.cisco.com (8.14.3/8.14.3) with ESMTP id p2G4xlUi009462; Wed, 16 Mar 2011 04:59:51 GMT
Received: from [127.0.0.1] by stealth-10-32-244-221.cisco.com (PGP Universal service); Tue, 15 Mar 2011 21:59:51 -0700
X-PGP-Universal: processed; by stealth-10-32-244-221.cisco.com on Tue, 15 Mar 2011 21:59:51 -0700
Mime-Version: 1.0 (Apple Message framework v1082)
From: Fred Baker <fred@cisco.com>
In-Reply-To: <B647DC46-D255-407E-B67B-A3C630E8B0BA@apple.com>
Date: Tue, 15 Mar 2011 21:59:33 -0700
Message-Id: <47CC6E82-1B5E-47DE-86AE-954924A53BB4@cisco.com>
References: <20110314063002.28048.29694.idtracker@localhost> <19F3A4CD-F39C-4F17-A6E9-7AA8AFBC6B3B@cisco.com> <CF8367A6-F303-43D7-99C6-D40D1DD5D5D9@free.fr> <125BC580-ED43-40EE-B6B9-FD88557C35B9@apple.com> <758DD037-9DC2-4A1E-BEAE-7E99CBED6D3A@cisco.com> <5E3E1015-9750-4ADA-91D9-F10FFFDB2BD0@apple.com> <B4FD874E-1AC2-49DF-A7C0-D1D48B940292@cisco.com> <3B1E3A80-B4A8-4DF0-B345-168BAD532C6E@apple.com> <4C14147C-03C5-48BC-A182-55DB298F2113@cisco.com> <B647DC46-D255-407E-B67B-A3C630E8B0BA@apple.com>
To: james woodyatt <jhw@apple.com>
X-Mailer: Apple Mail (2.1082)
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Cc: NAT66 HappyFunBall <nat66@ietf.org>
Subject: Re: [nat66] Comments on draft-mrw-nat66-12
X-BeenThere: nat66@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: "List for discussion of IPv6-to-IPv6 NAT." <nat66.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/nat66>, <mailto:nat66-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/nat66>
List-Post: <mailto:nat66@ietf.org>
List-Help: <mailto:nat66-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/nat66>, <mailto:nat66-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Mar 2011 04:58:28 -0000

On Mar 15, 2011, at 6:42 PM, james woodyatt wrote:

> I am talking about the implications for firewalls and PCP-capable hosts deployed behind site multi-homing NPTv6 systems as described in section 2.4 of your draft.

They will be exactly the same as any other firewall. Since the feature doesn't change the ports, PCP will turn them on or off, exactly as it does with any other firewall.