Re: [spring] Seeking comments for draft-dunbar-sr-sdwan-over-hybrid-networks: is it appropriate for not-directly connect SDWAN edges to use GRE/VxLAN header bits to indicate the desired SR path?

Linda Dunbar <linda.dunbar@futurewei.com> Thu, 18 July 2019 16:16 UTC

Return-Path: <linda.dunbar@futurewei.com>
X-Original-To: spring@ietfa.amsl.com
Delivered-To: spring@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DCEC7120872; Thu, 18 Jul 2019 09:16:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=futurewei.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 88X29YhdFXi3; Thu, 18 Jul 2019 09:16:05 -0700 (PDT)
Received: from NAM02-BL2-obe.outbound.protection.outlook.com (mail-bl2nam02on072e.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe46::72e]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6C5B5120887; Thu, 18 Jul 2019 09:16:05 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=AebAScaxQuFQLIarIW79r1a3x1EnJqfN06qAMGF85R2Tfp81RlyYLZlcUFG9cJQfNyvVOC58SMjBgARD3tP6n5dRxV1Yz7kJH+d/dGVhb5PiqETNUCUSNdKH5Cnm2+t1K0pKF/DHw0XQVm8DyHkjK8LkyF8BXHz1p7d98mrjVost8ZaMzMTkMxxN9WqXHUkmfFq60NFqqWm2iPvzuNDyzuE7obv7NRsbsbST5l+bmta37oiwkOYJJfPLbJvYeDQQRwwtD674oA97psig56xho5wUKHQOCr8qBVoq633r/VsvAtWu3WGAGM2eR8z4sUql+fbMASKLAPkfzib7s2YYAA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=AaNojbOLMduBF8wS+YHPCh2sgTsxaQ+nwliEgY1JQMY=; b=a+VirweRyoHzOE1Nxbj5foYLbOT89m/UgISalEO06XFTja58wlYMtzE5S3SouhpyZEpFTpKpTSxcg+0Q7jUl6ihoNLbPTlncEKy/UbcnCz/107gNq9cgPP1xJTEsnGJBX1OlTGaxjg9PIvGFxr4k+Z/J8fu/rZz+wQSHHOlXhqOJtZsLDyDzO8yMQLuoqol57AwJdR/v7xZ9CXJHxCP1UpyhRdOsCtb3FuISSkdcH0Lc9jW/BLg1nKPNt+SyLCLsVqwTCF6Nu++elrI3zMni5vwLP81fd44E4tG+odncmWYCcT5LjrUYCi+wftlDRRrVjKt+LMJJ/HZmFzl7iKAyHA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1;spf=pass smtp.mailfrom=futurewei.com;dmarc=pass action=none header.from=futurewei.com;dkim=pass header.d=futurewei.com;arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Futurewei.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=AaNojbOLMduBF8wS+YHPCh2sgTsxaQ+nwliEgY1JQMY=; b=CEGIWOy7qIyEqXJE1avrbFaf3E9VvQkkgj/LbymGfuvIb6//IkO4mSzi3icMk2319XIcTYxsHnPGFpab167yYtaWMIEjCvBID0PvPvxv+St1l8k4Q1IdW4/1sU5FzulvbVnTAzpmlg4j2iGWHP3SkURxZOJv6yWXk5bOCuebDvI=
Received: from MN2PR13MB3582.namprd13.prod.outlook.com (10.255.238.139) by MN2PR13MB3215.namprd13.prod.outlook.com (20.179.151.13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2094.10; Thu, 18 Jul 2019 16:16:03 +0000
Received: from MN2PR13MB3582.namprd13.prod.outlook.com ([fe80::e068:8461:62d7:e0c1]) by MN2PR13MB3582.namprd13.prod.outlook.com ([fe80::e068:8461:62d7:e0c1%7]) with mapi id 15.20.2094.009; Thu, 18 Jul 2019 16:16:03 +0000
From: Linda Dunbar <linda.dunbar@futurewei.com>
To: Jeff Tantsura <jefftant.ietf@gmail.com>, spring <spring-bounces@ietf.org>, SPRING WG <spring@ietf.org>, "徐小虎(义先)" <xiaohu.xxh@alibaba-inc.com>
Thread-Topic: [spring] Seeking comments for draft-dunbar-sr-sdwan-over-hybrid-networks: is it appropriate for not-directly connect SDWAN edges to use GRE/VxLAN header bits to indicate the desired SR path?
Thread-Index: AdU12gZxiC6o7DmCSja15PZWT4zSoAAAVQwAABGhPIAAHfM+gAEu9MiQAAJ32QAAiRpZwA==
Date: Thu, 18 Jul 2019 16:16:02 +0000
Message-ID: <MN2PR13MB358203FF79A59C59A460CE5185C80@MN2PR13MB3582.namprd13.prod.outlook.com>
References: <MN2PR13MB35821DA403CCE784CB3B065D85F60@MN2PR13MB3582.namprd13.prod.outlook.com> <MN2PR13MB3582CAA473AD49E7357B6CD085F60@MN2PR13MB3582.namprd13.prod.outlook.com> <c4f2a5ff-cac2-4d5f-9f9d-2dd810009384.xiaohu.xxh@alibaba-inc.com> <53f3a00b-2dc1-4762-99c3-de7f57b592d2@Spark> <MN2PR13MB358219A35895BE96008D1DDB85CF0@MN2PR13MB3582.namprd13.prod.outlook.com> <b1f72412-c484-41ad-b5f9-1922458819c6@Spark>
In-Reply-To: <b1f72412-c484-41ad-b5f9-1922458819c6@Spark>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=linda.dunbar@futurewei.com;
x-originating-ip: [12.111.81.80]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: ae570ec5-295b-456b-b87c-08d70b9b3ae3
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600148)(711020)(4605104)(1401327)(2017052603328)(7193020); SRVR:MN2PR13MB3215;
x-ms-traffictypediagnostic: MN2PR13MB3215:
x-ms-exchange-purlcount: 5
x-microsoft-antispam-prvs: <MN2PR13MB3215BB463763790961D5EAAF85C80@MN2PR13MB3215.namprd13.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 01026E1310
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(4636009)(366004)(396003)(376002)(346002)(136003)(39840400004)(199004)(189003)(52536014)(6506007)(53936002)(71200400001)(71190400001)(86362001)(14444005)(102836004)(25786009)(81166006)(14454004)(6436002)(7696005)(236005)(5660300002)(9686003)(8676002)(99286004)(66066001)(53546011)(6246003)(7736002)(66446008)(66556008)(66476007)(6306002)(74316002)(76176011)(446003)(66946007)(76116006)(64756008)(2906002)(316002)(110136005)(186003)(66574012)(478600001)(68736007)(606006)(229853002)(54896002)(8936002)(966005)(55016002)(44832011)(33656002)(3846002)(6116002)(486006)(26005)(256004)(81156014)(790700001)(11346002)(476003); DIR:OUT; SFP:1102; SCL:1; SRVR:MN2PR13MB3215; H:MN2PR13MB3582.namprd13.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: futurewei.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: 4Y973k6jks0vla9CCoH4m4QIL+F19edgg/pVUHzW0qEt1fnm74lJKg7WXDTDmDbgCjq77H7sZu03gaK5K/LWjuWLEtkTA1Yy4vWb8Y2FHYyPalUH5sBxv5sxkC8FOLlescBOP/V1mQ/oevstOwz6mrl37XKyF774baBVzibDf6VnUAZER+XszqegacsYtFbBfYKh7PrK5aMFQDq5W6sojQl2/MFY5v09Lps0CwPbQnNQkRILIBY88hbtrHmd3m1y48S5I8Gn2ZuD7GQ2l4wH8TPXCZViVNBUz14xdeOQ02PO46RrjKwejQTxxSUvmo3OsKuW4B/MCOVFoYQQNw0gVAuro/Vw7rL6bWkSHjpAi1K0iX4E9Fov2UofImUDbfcrHTC16Nt1yOohqDNpYdOwR4xqb+Z4Zwr/781ffsEWskY=
Content-Type: multipart/alternative; boundary="_000_MN2PR13MB358203FF79A59C59A460CE5185C80MN2PR13MB3582namp_"
MIME-Version: 1.0
X-OriginatorOrg: Futurewei.com
X-MS-Exchange-CrossTenant-Network-Message-Id: ae570ec5-295b-456b-b87c-08d70b9b3ae3
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Jul 2019 16:16:02.9434 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 0fee8ff2-a3b2-4018-9c75-3a1d5591fedc
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ldunbar@futurewei.com
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR13MB3215
Archived-At: <https://mailarchive.ietf.org/arch/msg/spring/0bmXy2eTvPwbwc-R6_jnGQu6FlU>
Subject: Re: [spring] Seeking comments for draft-dunbar-sr-sdwan-over-hybrid-networks: is it appropriate for not-directly connect SDWAN edges to use GRE/VxLAN header bits to indicate the desired SR path?
X-BeenThere: spring@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Source Packet Routing in NetworkinG \(SPRING\)" <spring.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spring>, <mailto:spring-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spring/>
List-Post: <mailto:spring@ietf.org>
List-Help: <mailto:spring-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spring>, <mailto:spring-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 18 Jul 2019 16:16:14 -0000

Jeff,

For SDWAN case, the Source node and Destination nodes (a.k.a. SDWAN edge nodes) are IP based.

So it should be reversed, IP segments -> SR segments which include both SRv6 & MPLS-SR -> IP segments

Linda

From: Jeff Tantsura <jefftant.ietf@gmail.com>
Sent: Monday, July 15, 2019 5:48 PM
To: spring <spring-bounces@ietf.org>; SPRING WG <spring@ietf.org>; 徐小虎(义先) <xiaohu.xxh@alibaba-inc.com>; Linda Dunbar <linda.dunbar@futurewei.com>
Subject: RE: [spring] Seeking comments for draft-dunbar-sr-sdwan-over-hybrid-networks: is it appropriate for not-directly connect SDWAN edges to use GRE/VxLAN header bits to indicate the desired SR path?

Linda,

What you want is to use native MPLS when available and encapsulate MPLS packets in IP/UDP when you need to travers IP, you destination in the imposed IP header would be that of the next SR capable device as described in draft-ietf-mpls-sr-over-ip.

Cheers,
Jeff
On Jul 15, 2019, 3:24 PM -0700, Linda Dunbar <linda.dunbar@futurewei.com<mailto:linda.dunbar@futurewei.com>>, wrote:


Jeff,

The draft-ietf-mpls-sr-over-ip only has MPLS packets being tunneled by IP, but not reversed (IP packets tunneled over MPLS).

Do you think it worthwhile to add some similar sections (of course with different content), such as Forwarding entry Construction, forwarding procedures as in draft-ietf-mpls-sr-over-ip?

Linda

From: Jeff Tantsura <jefftant.ietf@gmail.com<mailto:jefftant.ietf@gmail.com>>
Sent: Tuesday, July 09, 2019 4:03 PM
To: spring <spring-bounces@ietf.org<mailto:spring-bounces@ietf.org>>; Linda Dunbar <linda.dunbar@futurewei.com<mailto:linda.dunbar@futurewei.com>>; SPRING WG <spring@ietf.org<mailto:spring@ietf.org>>; 徐小虎(义先) <xiaohu.xxh@alibaba-inc.com<mailto:xiaohu.xxh@alibaba-inc.com>>
Subject: Re: [spring] Seeking comments for draft-dunbar-sr-sdwan-over-hybrid-networks: is it appropriate for not-directly connect SDWAN edges to use GRE/VxLAN header bits to indicate the desired SR path?

+1

take a look at draft-ietf-mpls-sr-over-ip

Cheers,
Jeff
On Jul 8, 2019, 11:45 PM -0700, 徐小虎(义先) <xiaohu.xxh@alibaba-inc.com<mailto:xiaohu.xxh@alibaba-inc.com>>, wrote:
Hi Linda,

Why not directly use the MPLSoUDP encapsulation to carry the B-SID label so as to indicate the preferred path? For more details, please read https://tools.ietf.org/html/draft-dukes-spring-sr-for-sdwan-02#section-7.3<https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.ietf.org%2Fhtml%2Fdraft-dukes-spring-sr-for-sdwan-02%23section-7.3&data=02%7C01%7Clinda.dunbar%40futurewei.com%7Ce2ef92e9de2143db0be208d709768846%7C0fee8ff2a3b240189c753a1d5591fedc%7C1%7C0%7C636988277015484955&sdata=hasaujqJuyv%2FvF2rnj8Gv%2FM%2BUVAUN5q2A6djQQBvl5g%3D&reserved=0>

Best regards,
Xiaohu

------------------------------------------------------------------
From:Linda Dunbar <linda.dunbar@futurewei.com<mailto:linda.dunbar@futurewei.com>>
Send Time:2019年7月9日(星期二) 06:26
To:Linda Dunbar <linda.dunbar@futurewei.com<mailto:linda.dunbar@futurewei.com>>; SPRING WG <spring@ietf.org<mailto:spring@ietf.org>>
Subject:Re: [spring] Seeking comments for draft-dunbar-sr-sdwan-over-hybrid-networks: is it appropriate for not-directly connect SDWAN edges to use GRE/VxLAN header bits to indicate the desired SR path?

Sorry, I meant to ask:

When the SDWAN edge nodes are NOT directly connected to the PEs of SR domain, is it appropriate for SDWAN edge nodes to use GRE/VxLAN header bits to indicate the desired SR Path?

Linda

From: spring <spring-bounces@ietf.org<mailto:spring-bounces@ietf.org>> On Behalf Of Linda Dunbar
Sent: Monday, July 08, 2019 5:11 PM
To: SPRING WG <spring@ietf.org<mailto:spring@ietf.org>>
Subject: [spring] Seeking comments for draft-dunbar-sr-sdwan-over-hybrid-networks: is it appropriate for not-directly connect SDWAN edges to use GRE/VxLAN header bits to indicate the desired SR path?

SD-WAN, as described by ONUG (Open Network User Group), is about pooling WAN bandwidth from multiple service providers to get better WAN bandwidth management, visibility & control.
Because of the ephemeral property of the selected Cloud DCs, an enterprise or its network service provider may not have the direct links to the Cloud DCs that are optimal for hosting the enterprise’s specific workloads/Apps. Under those circumstances, SD-WAN is a very flexible choice to interconnect the enterprise on-premises data centers & branch offices to its desired Cloud DCs...
However, SD-WAN paths over public internet can have unpredictable performance, especially over long distances and cross state/country boundaries. Therefore, it is highly desirable to place as much as possible the portion of SD-WAN paths over service provider VPN (e.g. enterprise’s existing VPN) that have guaranteed SLA and to minimize the distance/segments over public internet.

https://datatracker.ietf.org/doc/draft-dunbar-sr-sdwan-over-hybrid-networks/<https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-dunbar-sr-sdwan-over-hybrid-networks%2F&data=02%7C01%7Clinda.dunbar%40futurewei.com%7Ce2ef92e9de2143db0be208d709768846%7C0fee8ff2a3b240189c753a1d5591fedc%7C1%7C0%7C636988277015484955&sdata=oPw5CZJK%2BtRB68%2FbGa9m%2BIhS8WgweEIb1Ne2yIRGnkY%3D&reserved=0> describes a method to enforce a SD-WAN path’s head-end selected route traversing through a list of specific nodes of multiple network segments without requiring the nodes in each network segments to have the intelligence (or maintaining states) of selecting next hop or next segments.

When a SR domain has multiple PEs with ports facing the external networks (such as the public internet or LTE termination), SD-WAN paths can traverse the SR domain via different ingress/egress PEs resulting in different E2E performance.

Even with the same ingress/egress, some flows may need different segments across the SR Domain. It is not practical, or even possible, for PEs to determine which Apps’ flows should egress.
Segment Routing can be used to steer packets (or path) to traverse the explicit egress node, or explicit segments through the SR Domain based on the SLA requested by the SD-WAN head-end nodes.

When the SDWAN edge nodes are directly connected to the PEs of SR domain, is it appropriate for SDWAN edge nodes to use GRE/VxLAN header bits to indicate the desired SR Path?

We are looking for feedback, criticisms, or suggestion on the the proposed approach.

Thank you,
Linda
_______________________________________________
spring mailing list
spring@ietf.org<mailto:spring@ietf.org>
https://www.ietf.org/mailman/listinfo/spring<https://nam03.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Fspring&data=02%7C01%7Clinda.dunbar%40futurewei.com%7Ce2ef92e9de2143db0be208d709768846%7C0fee8ff2a3b240189c753a1d5591fedc%7C1%7C0%7C636988277015494945&sdata=Fd1INBJQ4sjPR43b425zROXFlvrw%2BYQ3f%2FeCHh31Q6o%3D&reserved=0>