[quicwg/base-drafts] Support IP Anycast with server IP+Port renegotiation (#560)

Christian Huitema <notifications@github.com> Mon, 29 May 2017 01:18 UTC

Return-Path: <bounces+848413-a050-quic-issues=ietf.org@sgmail.github.com>
X-Original-To: quic-issues@ietfa.amsl.com
Delivered-To: quic-issues@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5DF021294C8 for <quic-issues@ietfa.amsl.com>; Sun, 28 May 2017 18:18:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.901
X-Spam-Level:
X-Spam-Status: No, score=-2.901 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_32=0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Zk0s9_1XnrFr for <quic-issues@ietfa.amsl.com>; Sun, 28 May 2017 18:18:04 -0700 (PDT)
Received: from o5.sgmail.github.com (o5.sgmail.github.com [192.254.113.10]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 058F21294C7 for <quic-issues@ietf.org>; Sun, 28 May 2017 18:18:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com; h=from:reply-to:to:cc:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=9hOOFhIeb2/lxOJGgpAZWenFN40=; b=prNTJuNxUh67twFE M75ilwo+h5R1Yg0aE0trUaMW6E8gd8+QyaB+S9US84r42Fg4o/iFYY1hL1Y5g1Qk NwsorHaqqdShBed7L5Z0Jpm8MzzH9FfCC9MoV0NertRijL8RcuR7Onh/Ffp9UMlo m4lcwVodzTbcGQyM/x9YEQYDA60=
Received: by filter1151p1mdw1.sendgrid.net with SMTP id filter1151p1mdw1-1983-592B76CB-2 2017-05-29 01:18:03.038961146 +0000 UTC
Received: from github-smtp2a-ext-cp1-prd.iad.github.net (github-smtp2a-ext-cp1-prd.iad.github.net [192.30.253.16]) by ismtpd0005p1iad1.sendgrid.net (SG) with ESMTP id EC7b8H7aSnmQcXvh7n9Jdg for <quic-issues@ietf.org>; Mon, 29 May 2017 01:18:03.023 +0000 (UTC)
Date: Sun, 28 May 2017 18:18:02 -0700
From: Christian Huitema <notifications@github.com>
Reply-To: quicwg/base-drafts <reply+0166e4abfe0ef7bc7b5fc332a309d4beebd370bd0270ee4a92cf00000001154338ca92a169ce0dd2a43a@reply.github.com>
To: quicwg/base-drafts <base-drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <quicwg/base-drafts/issues/560@github.com>
Subject: [quicwg/base-drafts] Support IP Anycast with server IP+Port renegotiation (#560)
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_592b76caa5c6f_55093f86f0961c3c724ae"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: huitema
X-GitHub-Recipient: quic-issues
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: quic-issues@ietf.org
X-SG-EID: l64QuQ2uJCcEyUykJbxN122A6QRmEpucztpreh3Pak3J9egDu9pnkSboC/wVe5Dl3h1jzEGDbKOeVa Bk2NQEQGdjclM8Ih4/Xgz4DSByKKTOqjRd/c0BRhke50Zw58WHWcsoHOdLkICxBJzW3iNdgr3lnWs6 9Iea8aNAcCgn8Ggy+fFbt8ExJcXZn/vcVwXWouIePuMDILOspODPcxF0PgRy19OrLoxgTu9yThU+1u c=
Archived-At: <https://mailarchive.ietf.org/arch/msg/quic-issues/pQnXS90RsBUjFkMtE1WnflEcMoM>
X-BeenThere: quic-issues@ietf.org
X-Mailman-Version: 2.1.22
List-Id: Notification list for GitHub issues related to the QUIC WG <quic-issues.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/quic-issues/>
List-Post: <mailto:quic-issues@ietf.org>
List-Help: <mailto:quic-issues-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/quic-issues>, <mailto:quic-issues-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 May 2017 01:18:05 -0000

Many large DNS server deployments rely on IP Anycast for directing UDP requests to the "closest" server. As we consider QUIC for DNS, it would be nice to support the same kind of deployment. However, DNS over QUIC requires server-side state. The instantaneous nature of IP routing could cause anycast packets to be delivered to the "wrong" server - a server instance that does not hold the state for the connection.

This could be solved if after the initial exchange the server indicated an alternative  non-anycast IP address, and maybe an alternative port number. The client could then switch to using that address, assuring then that the QUIC connection would remain stable even if IP routing did change.

There is are obvious security issues, but they can be mitigated. The server indication would need be protected against spoofing, which probably means that it would have to come as a 1-RTT packet. A malicious server could redirect client traffic towards an unsuspecting party, in some kind of DOS attack. This can be mitigated if the client sends a verification packet to the new address, and only starts using the new address for "regular" traffic if the verification packet is acknowledged. 

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/quicwg/base-drafts/issues/560