Re: [spring] SRv6 Network Programming - ICMP Source Address Selection

Ron Bonica <rbonica@juniper.net> Tue, 07 January 2020 18:07 UTC

Return-Path: <rbonica@juniper.net>
X-Original-To: spring@ietfa.amsl.com
Delivered-To: spring@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4F62B12013C for <spring@ietfa.amsl.com>; Tue, 7 Jan 2020 10:07:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=juniper.net header.b=gOjMTc3O; dkim=pass (1024-bit key) header.d=juniper.net header.b=W7Wi+NbO
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id n1i_KMHtXR2F for <spring@ietfa.amsl.com>; Tue, 7 Jan 2020 10:07:11 -0800 (PST)
Received: from mx0a-00273201.pphosted.com (mx0a-00273201.pphosted.com [208.84.65.16]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 041E912012E for <spring@ietf.org>; Tue, 7 Jan 2020 10:07:10 -0800 (PST)
Received: from pps.filterd (m0108158.ppops.net [127.0.0.1]) by mx0a-00273201.pphosted.com (8.16.0.42/8.16.0.42) with SMTP id 007HwhMi026709; Tue, 7 Jan 2020 10:07:09 -0800
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; h=from : to : cc : subject : date : message-id : references : in-reply-to : content-type : mime-version; s=PPS1017; bh=Z0Eg91TjDP0qvgk2voY2j7NT6s5FWqpy6SYtuCldlI0=; b=gOjMTc3O5xnF715n8/crZevMfY2PwQ1N56HYU+FNIBkPVdQ9ze2RYWt2IzPSrwTfN/L/ Tk55If3a5Niv5xOChwzNAypUDaIPbMP3S+2BmwVYrccuXCeRitDDrSZoG5QQQTuhLxj+ zBoIGOvqFilq8REpfKUWYpIlVdJfc2pSuIP2HqGxu8ibJkuF6f4TpX258BJuOF9wlXvo Lur0OOC9qm2XfrICzXqe9lrGDXzo2iNftIomu0O/gTQVLXr3M3sf1ARJY9P7nBNrWzkv iQacuRyaqg0vP3aqasG1OM27ZS2c30M7g/SkgvYWhTiOSoOZPpnlWjRuoZLgO6rAvQsc vA==
Received: from nam04-co1-obe.outbound.protection.outlook.com (mail-co1nam04lp2055.outbound.protection.outlook.com [104.47.45.55]) by mx0a-00273201.pphosted.com with ESMTP id 2xaq9v5bxx-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 07 Jan 2020 10:07:09 -0800
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=URTIR5LkJs+4f5X7AvOLZi6f6ZOkm76zMWaVLEtOJ/fLs/v+afIJlBa+4/llqIrHX2/RnTwpDKmamHOhtc3ZB0ByV2rGZ3UzphkLxBkovXBKydMRQXP6zWhhwJ3JvwP5eGsxic6FmlrBcJ1VEgBOYSJXmrvfODu37DBee9mF0fzJ4nbcmVn6qAJpP/YhEs86h3d+X3ZBTqwwhVD8N34h/qGZ256j+NGHlKa0oXWii+hMMHNcViSK8I5vhNhQorT5qrhX85d/qu4dzwFSKrNgr4SlCV8sHUQoiCxZp/QSp9cwUYD55dkg4xvx5+KP2g7RSMVwXPJU933vKX3z79vCqA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Z0Eg91TjDP0qvgk2voY2j7NT6s5FWqpy6SYtuCldlI0=; b=PbyguGmLDMdADoCGGE8pJNq0V299c9Oa43rybT6sHyVvdr3q0MuI3PeVLIlTjsBcTapyVqaasJLozW9lO3v3l10/SSPS7f7fZaR2RY7ivmqBRqf5Yn8Kf/hlAFTbrzUkI0bbzmN0NMT7lLE0ElNW+/M7rpZIPRbK0EtKj3ZW4GPRci/EP9UJL7PjnJoJ4S5c8wo3l/hPSpBGtqSsmDZXFbuQMtgcv6kC009sn1roD92Lh1Vh9zRCHKKvuvZ2dnDrW+c7n6cLB/HjyMpRnGZhdtb6Cm/uy79XvRWj0Tcj9IQKMPXyYErnXmmuNLxFGZBhSg6EnrvJR3eADDbOS4vbFw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=juniper.net; dmarc=pass action=none header.from=juniper.net; dkim=pass header.d=juniper.net; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Z0Eg91TjDP0qvgk2voY2j7NT6s5FWqpy6SYtuCldlI0=; b=W7Wi+NbOslZ2VAKjONhPdgrzLENmhJhjpr7QZw5xEZ4YQ++eLLo51KYZ+DbORzRHuEF820wJYDTQ0+X1lH2STlxCSUTwIaBbWhUB1Dm5F4Ix6F0qwwxzwqUhmwlYZtEtjtHzVyTU10RTXGm8I4OX+2uaRmgaTF8wz1gwca83gNs=
Received: from BN7PR05MB3938.namprd05.prod.outlook.com (52.132.216.30) by BN7PR05MB6401.namprd05.prod.outlook.com (20.176.179.214) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2623.6; Tue, 7 Jan 2020 18:07:04 +0000
Received: from BN7PR05MB3938.namprd05.prod.outlook.com ([fe80::f826:68df:3aa7:4864]) by BN7PR05MB3938.namprd05.prod.outlook.com ([fe80::f826:68df:3aa7:4864%5]) with mapi id 15.20.2623.008; Tue, 7 Jan 2020 18:07:04 +0000
From: Ron Bonica <rbonica@juniper.net>
To: "Pablo Camarillo (pcamaril)" <pcamaril@cisco.com>
CC: SPRING WG <spring@ietf.org>
Thread-Topic: [spring] SRv6 Network Programming - ICMP Source Address Selection
Thread-Index: AQHVt1sjI5E9vezZDUu0pc5hCyLTq6fFADeQgBI8Q4CACFa2YA==
Content-Class:
Date: Tue, 07 Jan 2020 18:07:04 +0000
Message-ID: <BN7PR05MB39386FA6A2666370FF07FAA7AE3F0@BN7PR05MB3938.namprd05.prod.outlook.com>
References: <B91AA98B-F605-4C6B-AFAF-C9FDEA703460@cisco.com> <BN7PR05MB5699B27F84C5E8051028D97AAE2C0@BN7PR05MB5699.namprd05.prod.outlook.com> <44F0ED35-5684-4594-BB29-BDCC193284A4@cisco.com>
In-Reply-To: <44F0ED35-5684-4594-BB29-BDCC193284A4@cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Enabled=True; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SiteId=bea78b3c-4cdb-4130-854a-1d193232e5f4; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Owner=rbonica@juniper.net; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_SetDate=2020-01-07T18:07:02.1571015Z; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Name=Juniper Business Use Only; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Application=Microsoft Azure Information Protection; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_ActionId=e3c16843-032c-4ac6-977e-a9c0c2a4413b; MSIP_Label_0633b888-ae0d-4341-a75f-06e04137d755_Extended_MSFT_Method=Automatic
dlp-product: dlpe-windows
dlp-version: 11.3.2.8
dlp-reaction: no-action
x-originating-ip: [108.28.233.91]
x-ms-publictraffictype: Email
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: ec1a8835-cec3-426e-b837-08d7939c66b8
x-ms-traffictypediagnostic: BN7PR05MB6401:
x-microsoft-antispam-prvs: <BN7PR05MB64019EC73A6A52BF1552B5B2AE3F0@BN7PR05MB6401.namprd05.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 027578BB13
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(376002)(136003)(366004)(346002)(396003)(39860400002)(199004)(189003)(51444003)(2906002)(66556008)(66476007)(55016002)(71200400001)(186003)(26005)(52536014)(316002)(64756008)(9686003)(6916009)(4326008)(53546011)(6506007)(5660300002)(66446008)(86362001)(33656002)(8676002)(478600001)(66946007)(7696005)(8936002)(76116006)(81166006)(81156014); DIR:OUT; SFP:1102; SCL:1; SRVR:BN7PR05MB6401; H:BN7PR05MB3938.namprd05.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: juniper.net does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: DdwPgNsMmY+yHTyIQidj9RUBH2iBa7fW1WNRcEibA+kzXrrfWHYOjkIXBI2nqlcFgANJ0qLND69lGsXPco4mW2zWI6Sp2byN6NdTg08GFdVZPsiCwzq+hQVLpu4w+k/zZX2POh5fXGj+72uo99DYqxzzptDkGHimMtts9QKhJAXxirVMcwBs4uZtzoLmdMSgpT3AK88WFpO3oNPlJ14SXwEeAnQu1I3cTPGsMJULwzH02QlRVEzi57gxOmLufGGFzFTCFJDcFyT04BVwHa2YEKhGKieLKfgUdDIvnP8OHk5XV6I3BXGsbS4aakJVQlopgXI54eCWC6kU6ApXNBXEh8eInu8XAo1gPRT6Zs04o45eUetavJbaqDNxfW2LesRNE0Pjpf9ouS+V4MSbmc2Xt6NR36+BkTxox9hko0ay6j/U9Iou6VFsiKQIWbHRbFw4M/PBVB8KY+pzQaMumTcty+suFhRmsK6ND5dQdv+NO4VZVKEgUYOGYv4PoYdRXRD3
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_BN7PR05MB39386FA6A2666370FF07FAA7AE3F0BN7PR05MB3938namp_"
MIME-Version: 1.0
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-Network-Message-Id: ec1a8835-cec3-426e-b837-08d7939c66b8
X-MS-Exchange-CrossTenant-originalarrivaltime: 07 Jan 2020 18:07:04.2278 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: /h32MMFAYzDyQDbix4AGpuPcOpHsyjwFAIjVrosUnPFqjCxu4Cnfb/OwX9qM+JEVEIzXmU5eSGlNiFz376gZ6g==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN7PR05MB6401
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:6.0.138, 18.0.572 definitions=2020-01-07_06:2020-01-07, 2020-01-07 signatures=0
X-Proofpoint-Spam-Details: rule=outbound_spam_notspam policy=outbound_spam score=0 spamscore=0 bulkscore=0 phishscore=0 adultscore=0 impostorscore=0 clxscore=1015 priorityscore=1501 malwarescore=0 lowpriorityscore=0 mlxlogscore=999 mlxscore=0 suspectscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-1910280000 definitions=main-2001070141
Archived-At: <https://mailarchive.ietf.org/arch/msg/spring/9o-zzwsp_0XcdSXwMBw6YIjHSaA>
Subject: Re: [spring] SRv6 Network Programming - ICMP Source Address Selection
X-BeenThere: spring@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Source Packet Routing in NetworkinG \(SPRING\)" <spring.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/spring>, <mailto:spring-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/spring/>
List-Post: <mailto:spring@ietf.org>
List-Help: <mailto:spring-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/spring>, <mailto:spring-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 07 Jan 2020 18:07:13 -0000

Pablo,

Let me try to ask the question another way:


  1.  Is it generally acceptable for a SID to appear in the source address field of an IPv6 header?
  2.  Can an exception be made for ICMP messages?

I think that the answer to the first question is "no", because doing so would break ICMP. Think about what would happen if:


  *   Node S sends a packet to Node D with a SID S as its source address.
  *   Node Q is an intermediate node on the path from Node S to Node D. For some reason, Node Q cannot forward the packet.
  *   Node Q sends an ICMP message to Node S. The ICMP destination address is SID S.
  *   The ICMP message arrives at Node A
  *   Node A discards the ICMP message, because the payload is ICMP

It might be OK to make an exception for ICMP messages. This is because RFC 4443 forbids sending an ICMP message in response to another ICMP message. However, I am not entirely sure that this is a good idea. One day in the future, some protocol other than ICMP may try send a response to the source address of the ICMP message.

                                                                                     Ron




Juniper Business Use Only
From: Pablo Camarillo (pcamaril) <pcamaril@cisco.com>
Sent: Tuesday, January 7, 2020 4:18 AM
To: Ron Bonica <rbonica@juniper.net>
Cc: SPRING WG <spring@ietf.org>
Subject: Re: [spring] SRv6 Network Programming - ICMP Source Address Selection

Ron,

It's good to see agreement on the fact that SRH follows RFC4443 Section 2.2 with respect to how the ICMP Source Address is selected.

Can you please point me to the text in draft-ietf-spring-srv6-network-programming that changes the behavior below from RFC4443 Section 2.2? I believe there is no such text.

Thanks,
Pablo.

From: Ron Bonica <rbonica@juniper.net<mailto:rbonica@juniper.net>>
Date: Saturday, 21 December 2019 at 20:59
To: "Pablo Camarillo (pcamaril)" <pcamaril@cisco.com<mailto:pcamaril@cisco.com>>
Cc: "spring@ietf.org<mailto:spring@ietf.org>" <spring@ietf.org<mailto:spring@ietf.org>>
Subject: RE: [spring] SRv6 Network Programming - ICMP Source Address Selection

Pablo,

Section 2.2 of RFC 4443 offers the following options:

"   (a) If the message is a response to a message sent to one of the
       node's unicast addresses, the Source Address of the reply MUST be
       that same address.

   (b) If the message is a response to a message sent to any other
       address, such as

       - a multicast group address,
       - an anycast address implemented by the node, or
       - a unicast address that does not belong to the node

      the Source Address of the ICMPv6 packet MUST be a unicast address
      belonging to the node. "

So, the question boils down to whether you consider a SID to be one of the node's unicast addresses. If so, the answer is a). If not, the answer is b).

So, which is it?

                                                    Happy Holidays,
                                                         Ron





Juniper Business Use Only
From: Pablo Camarillo (pcamaril) <pcamaril@cisco.com<mailto:pcamaril@cisco.com>>
Sent: Friday, December 20, 2019 12:30 PM
To: Ron Bonica <rbonica@juniper.net<mailto:rbonica@juniper.net>>
Cc: spring@ietf.org<mailto:spring@ietf.org>
Subject: Re: [spring] SRv6 Network Programming - ICMP Source Address Selection

Ron,

I guess that draft-ietf-6man-segment-routing-header does not contain any explicit text about it because it is not needed.
Instead draft-ietf-6man-segment-routing-header contains a reference to RFC4443 that details in section 2.2 how to select it.

There is no text in draft-ietf-spring-srv6-network-programming that changes such behavior.

Happy Holidays,
Pablo.

From: spring <spring-bounces@ietf.org<mailto:spring-bounces@ietf.org>> on behalf of Ron Bonica <rbonica=40juniper.net@dmarc.ietf.org<mailto:rbonica=40juniper.net@dmarc.ietf.org>>
Date: Thursday, 19 December 2019 at 14:59
To: "Pablo Camarillo (pcamaril)" <pcamaril@cisco.com<mailto:pcamaril@cisco.com>>, "spring@ietf.org<mailto:spring@ietf.org>" <spring@ietf.org<mailto:spring@ietf.org>>
Subject: Re: [spring] SRv6 Network Programming - ICMP Source Address Selection

Pablo,

Can you provide a specific reference into draft-ietf-6man-segment-routing-header? I can't find the answer to my question in there.

                                                                                         Ron





Juniper Business Use Only
From: Pablo Camarillo (pcamaril) <pcamaril@cisco.com<mailto:pcamaril@cisco.com>>
Sent: Thursday, December 19, 2019 6:47 AM
To: Ron Bonica <rbonica@juniper.net<mailto:rbonica@juniper.net>>; spring@ietf.org<mailto:spring@ietf.org>
Subject: Re: SRv6 Network Programming - ICMP Source Address Selection

Ron,

This is exactly the same as in the SRH.
There is no text in draft-ietf-spring-srv6-network-programming that changes this.

Cheers,
Pablo.

From: Ron Bonica <rbonica@juniper.net<mailto:rbonica@juniper.net>>
Date: Monday, 9 December 2019 at 23:48
To: "Pablo Camarillo (pcamaril)" <pcamaril@cisco.com<mailto:pcamaril@cisco.com>>, SPRING WG <spring@ietf.org<mailto:spring@ietf.org>>, 6man <6man@ietf.org<mailto:6man@ietf.org>>
Subject: RE: SRv6 Network Programming - ICMP Source Address Selection

Pablo,

Section 2.2 of RFC 4443 offers two options. If you think that a SID is a unicast address, the first option is applicable. If you think that a SID is not a unicast address, the second option is applicable.

Which did you choose?

                                                                         Ron



Juniper Business Use Only
From: Pablo Camarillo (pcamaril) <pcamaril@cisco.com<mailto:pcamaril@cisco.com>>
Sent: Monday, December 9, 2019 10:18 AM
To: Ron Bonica <rbonica@juniper.net<mailto:rbonica@juniper.net>>; SPRING WG <spring@ietf.org<mailto:spring@ietf.org>>; 6man <6man@ietf.org<mailto:6man@ietf.org>>
Subject: Re: SRv6 Network Programming - ICMP Source Address Selection

Ron,

As you pointed out in your email, RFC4443 Section 2.2 is very clear about how to select the source address.
draft-ietf-spring-srv6-network-programming does not change this.

Thanks,
Pablo.

From: ipv6 <ipv6-bounces@ietf.org<mailto:ipv6-bounces@ietf.org>> on behalf of Ron Bonica <rbonica=40juniper.net@dmarc.ietf.org<mailto:rbonica=40juniper.net@dmarc.ietf.org>>
Date: Friday, 6 December 2019 at 17:40
To: SPRING WG <spring@ietf.org<mailto:spring@ietf.org>>, 6man <6man@ietf.org<mailto:6man@ietf.org>>
Subject: SRv6 Network Programming - ICMP Source Address Selection

Authors,

When an SRv6 node sends an ICMP message, how does it select the ICMP message's source address?

Section 2.2 of RFC 4443 offers two options. If you think that a SID is a unicast address, the first option is applicable. If you think that a SID is not a unicast address, the second option is applicable.

                                                                     Ron


Juniper Business Use Only