Re: [rtcweb] Usefulness of ICE-TCP (Was: Comments on draft-ietf-rtcweb-transports-01)

<Markus.Isomaki@nokia.com> Wed, 13 November 2013 20:00 UTC

Return-Path: <Markus.Isomaki@nokia.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8A78C11E81A9 for <rtcweb@ietfa.amsl.com>; Wed, 13 Nov 2013 12:00:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.53
X-Spam-Level:
X-Spam-Status: No, score=-6.53 tagged_above=-999 required=5 tests=[AWL=0.069, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id t8Z5SN8CGJAJ for <rtcweb@ietfa.amsl.com>; Wed, 13 Nov 2013 12:00:36 -0800 (PST)
Received: from mgw-sa02.nokia.com (smtp.nokia.com [147.243.1.48]) by ietfa.amsl.com (Postfix) with ESMTP id 80D4921E814A for <rtcweb@ietf.org>; Wed, 13 Nov 2013 12:00:33 -0800 (PST)
Received: from smtp.mgd.nokia.com ([65.54.30.47]) by mgw-sa02.nokia.com (Sentrion-MTA-4.2.2/Sentrion-MTA-4.2.2) with ESMTP id rADJvZ2a013820 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=OK); Wed, 13 Nov 2013 21:57:36 +0200
Received: from 008-AM1MPN1-043.mgdnok.nokia.com ([169.254.3.74]) by 008-AM1MMR1-013.mgdnok.nokia.com ([2002:4136:1e2f::4136:1e2f]) with mapi id 14.03.0136.001; Wed, 13 Nov 2013 19:57:34 +0000
From: Markus.Isomaki@nokia.com
To: pgiralt@cisco.com
Thread-Topic: [rtcweb] Usefulness of ICE-TCP (Was: Comments on draft-ietf-rtcweb-transports-01)
Thread-Index: Ac7gpqENKxnuBO9vSm6c7jmb7Ls8IQAA4GOAAAAFGRA=
Date: Wed, 13 Nov 2013 19:57:30 +0000
Message-ID: <E44893DD4E290745BB608EB23FDDB7620A115B99@008-AM1MPN1-043.mgdnok.nokia.com>
References: <E44893DD4E290745BB608EB23FDDB7620A115B66@008-AM1MPN1-043.mgdnok.nokia.com> <EC27E18D-9B08-4802-872B-572E866DBF24@cisco.com>
In-Reply-To: <EC27E18D-9B08-4802-872B-572E866DBF24@cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-tituslabs-classifications-30: TLPropertyRoot=Nokia; Confidentiality=Nokia Internal Use Only; Project=None;
x-titus-version: 3.5.9.3
x-headerinfofordlp: None
x-tituslabs-classificationhash-30: VgNFIFU9Hx+/nZJb9Kg7IjbYxkZuTg+u6rJVgTLbWM4NbqZfy4gjZMCCssTX82f1DJN+H7L6SrZ1bBWTkVeBlPloXyJJ826tQWiBJZy/FLKyr44pIl3GN2ob/skI021hEvDQBiRVcWsnEc7DVSDuvnaUL+f3UpFYFnXoNhw24VqYYtrQnA70VSG9mOzLwPZb3tgTmWFB+tEs2VdK7Es6l3qzZiLedaIYxd341EDAAFLOuUXex/6lT/pD6cmPk0ibo/e5HM2AqciWKohWfuvreWQKAKUX0J4hJGnO/0y5XXPMu9S3IDK7D+uaFsYHwojV
x-originating-ip: [10.163.173.36]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Nokia-AV: Clean
Cc: rtcweb@ietf.org
Subject: Re: [rtcweb] Usefulness of ICE-TCP (Was: Comments on draft-ietf-rtcweb-transports-01)
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/rtcweb>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Nov 2013 20:00:43 -0000

Hi Paul,

> >
> > So unless people have data that shows that "UDP blocked but direct TCP
> allowed" is in itself a very rare setup (this is a question, I don't know that
> either), I think ICE-TCP is definitely worthwhile for a WebRTC endpoint to
> support.
> 
> This is actually a very common firewall configuration for enterprise
> customers. Outbound TCP is allowed but UDP is blocked (even if UDP is
> initiated from the inside).
>

Yes. UDP is blocked for sure and so is inbound TCP, so only outbound TCP is usable. However in many enterprises direct outbound TCP is not allowed but connection need to be made via an HTTP proxy. Do you (or someone else) have an estimate how often *direct* outbound TCP connections actually work?
 
> -Paul

Markus