Re: [sami] A new draft on state migration use cases is submitted.

Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de> Sun, 09 October 2011 16:01 UTC

Return-Path: <j.schoenwaelder@jacobs-university.de>
X-Original-To: sami@ietfa.amsl.com
Delivered-To: sami@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 35BDC21F8B1C for <sami@ietfa.amsl.com>; Sun, 9 Oct 2011 09:01:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -100.349
X-Spam-Level:
X-Spam-Status: No, score=-100.349 tagged_above=-999 required=5 tests=[BAYES_50=0.001, HELO_EQ_DE=0.35, MIME_8BIT_HEADER=0.3, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id HTHvfM8LbTJ3 for <sami@ietfa.amsl.com>; Sun, 9 Oct 2011 09:01:54 -0700 (PDT)
Received: from hermes.jacobs-university.de (hermes.jacobs-university.de [212.201.44.23]) by ietfa.amsl.com (Postfix) with ESMTP id 837D621F8B17 for <sami@ietf.org>; Sun, 9 Oct 2011 09:01:54 -0700 (PDT)
Received: from localhost (demetrius4.jacobs-university.de [212.201.44.49]) by hermes.jacobs-university.de (Postfix) with ESMTP id 8771820D06; Sun, 9 Oct 2011 18:01:53 +0200 (CEST)
X-Virus-Scanned: amavisd-new at jacobs-university.de
Received: from hermes.jacobs-university.de ([212.201.44.23]) by localhost (demetrius4.jacobs-university.de [212.201.44.32]) (amavisd-new, port 10024) with ESMTP id vPkkRlSrK8TZ; Sun, 9 Oct 2011 18:01:52 +0200 (CEST)
Received: from elstar.local (elstar.jacobs.jacobs-university.de [10.50.231.133]) by hermes.jacobs-university.de (Postfix) with ESMTP id 0369E20D00; Sun, 9 Oct 2011 18:01:52 +0200 (CEST)
Received: by elstar.local (Postfix, from userid 501) id C35A71B17CF0; Sun, 9 Oct 2011 18:01:38 +0200 (CEST)
Date: Sun, 09 Oct 2011 18:01:38 +0200
From: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
To: "刘茗(研六 福州)" <lium@ruijie.com.cn>
Message-ID: <20111009160138.GB99820@elstar.local>
References: <CAB+71L3btz_h8Lkm9jW-WHUeS4=K-Jq-r9mmX94=NdHiepkJ-Q@mail.gmail.com> <2CE4AB2F9CD06543A3F2B0FE76661E12125C8295@fzex.ruijie.com.cn>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <2CE4AB2F9CD06543A3F2B0FE76661E12125C8295@fzex.ruijie.com.cn>
User-Agent: Mutt/1.5.21 (2010-09-15)
Cc: A tao <yangjingtao@gmail.com>, "sami@ietf.org" <sami@ietf.org>
Subject: Re: [sami] A new draft on state migration use cases is submitted.
X-BeenThere: sami@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: Juergen Schoenwaelder <j.schoenwaelder@jacobs-university.de>
List-Id: State Migration <sami.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sami>, <mailto:sami-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sami>
List-Post: <mailto:sami@ietf.org>
List-Help: <mailto:sami-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sami>, <mailto:sami-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 09 Oct 2011 16:01:55 -0000

On Sun, Oct 09, 2011 at 01:41:24PM +0000, 刘茗(研六 福州) wrote:
> One of our customers, the leader of online shopping provider in china, have the same requirement.  They run VMs on the power x86 machine with KVM hypervisor. For some security reasons, they applied the ACLs through the Linux’s IPtable running on the Hypervisor. But when the VM floating , the IPtable profile can not be migrated to the other machine. So they hope the switch can replace the IPTable  and can migrates the ACL profiles for the VM when floating .

The switches really have nothing to do with ACLs sitting in the
hypervisor. Making the switches responsible for migrating the ACLs
seems broken to me.

/js

-- 
Juergen Schoenwaelder           Jacobs University Bremen gGmbH
Phone: +49 421 200 3587         Campus Ring 1, 28759 Bremen, Germany
Fax:   +49 421 200 3103         <http://www.jacobs-university.de/>