Re: [savnet] A variation of DSAV as a BGP extension

Jari Arkko <jari.arkko@piuha.net> Thu, 24 March 2022 07:38 UTC

Return-Path: <jari.arkko@piuha.net>
X-Original-To: savnet@ietfa.amsl.com
Delivered-To: savnet@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1003A3A10BA for <savnet@ietfa.amsl.com>; Thu, 24 Mar 2022 00:38:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.907
X-Spam-Level:
X-Spam-Status: No, score=-1.907 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JFKgeuXzzkTN for <savnet@ietfa.amsl.com>; Thu, 24 Mar 2022 00:38:40 -0700 (PDT)
Received: from p130.piuha.net (p130.piuha.net [193.234.219.226]) by ietfa.amsl.com (Postfix) with ESMTP id 3AF493A10B3 for <savnet@ietf.org>; Thu, 24 Mar 2022 00:38:40 -0700 (PDT)
Received: from smtpclient.apple (dhcp-9af6.meeting.ietf.org [31.133.154.246]) by p130.piuha.net (Postfix) with ESMTPSA id C0B766600E3; Thu, 24 Mar 2022 09:38:37 +0200 (EET)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 14.0 \(3654.120.0.1.13\))
From: Jari Arkko <jari.arkko@piuha.net>
In-Reply-To: <dcf252ce9dd04cb58fba15d5e5e228dd@ustx2ex-dag1mb5.msg.corp.akamai.com>
Date: Thu, 24 Mar 2022 08:38:36 +0100
Cc: "savnet@ietf.org" <savnet@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <E793BA6D-1808-4C57-9652-56E718804888@piuha.net>
References: <dcf252ce9dd04cb58fba15d5e5e228dd@ustx2ex-dag1mb5.msg.corp.akamai.com>
To: "Lubashev, Igor" <ilubashe=40akamai.com@dmarc.ietf.org>
X-Mailer: Apple Mail (2.3654.120.0.1.13)
Archived-At: <https://mailarchive.ietf.org/arch/msg/savnet/WH5xfIBNSfjHpYLOYAHfake59gs>
Subject: Re: [savnet] A variation of DSAV as a BGP extension
X-BeenThere: savnet@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <savnet.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/savnet>, <mailto:savnet-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/savnet/>
List-Post: <mailto:savnet@ietf.org>
List-Help: <mailto:savnet-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savnet>, <mailto:savnet-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Mar 2022 07:38:45 -0000

Very interesting, thanks Igor!

Jari

> On 22. Mar 2022, at 5.15, Lubashev, Igor <ilubashe=40akamai.com@dmarc.ietf.org> wrote:
> 
> I am glad to see some renewed attention paid to SAV.
> 
> Here is a quick proposal I've made on the topic @ IETF-101.
> https://datatracker.ietf.org/meeting/101/materials/slides-101-rtgwg-sessb-ingress-filtering-for-asymmetric-routing-01
> 
> The quick summary of the above:
> 
> 1. We have a problem today, because we use the same BGP reachability advertisements for two separate purposes: advertising reachability and SAV.
> 
> 2. The proposal is a creation of a new "SAV Allow" SAFI. Advertisements with "SAV Allow" SAFI are never used for forwarding and can only be used for SAV.
> 2a. The advertisements are secured against spoofing by all the usual means that BGP advertisements are secured.
> 2b. "SAV Allow" SAFI advertisements are transitive, unless a route (a regular or "SAV Allow") with the same or a shorter prefix is advertised to a peer. This is because the advertised route already serves "SAV Allow" purpose.
> 2c. Only routers that support "SAV Allow" SAFI get these advertisements.
> 
> 3. The upside is that this seems like it would solve SAV problem and use just a simple BGP extension for it. The downside is that incremental deployment can only start with the routers that are originating the routes -- upgrading an intermediary router does no good, unless all routers between the path originator and itself have been upgraded.
> 3a. Compared to RFC8704, RFC8704 does not solve SAV completely, but it allows for a much looser increment deployment to be useful.
> 
> Happy to discuss this more, of course.
> 
> - Igor
> 
> -- 
> savnet mailing list
> savnet@ietf.org
> https://www.ietf.org/mailman/listinfo/savnet