Re: [OPSEC] OPSEC control plane protection draft

Rodney Dunn <rodunn@cisco.com> Tue, 17 August 2010 01:34 UTC

Return-Path: <rodunn@cisco.com>
X-Original-To: opsec@core3.amsl.com
Delivered-To: opsec@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id D098C3A6781 for <opsec@core3.amsl.com>; Mon, 16 Aug 2010 18:34:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level:
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZmYwDV2y+e4T for <opsec@core3.amsl.com>; Mon, 16 Aug 2010 18:34:10 -0700 (PDT)
Received: from av-tac-rtp.cisco.com (hen.cisco.com [64.102.19.198]) by core3.amsl.com (Postfix) with ESMTP id 3952A3A67C0 for <opsec@ietf.org>; Mon, 16 Aug 2010 18:34:09 -0700 (PDT)
X-TACSUNS: Virus Scanned
Received: from rooster.cisco.com (localhost.cisco.com [127.0.0.1]) by av-tac-rtp.cisco.com (8.13.8+Sun/8.13.8) with ESMTP id o7H1Yhga013288; Mon, 16 Aug 2010 21:34:43 -0400 (EDT)
Received: from rtp-rodunn-8714.cisco.com (rtp-rodunn-8714.cisco.com [10.116.190.133]) by rooster.cisco.com (8.13.8+Sun/8.13.8) with ESMTP id o7H1Ye2D022221; Mon, 16 Aug 2010 21:34:40 -0400 (EDT)
Message-ID: <4C69E72F.6090608@cisco.com>
Date: Mon, 16 Aug 2010 21:34:39 -0400
From: Rodney Dunn <rodunn@cisco.com>
Organization: Cisco Systems Inc.
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:1.9.2.8) Gecko/20100802 Thunderbird/3.1.2
MIME-Version: 1.0
To: "Smith, Donald" <Donald.Smith@qwest.com>
References: <45c8c21a1003260906j41580868p12466e6ed42ef3d0@mail.gmail.com> <4BACE777.3010000@juniper.net> <ba2fbc6f1003261027u5c62b7b4od135d00144a83a02@mail.gmail.com> <B01905DA0C7CDC478F42870679DF0F10091D90BD15@qtdenexmbm24.AD.QINTRA.COM>
In-Reply-To: <B01905DA0C7CDC478F42870679DF0F10091D90BD15@qtdenexmbm24.AD.QINTRA.COM>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Cc: "'draft-dugal-opsec-protect-control-plane@tools.ietf.org'" <draft-dugal-opsec-protect-control-plane@tools.ietf.org>, "'opsec@ietf.org'" <opsec@ietf.org>
Subject: Re: [OPSEC] OPSEC control plane protection draft
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: rodunn@cisco.com
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/opsec>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 17 Aug 2010 01:34:16 -0000

Donald,

First thanks for the comment. It's a good one. We actually originally 
had it with a default drop for the all IP and default classes. However, 
after a good bit of discussion we (both Cisco and Juniper) felt that we 
should soften it up just a bit. We agreed to add the explicit match for 
the ALLIP class so it could be monitored and then tightened down further.

We realized there were various opinions on how that should be done.

ie:

http://www.cisco.com/web/about/security/intelligence/coppwp_gs.html


Thanks,
Rodney





On 8/16/10 5:16 PM, Smith, Donald wrote:
>
> For undesirables in JTK's paper here he specifically did a deny ip any any at the end of the cpp policy for that.
>
> http://aharp.ittns.northwestern.edu/papers/copp.html
>
> The default term for juniper is log and discard.
>
> There isn't a deny ip any any in the draft.
>
>
>
> (coffee != sleep)&  (!coffee == sleep)
> Donald.Smith@qwest.com gcia
>
>> -----Original Message-----
>> From: opsec-bounces@ietf.org [mailto:opsec-bounces@ietf.org]
>> On Behalf Of Rob Bird
>> Sent: Friday, March 26, 2010 11:28 AM
>> To: David Dugal
>> Cc: draft-dugal-opsec-protect-control-plane@tools.ietf.org;
>> opsec@ietf.org
>> Subject: Re: [OPSEC] OPSEC control plane protection draft
>>
>> This is most excellent. I was just advising a customer this
>> morning on this very issue (again).
>>
>> I look forward to working on this.
>> Rob
>>
>> -
>> Rob Bird, Chief Technology Officer
>> Red Lambda, Inc.
>> "Network security at global scale"
>> www.redlambda.com
>>
>>        On Mar 26, 2010 1:03 PM, "David Dugal"
>> <ddugal@juniper.net>  wrote:
>>
>>        -----BEGIN PGP SIGNED MESSAGE-----
>>        Hash: SHA1
>>
>>        Hi Richard.
>>
>>        Thank you very much for the scrutiny, analysis and feedback.  As
>>        mentioned during my brief presentation, our hope is that this
>>        recommendation by example will provide awareness of a
>> possible attack
>>        surface occasionally overlooked, especially by smaller or newer
>>        installations.
>>
>>        I appreciate the feedback and will enhance the draft to
>> make reference
>>        to cryptographic security, as well as attempt to make
>> the document IP
>>        version agnostic.
>>
>>        Thank you for your support, both in carefully reading
>> the document, and
>>        for your willingness to have our draft taken under the
>> OPSEC WG wing.
>>
>>        - ---
>>        David G. Dugal                           Support:
>> +1-408-745-9500
>>        Security Incident Response Team          Direct:
>> +1-978-589-0719
>>        Juniper Networks                         Mobile:
>> +1-603-377-1162
>>        Westford, MA, USA                        PGP Key: 0xAB6E02A5
>>
>>
>>        On Fri Mar 26 2010 09:06:40 GMT-0700 (Pacific Daylight
>> Time), Richard
>>        Graveman<rfgraveman@gmail.com>  proclaimed ...
>>
>>
>>        >  David,
>>        >
>>        >  I read the draft carefully after the meeting and
>> realize that my
>>        >  comments missed the...
>>
>>        >  .
>>        >
>>        -----BEGIN PGP SIGNATURE-----
>>        Version: GnuPG v1.4.10 (MingW32)
>>
>>        iEYEARECAAYFAkus53cACgkQh59lzatuAqVE9wCgh53mgxNRPWUztlI27aOITHRr
>>        2zMAoPb5y3phm260P1zSoDu0LSbUjNcN
>>        =kitD
>>        -----END PGP SIGNATURE-----
>>
>>
>>        _______________________________________________
>>        OPSEC mailing list
>>        OPSEC@ietf.org
>>        https://www.ietf.o...
>>
>>
>
> This communication is the property of Qwest and may contain confidential or
> privileged information. Unauthorized use of this communication is strictly
> prohibited and may be unlawful.  If you have received this communication
> in error, please immediately notify the sender by reply e-mail and destroy
> all copies of the communication and any attachments.
> _______________________________________________
> OPSEC mailing list
> OPSEC@ietf.org
> https://www.ietf.org/mailman/listinfo/opsec