Re: [sunset4] CGN document for consideration

"George, Wes" <wesley.george@twcable.com> Fri, 27 July 2012 21:05 UTC

Return-Path: <wesley.george@twcable.com>
X-Original-To: sunset4@ietfa.amsl.com
Delivered-To: sunset4@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AA86F11E808A for <sunset4@ietfa.amsl.com>; Fri, 27 Jul 2012 14:05:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.521
X-Spam-Level:
X-Spam-Status: No, score=-0.521 tagged_above=-999 required=5 tests=[AWL=-0.058, BAYES_00=-2.599, HELO_EQ_MODEMCABLE=0.768, HOST_EQ_MODEMCABLE=1.368]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UOsfci1hmRyH for <sunset4@ietfa.amsl.com>; Fri, 27 Jul 2012 14:05:55 -0700 (PDT)
Received: from cdpipgw02.twcable.com (cdpipgw02.twcable.com [165.237.59.23]) by ietfa.amsl.com (Postfix) with ESMTP id DCC5E21F8463 for <sunset4@ietf.org>; Fri, 27 Jul 2012 14:05:54 -0700 (PDT)
X-SENDER-IP: 10.136.163.15
X-SENDER-REPUTATION: None
X-IronPort-AV: E=Sophos;i="4.77,669,1336363200"; d="scan'208";a="398652502"
Received: from unknown (HELO PRVPEXHUB06.corp.twcable.com) ([10.136.163.15]) by cdpipgw02.twcable.com with ESMTP/TLS/RC4-MD5; 27 Jul 2012 17:05:45 -0400
Received: from PRVPEXVS03.corp.twcable.com ([10.136.163.27]) by PRVPEXHUB06.corp.twcable.com ([10.136.163.15]) with mapi; Fri, 27 Jul 2012 17:05:50 -0400
From: "George, Wes" <wesley.george@twcable.com>
To: Reinaldo Penno <repenno@cisco.com>, "sunset4@ietf.org" <sunset4@ietf.org>
Date: Fri, 27 Jul 2012 17:05:47 -0400
Thread-Topic: CGN document for consideration
Thread-Index: Ac0n5gon3kbCiaUERKKQWfa6RmaDIBEVJl2Q
Message-ID: <DCC302FAA9FE5F4BBA4DCAD46569377917487E2225@PRVPEXVS03.corp.twcable.com>
References: <CBC5AB36.48FD%repenno@cisco.com>
In-Reply-To: <CBC5AB36.48FD%repenno@cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: Re: [sunset4] CGN document for consideration
X-BeenThere: sunset4@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: sunset4 working group discussion list <sunset4.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sunset4>, <mailto:sunset4-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sunset4>
List-Post: <mailto:sunset4@ietf.org>
List-Help: <mailto:sunset4-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sunset4>, <mailto:sunset4-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 27 Jul 2012 21:05:55 -0000

Reinaldo -

A comment about this draft:
In section 3.2, you mention immediate purge of mapping when a TCP RST is received. While it's not a unique issue to this recommendation, I think there's a security consideration around this - an attacker could cause a lot of state-mapping churn on the CGN (in addition to the obvious impact to the customer session itself) by sending random TCP RSTs to ports on the external IP address block of the CGN. Therefore it may not be advisable to recommend this behavior without some sort of rate-limiting or a discussion of ways to distinguish legitimate TCP RSTs that do legitimately occur from maliciously initiated RSTs.


Thanks,

Wes George, speaking as an individual



> -----Original Message-----
> From: sunset4-bounces@ietf.org [mailto:sunset4-bounces@ietf.org] On
> Behalf Of Reinaldo Penno
> Sent: Tuesday, May 01, 2012 6:01 PM
> To: sunset4@ietf.org
> Subject: [sunset4] CGN document for consideration
>
> Hi,
>
> I would like to submit this document to the WG for consideration.
>
> http://tools.ietf.org/html/draft-penno-behave-rfc4787-5382-5508-bis-02
>
> I'm assuming that port allocation method drafts should be submitted to
> this WG.
>
> Thanks,
>
> Reinaldo
>
>
> _______________________________________________
> sunset4 mailing list
> sunset4@ietf.org
> https://www.ietf.org/mailman/listinfo/sunset4

This E-mail and any of its attachments may contain Time Warner Cable proprietary information, which is privileged, confidential, or subject to copyright belonging to Time Warner Cable. This E-mail is intended solely for the use of the individual or entity to which it is addressed. If you are not the intended recipient of this E-mail, you are hereby notified that any dissemination, distribution, copying, or action taken in relation to the contents of and attachments to this E-mail is strictly prohibited and may be unlawful. If you have received this E-mail in error, please notify the sender immediately and permanently delete the original and any copy of this E-mail and any printout.