Re: [shara] port randomization (draft-ymbk-aplusp-03)
Rémi Després <remi.despres@free.fr> Sat, 14 March 2009 10:34 UTC
Return-Path: <remi.despres@free.fr>
X-Original-To: shara@core3.amsl.com
Delivered-To: shara@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix)
with ESMTP id 02DE43A6930 for <shara@core3.amsl.com>;
Sat, 14 Mar 2009 03:34:20 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.468
X-Spam-Level:
X-Spam-Status: No, score=-0.468 tagged_above=-999 required=5 tests=[AWL=-0.018,
BAYES_00=-2.599, HELO_EQ_FR=0.35, MIME_8BIT_HEADER=0.3, WHOIS_MYPRIVREG=1.499]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com
[127.0.0.1]) (amavisd-new, port 10024) with ESMTP id t4Wb16ThO4r2 for
<shara@core3.amsl.com>; Sat, 14 Mar 2009 03:34:18 -0700 (PDT)
Received: from smtp1-g21.free.fr (smtp1-g21.free.fr [212.27.42.1]) by
core3.amsl.com (Postfix) with ESMTP id 986AA3A692C for <shara@ietf.org>;
Sat, 14 Mar 2009 03:34:17 -0700 (PDT)
Received: from smtp1-g21.free.fr (localhost [127.0.0.1]) by smtp1-g21.free.fr
(Postfix) with ESMTP id F2AFC940185; Sat, 14 Mar 2009 11:34:52 +0100 (CET)
Received: from RD-Mac.local (per92-10-88-166-221-144.fbx.proxad.net
[88.166.221.144]) by smtp1-g21.free.fr (Postfix) with ESMTP id E27AA94017B;
Sat, 14 Mar 2009 11:34:49 +0100 (CET)
Message-ID: <49BB87C7.9040501@free.fr>
Date: Sat, 14 Mar 2009 11:32:39 +0100
From: =?ISO-8859-15?Q?R=E9mi_Despr=E9s?= <remi.despres@free.fr>
User-Agent: Thunderbird 2.0.0.19 (Macintosh/20081209)
MIME-Version: 1.0
To: "Jan Zorz @ go6.si" <jan@go6.si>
References: <022a01c9a2ab$fd5abf60$fd736b80@cisco.com><49B91C8B.5010906@go6.si><04a201c9a338$d5ce8f70$fd736b80@cisco.com> <49B9752B.8030407@go6.si> <D109C8C97C15294495117745780657AE0B6BEB6B@ftrdmel1>
<49BB60AF.1010806@go6.si>
In-Reply-To: <49BB60AF.1010806@go6.si>
Content-Type: text/plain; charset=ISO-8859-15; format=flowed
Content-Transfer-Encoding: 7bit
Cc: shara@ietf.org
Subject: Re: [shara] port randomization (draft-ymbk-aplusp-03)
X-BeenThere: shara@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Sharing of an IPv4 Address discussion list <shara.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/shara>,
<mailto:shara-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/shara>
List-Post: <mailto:shara@ietf.org>
List-Help: <mailto:shara-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/shara>,
<mailto:shara-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 14 Mar 2009 10:34:20 -0000
Jan Zorz @ go6.si - le (m/j/a) 3/14/09 8:45 AM: > Pierre, hi. > > pierre.levis@orange-ftgroup.com wrote: >> I'm also wondering, currently how many OSs and how many NATs do >> implement a good randomization function? > Not sure... but rather than port randomization I would prefer to see > dnssec implemented in clients, maybe also combined with dnscurve. DNSsec is better, but hosts have to also support DNS servers that don't have, and therefore port randomization. Note that, if both hosts and DNS have IPv6 addresse, hosts are can randomize on the full range of ephemeral ports (not concerned with Shara mechanisms). >> More generally, in port range solutions we (I include myself) propose >> sophisticated functions that surely make sense. > We have no other option. But, how sophisticated (complex) may we get? > Where is the balance between "good enough" usability and complexity on > the other hand? Full agreement. The proposal than is included in SAM (www.nabble.com/FYI:-draft-despres-sam-02--enclosed-td22493319.html) is intended to be good enough and simpler than the other proposals so far. (Routing is still based on prefixes, and the cyphering function is just a modulo 2^n multiplication by an odd constant of the bits to be scrambled.) >> However, I do believe that, if we want to see vendors rapidly >> implement port range capabilities, we have to agree on a minimum set >> of functionalities that makes it possible to build a viable port >> range solution. > If we want to assure at least minimum compatibility between different > vendors equipment and still have a solution, that makes sense to > customer, then we need to set, what minimum means. I suspect every > vendor will speculate with it's own proprietary features, so we need > to set basics straight. You are perfectly right. Full agreement. Regards, RD
- [shara] port randomization (draft-ymbk-aplusp-03) Dan Wing
- Re: [shara] port randomization (draft-ymbk-aplusp… Gabor.Bajko
- Re: [shara] port randomization (draft-ymbk-aplusp… Dan Wing
- Re: [shara] port randomization (draft-ymbk-aplusp… Randy Bush
- Re: [shara] port randomization (draft-ymbk-aplusp… Jan Zorz @ go6.si
- Re: [shara] port randomization (draft-ymbk-aplusp… teemu.savolainen
- Re: [shara] port randomization (draft-ymbk-aplusp… Dan Wing
- Re: [shara] port randomization (draft-ymbk-aplusp… Jan Zorz @ go6.si
- Re: [shara] port randomization (draft-ymbk-aplusp… pierre.levis
- Re: [shara] port randomization (draft-ymbk-aplusp… Lars Eggert
- Re: [shara] port randomization (draft-ymbk-aplusp… Rémi Denis-Courmont
- Re: [shara] port randomization (draft-ymbk-aplusp… Jan Zorz @ go6.si
- Re: [shara] port randomization (draft-ymbk-aplusp… Jan Zorz @ go6.si
- Re: [shara] port randomization (draft-ymbk-aplusp… Jan Zorz @ go6.si
- Re: [shara] port randomization (draft-ymbk-aplusp… Rémi Després
- Re: [shara] port randomization (draft-ymbk-aplusp… Rémi Després
- Re: [shara] port randomization (draft-ymbk-aplusp… teemu.savolainen
- Re: [shara] port randomization (draft-ymbk-aplusp… MILES DAVID
- Re: [shara] port randomization (draft-ymbk-aplusp… Jan Zorz @ go6.si
- Re: [shara] port randomization (draft-ymbk-aplusp… Dan Wing
- Re: [shara] port randomization (draft-ymbk-aplusp… Jan Zorz @ go6.si
- Re: [shara] port randomization (draft-ymbk-aplusp… Dan Wing
- Re: [shara] port randomization (draft-ymbk-aplusp… Gabor.Bajko
- Re: [shara] port randomization (draft-ymbk-aplusp… Dan Wing
- Re: [shara] port randomization (draft-ymbk-aplusp… Dan Wing
- Re: [shara] port randomization (draft-ymbk-aplusp… pierre.levis
- Re: [shara] port randomization (draft-ymbk-aplusp… Jan Zorz @ go6.si
- Re: [shara] port randomization (draft-ymbk-aplusp… mohamed.boucadair
- Re: [shara] port randomization (draft-ymbk-aplusp… Jan Zorz @ go6.si
- Re: [shara] port randomization (draft-ymbk-aplusp… mohamed.boucadair
- Re: [shara] port randomization (draft-ymbk-aplusp… Jan Zorz @ go6.si
- Re: [shara] port randomization (draft-ymbk-aplusp… mohamed.boucadair