Re: [netmod] I-D Action: draft-ietf-netmod-acl-model-17.txt

Eliot Lear <lear@cisco.com> Wed, 14 March 2018 15:28 UTC

Return-Path: <lear@cisco.com>
X-Original-To: netmod@ietfa.amsl.com
Delivered-To: netmod@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D3F291200B9 for <netmod@ietfa.amsl.com>; Wed, 14 Mar 2018 08:28:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -12.63
X-Spam-Level:
X-Spam-Status: No, score=-12.63 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IsbuVpVlzD5H for <netmod@ietfa.amsl.com>; Wed, 14 Mar 2018 08:28:33 -0700 (PDT)
Received: from rcdn-iport-5.cisco.com (rcdn-iport-5.cisco.com [173.37.86.76]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 423DE127337 for <netmod@ietf.org>; Wed, 14 Mar 2018 08:28:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=5463; q=dns/txt; s=iport; t=1521041309; x=1522250909; h=subject:to:cc:references:from:message-id:date: mime-version:in-reply-to; bh=I7nSNuYQlHBlyQi0UExuAfxkVQijLl7rbnWB6KThcOk=; b=FuU1obb6RCXUWTEjFJrPAd4VTSWIyIO2GPp+zhLgvcWwNoZNufL9usRq ujUJVFGLg/VZ9f1z5Og9UXKeZnLI9rVz421vmmGBlVcMXcsBMi1OKrFni FISdZ0HAikeLayROzV+rm1mPpJxmce2ZBCg8qI8s41j6O+RtwRuhljPBF g=;
X-Files: signature.asc : 488
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0D0AAAtPqla/4ENJK1dGQEBAQEBAQEBAQEBAQcBAQEBAYJadoFVg3iKGo1zggOBFo8UhSKCEwcDhRECgyYhNBgBAgEBAQEBAQJrKIUmAQUjVhALBAoKKgICVwYBDAgBAYUUrHqCJiaESYNxgX0PhS6CFINRgniIDoJiBI5ohFKHHgmDeYFtincHiQuFVpFNgSweOIFSMxoIGxWCfpEOIJADAQEB
X-IronPort-AV: E=Sophos;i="5.47,470,1515456000"; d="asc'?scan'208,217";a="149708400"
Received: from alln-core-9.cisco.com ([173.36.13.129]) by rcdn-iport-5.cisco.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 14 Mar 2018 15:28:28 +0000
Received: from [10.155.124.100] (dhcp-10-155-124-4-124-100.cisco.com [10.155.124.100]) by alln-core-9.cisco.com (8.14.5/8.14.5) with ESMTP id w2EFSRKK012031; Wed, 14 Mar 2018 15:28:28 GMT
To: Mahesh Jethanandani <mjethanandani@gmail.com>, Kent Watsen <kwatsen@juniper.net>
Cc: NETMOD WG <netmod@ietf.org>
References: <152011518004.12021.16209647205835091770@ietfa.amsl.com> <B961C87E-F925-4420-A23E-45BCB6AAA5AC@gmail.com> <18B0636C-36F2-4EF9-B518-04C29D2D3FDD@juniper.net> <40483B35-C929-4754-86F7-89D9FF38DE35@gmail.com> <789CD28A-F375-4392-9A09-5F1FAB135292@juniper.net> <70A81D2E-7038-4D06-B734-4675B30A1DF1@gmail.com>
From: Eliot Lear <lear@cisco.com>
Message-ID: <47c0e4ac-693e-03c0-50ad-34a41526ba4b@cisco.com>
Date: Wed, 14 Mar 2018 08:28:26 -0700
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:52.0) Gecko/20100101 Thunderbird/52.6.0
MIME-Version: 1.0
In-Reply-To: <70A81D2E-7038-4D06-B734-4675B30A1DF1@gmail.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="oc2u7xGmhhN3IPSQaETTrKiVppAm9QNgA"
Archived-At: <https://mailarchive.ietf.org/arch/msg/netmod/3nTyQyQ9MyiRE9Xn22pNNgHDg00>
Subject: Re: [netmod] I-D Action: draft-ietf-netmod-acl-model-17.txt
X-BeenThere: netmod@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: NETMOD WG list <netmod.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/netmod>, <mailto:netmod-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/netmod/>
List-Post: <mailto:netmod@ietf.org>
List-Help: <mailto:netmod-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/netmod>, <mailto:netmod-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Mar 2018 15:28:35 -0000

Hi Mahesh,

Just one point.


On 13.03.18 18:46, Mahesh Jethanandani wrote:
>> <KENT>or how about "The match criteria can be a multiplicity of
>> criteria, all of which must be true for the match to occur.   The
>> match criteria may match against values in the packet header or
>> against vendor-specific metadata about the packet."?   - or something
>> in between?
>
> Or simply as:
>
> “The match criteria allows for definition of packet headers and
> metadata, all of which must be true for the match to occur."

So long as we make clear what the null set means.  To me, that's "match
everything".

Eliot