RE: Why Scopes? (was: Re: [saad] About saad)

"Michel Py" <michel@arneill-py.sacramento.ca.us> Tue, 21 October 2003 16:09 UTC

Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA24916 for <saad-archive@odin.ietf.org>; Tue, 21 Oct 2003 12:09:23 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1ABz4C-0004Ir-9c for saad-archive@odin.ietf.org; Tue, 21 Oct 2003 12:09:04 -0400
Received: (from exim@localhost) by www1.ietf.org (8.12.8/8.12.8/Submit) id h9LG941M016535 for saad-archive@odin.ietf.org; Tue, 21 Oct 2003 12:09:04 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1ABz4C-0004Ic-3Q for saad-web-archive@optimus.ietf.org; Tue, 21 Oct 2003 12:09:04 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA24870 for <saad-web-archive@ietf.org>; Tue, 21 Oct 2003 12:08:52 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 1ABz4A-0005Vi-00 for saad-web-archive@ietf.org; Tue, 21 Oct 2003 12:09:02 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 1ABz4A-0005Vf-00 for saad-web-archive@ietf.org; Tue, 21 Oct 2003 12:09:02 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1ABz48-0004HN-HX; Tue, 21 Oct 2003 12:09:00 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1ABz3F-00044M-2I for saad@optimus.ietf.org; Tue, 21 Oct 2003 12:08:05 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA24824 for <saad@ietf.org>; Tue, 21 Oct 2003 12:07:53 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 1ABz3D-0005UN-00 for saad@ietf.org; Tue, 21 Oct 2003 12:08:03 -0400
Received: from adsl-209-233-126-65.dsl.scrm01.pacbell.net ([209.233.126.65] helo=arneill-py.sacramento.ca.us) by ietf-mx with esmtp (Exim 4.12) id 1ABz3D-0005SY-00 for saad@ietf.org; Tue, 21 Oct 2003 12:08:03 -0400
Subject: RE: Why Scopes? (was: Re: [saad] About saad)
Date: Tue, 21 Oct 2003 09:07:31 -0700
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Message-ID: <DD7FE473A8C3C245ADA2A2FE1709D90B06C69E@server2003.arneill-py.sacramento.ca.us>
Content-class: urn:content-classes:message
X-MimeOLE: Produced By Microsoft Exchange V6.5.6944.0
Thread-Topic: Why Scopes? (was: Re: [saad] About saad)
Thread-Index: AcOX6w2UcomcC/w0QdWJMQjE6BsuSwAAiDyA
From: "Michel Py" <michel@arneill-py.sacramento.ca.us>
To: "Erik Nordmark" <Erik.Nordmark@sun.com>
Cc: "James Kempf" <kempf@docomolabs-usa.com>, <saad@ietf.org>
Content-Transfer-Encoding: quoted-printable
Sender: saad-admin@ietf.org
Errors-To: saad-admin@ietf.org
X-BeenThere: saad@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/saad>, <mailto:saad-request@ietf.org?subject=unsubscribe>
List-Id: Scope Addressing Architecture Discussion <saad.ietf.org>
List-Post: <mailto:saad@ietf.org>
List-Help: <mailto:saad-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/saad>, <mailto:saad-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: quoted-printable
Content-Transfer-Encoding: quoted-printable

> Erik Nordmark
> Having a conceptual model with 3 top-level classes defined in the
> firewall
> 1. no communication through the firewall
> 2. outbound only
> 3. open
> is simple enough to prevent unintended side-effects of other
> filters.

Even if we could force firewall vendors to do this (which we can't) it's
not flexible enough. A significant part of access control is performed
by regular routers and there we can't pre-define which interface belongs
to which class, it's all configuration that unfortunately can be
SNAFUed.

Michel.


_______________________________________________
Saad mailing list
Saad@ietf.org
https://www1.ietf.org/mailman/listinfo/saad