Re: [tram] A few comments on draft-ietf-tram-stun-pmtud-17.txt

Magnus Westerlund <magnus.westerlund@ericsson.com> Mon, 31 August 2020 09:58 UTC

Return-Path: <magnus.westerlund@ericsson.com>
X-Original-To: tram@ietfa.amsl.com
Delivered-To: tram@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 235693A1171 for <tram@ietfa.amsl.com>; Mon, 31 Aug 2020 02:58:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.102
X-Spam-Level:
X-Spam-Status: No, score=-2.102 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0TGe_YyW0f8k for <tram@ietfa.amsl.com>; Mon, 31 Aug 2020 02:58:26 -0700 (PDT)
Received: from EUR05-AM6-obe.outbound.protection.outlook.com (mail-am6eur05on2072.outbound.protection.outlook.com [40.107.22.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D52D73A11BD for <tram@ietf.org>; Mon, 31 Aug 2020 02:58:25 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=K2ekASdt4EpK7japfjas3S4FpbTo4OzmBNq69xkp1vFOYh5iAV2SqeWj0pG+Fvd0Y9dsH7CLwPVzFESrY3cDtZro8jopIi4yMOwCQT+0BVfoIBd6uynsVCYvk9XE175cyr3HnJ3PO7RbdM+8wZ1C6NJIYKmSzmVJPEf7/rsIC2mI56LF7kegqqLcCT8EYFRV0L7d/qPGS1G/LS2ZFOW8J3z7c+G/XXtKOKlj2U5MBGpcBxpAYtwmZOljdQmtAjBhtDAXEnBoXea1VPvrfDV64+hPpssf96m5Oy4Fmm0b1XYoz7j40E4bnPXKsEi0Z3xjwQJLrrBdRVCMtOgWCfPzsA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=231XT89YIUqu/j0e5p/G0CqAiizSOIfFK1kD4eWLuGQ=; b=dxL9pLiOY78GGeuM9mBIQ25VX5y4cNtyaXqmGsaKSpfY2eCfMHyUqMjJIk6cjN+d3hyKpwiw+T4Jxzk1FhSAEBzk2Ey5WjPcEizGt6OvUAiHf6qaSDi0jeLMa9sVAdH3+WOi460k0OKOjM7HqhjzJtECACsI5mBk8771XzBKsRiB794nmwe5NW6VScqDnXxIqcP8uRX23qt/lXdK7eIviVIk42qFpnhokzZmL4UyWcX+HI2QyAdacemDIB4PsU7n6rZhdjmiBaAMUjsE8R3xsfa2SFZV4Bh1xlN/U3L3t26X37DdE0hAbl6j0nebgKXfXTm66wLmmbVYrUyBAUc2HA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=231XT89YIUqu/j0e5p/G0CqAiizSOIfFK1kD4eWLuGQ=; b=Ei0/wSBGGGTqDDr7RcBlnSwLKvh9Pzh3R4eysuzaz1fvA3o6LQwlUKDYVWpC02kNsqJySGydiEZ32c68y51aPaXRQlLs1DmlpXI1gLTwWdWCn2NHbKQH6lX2DTK43IxuF5RiCcf5A+lDEVvDm+0IYyHz/zUpXlLyZ73eE/BXvH4=
Received: from HE1PR0702MB3772.eurprd07.prod.outlook.com (2603:10a6:7:8e::14) by HE1PR0702MB3628.eurprd07.prod.outlook.com (2603:10a6:7:83::32) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3348.7; Mon, 31 Aug 2020 09:58:20 +0000
Received: from HE1PR0702MB3772.eurprd07.prod.outlook.com ([fe80::b56f:9a8e:3399:aaa3]) by HE1PR0702MB3772.eurprd07.prod.outlook.com ([fe80::b56f:9a8e:3399:aaa3%7]) with mapi id 15.20.3348.013; Mon, 31 Aug 2020 09:58:20 +0000
From: Magnus Westerlund <magnus.westerlund@ericsson.com>
To: "gorry@erg.abdn.ac.uk" <gorry@erg.abdn.ac.uk>, "tram@ietf.org" <tram@ietf.org>, "fegarrid=40cisco.com@dmarc.ietf.org" <fegarrid=40cisco.com@dmarc.ietf.org>
CC: "gorry@abdn.ac.uk" <gorry@abdn.ac.uk>
Thread-Topic: [tram] A few comments on draft-ietf-tram-stun-pmtud-17.txt
Thread-Index: AQHWWeITVyPEwYXhNkGopbvGaLdb06kmg0IAgAFFmYCAF/0PAIASgNIA
Date: Mon, 31 Aug 2020 09:58:19 +0000
Message-ID: <03d60cddfa8e9a057e497c893a575b1241156eb5.camel@ericsson.com>
References: <7c201e29-1a63-39ed-cdd9-3b8b9ac383e6@erg.abdn.ac.uk> <860e8240-ce51-5407-4187-92478262f87c@erg.abdn.ac.uk> <179FB260-1FAC-419B-B5F4-86F850177C97@cisco.com> <04b71d3e-1c79-cdc1-5b20-906732ffa768@erg.abdn.ac.uk> <025EEF1A-A751-4A45-A36F-70CCC043255C@cisco.com>
In-Reply-To: <025EEF1A-A751-4A45-A36F-70CCC043255C@cisco.com>
Accept-Language: sv-SE, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-mailer: Evolution 3.28.5-0ubuntu0.18.04.2
authentication-results: erg.abdn.ac.uk; dkim=none (message not signed) header.d=none;erg.abdn.ac.uk; dmarc=none action=none header.from=ericsson.com;
x-originating-ip: [192.176.1.82]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 66b458c8-0c8d-427e-7452-08d84d9463f2
x-ms-traffictypediagnostic: HE1PR0702MB3628:
x-microsoft-antispam-prvs: <HE1PR0702MB3628E7802B6DC65958F16DDD95510@HE1PR0702MB3628.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: e8+oCJwny3+wYGMWX3LJhmYQHEY/kR4B2xu/PDpgzjxI7IODlY2DAWP7zNjjOluZeg3LECsUxyEQnQ1q8bgOl+zUi5YATc9LA1lQ7Bsld8yfRXG0bqXHdRA9vNovHaGveqNlhOxDhiljb5a1LIzRuoIkRmdy6gpUMknvx1hybpA8c/DhImijCfleHRXUTMLd7Nfw081sm8lGslkXTngry9ByOf5OFfSnS8J+Q9OCOsNqf0VqNG6R2odv+wB9fpMLuenU4aEVd6DvNRXE0/xvvSgTppdu0ZyA/d59Q2sREmMQLOSxP1BuouAZx39bFXl/skSkWneQlC49Rhzr0aQjCYlJyn3SOrCnevBbDC7aWKTMriHkt/eS4IxLCxFf0no3GSYQJLnBMU7a5x5z3MOkNA5yRDHF+ckSb+bBMQANXFI7Se1ZPenJ3tOpjtitsjexUsS/89kywt5rmgAd05dSDQ==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:HE1PR0702MB3772.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(39860400002)(396003)(136003)(366004)(346002)(376002)(110136005)(316002)(8936002)(296002)(8676002)(83380400001)(71200400001)(6486002)(66446008)(64756008)(66556008)(66476007)(76116006)(4326008)(2616005)(966005)(26005)(86362001)(6506007)(53546011)(2906002)(6512007)(91956017)(66946007)(44832011)(186003)(36756003)(5660300002)(478600001)(99106002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: NeOGyXaBYknnJ3ZKpJJsMIE/JiUs1GVmouMhhbbH5SypRcbSsMIG3LJGzwWv7RNoAJKPK2Ki/AnKE6AqKggmg+W8IklXWFZhutMxUhX4XxxUjM4S5exV4V5+J32y30BBBAw4l8ytQIunbfStA+7gFEVuxOChe46fqW8YbGjYp8mz/JfTTjzuFF66hmB2siqd9ODEwXQ4u/yIedw+9WsoOWzPVu87gFVgz+fx3XG7VILwiOT1bAtWbDI3piLiWNxlcceyuWHvbUbvO+ZuxuTu3LAT307O/gDFg6FPl/1ZHQMrt137fELSGZhAmWcWvgFjl4QOxwuvWWTrrgcJSnwyQpDZp7c5gzfhVmwLJ/6Nl/+0rlJGmdTTdfeRl9j+8ZQWG9qb3aIpMMtLlhqf+UcSWpT7HW0prm9nBjFEypNRjXFGzx5jBHiclIuS+PVqgRydFCMrrVA+sozJjZuvnvPuVyIkHDtJnuotLKnQ2YgR3gJl/3Auj8ald1EWRqjksn8clLQ96Ce10BqMc0LdbwTQiguSmCWgUKUGg21bUqUEWWZFLB9Q4aQqks1axOlunCZXNtuEkDSTKPiISikz26H9nJ+icvh3h01EZCYGqIaRybw7MSyb2drb1QcoIAWU7aCIYrwQf3AEsFafPrzN0pz0Lw==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <AA318C25F9BFF7498BE2C36E339FE5F4@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: HE1PR0702MB3772.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 66b458c8-0c8d-427e-7452-08d84d9463f2
X-MS-Exchange-CrossTenant-originalarrivaltime: 31 Aug 2020 09:58:19.8668 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: n4hJbgn3BcYEF88l4aRRrjUdQPTkUU7L4LMRSABrSmp4zeNDYYaxQiknLYzfp18qNC0LoqhyUYdK9c222r1evi51STcIlQGJGN1McvoUD94=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: HE1PR0702MB3628
Archived-At: <https://mailarchive.ietf.org/arch/msg/tram/bLc_1ANyirciChoXywHIHRhWiNI>
Subject: Re: [tram] A few comments on draft-ietf-tram-stun-pmtud-17.txt
X-BeenThere: tram@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Discussing the creation of a Turn Revised And Modernized \(TRAM\) WG, which goal is to consolidate the various initiatives to update TURN and STUN." <tram.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tram>, <mailto:tram-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/tram/>
List-Post: <mailto:tram@ietf.org>
List-Help: <mailto:tram-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tram>, <mailto:tram-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 31 Aug 2020 09:58:29 -0000

Hi Felipe,

draft-ietf-tsvwg-datagram-plpmtud is in AUTH48 currently. Adding an
informational reference to your draft will result in it being published with a
draft reference. 

The expectation has always been that the RFC for tsvwg-datagram-plpmtud will be
referenced in the future by additional specific mechanism using what is
specified. 

So I am hesistant to add a reference in this stage as I see limited utility of
the reference that will require sufficient knowledge to find the future RFC for
the tram draft. 

Can you please provide a specific proposal for text for what you want to add if
you still think it is a good idea to add a informative reference. 

Cheers

Magnus Westerlund

On Wed, 2020-08-19 at 15:24 +0000, Felipe Garrido (fegarrid) wrote:
> Hi Gorry,
>  
> Version 18 has been published with the changes mentioned below.  To make sure
> readers are aware, can you add an informative reference to stun-pmtud in the
> tsvwg-datagram-plpmtud draft?
>  
> Thanks,
> -Felipe
>  
> From: Gorry Fairhurst <gorry@erg.abdn.ac.uk>
> Date: Tuesday, August 4, 2020 at 5:05 AM
> To: "Felipe Garrido (fegarrid)" <fegarrid@cisco.com>om>, "tram@ietf.org" <
> tram@ietf.org>
> Cc: "gorry@abdn.ac.uk" <gorry@abdn.ac.uk>
> Subject: Re: [tram] A few comments on draft-ietf-tram-stun-pmtud-17.txt
>  
>  
> On 03/08/2020 14:39, Felipe Garrido (fegarrid) wrote:
> > Hi Gorry,
> >  
> > Thank you for the comments. Responses are in-line.
> >  
> > Thanks,
> > -Felipe
> >  
> > From: tram <tram-bounces@ietf.org> on behalf of Gorry Fairhurst <
> > gorry@erg.abdn.ac.uk>
> > Date: Tuesday, July 14, 2020 at 9:24 AM
> > To: "tram@ietf.org" <tram@ietf.org>
> > Cc: "gorry@abdn.ac.uk" <gorry@abdn.ac.uk>
> > Subject: [tram] A few comments on draft-ietf-tram-stun-pmtud-17.txt
> >  
> > I had a look at draft-ietf-tram-stun-pmtud-17 with respect to the last
> > comments, and saw some changes and I have a few comments. These comments are
> > sent to the TRAM mailing list,
> > Gorry
> > ---
> > Section 2 does not discuss the frequency of the probe. This is a congestion
> > control case, and the method needs to assert some guidance/requirements on
> > the probing. Do probe packets count against cwnd when using this method?
> > 
> > In section 4.1.
> > I think this is misleading, and not a feature of the simple method:
> > “   Note: Routers can be configured to clear the DF bit or ignore the DF
> >    bit which can be difficult or impossible to detect if reassembly
> >    occurs prior to receiving the packet, rendering PLPMTUD inaccurate.
> > “
> > - I wouldn’t call this inaccurate? If the path contains a link-layer (or
> > tunnel or anything) that fragments and reassembles - then the path MTU is
> > whatever size that assembly is performed to. It has always been this way, if
> > links fragment and reassemble, IP uses the reassembled size.
> > 
> > 
> > --
> > Updated the Note as follows.
> > “   Note: Routers can be configured to clear the DF bit or ignore the DF
> >    bit which can be difficult or impossible to detect if reassembly
> >    occurs prior to receiving the packet.”
> >  
> 
> Sure. I'd actually suggest /might be configured/ to /can be configured/... I'm
> not sure any RFC should do this according to the spec.
> 
> > In section 4.2.2.  Receiving an ICMP Packet
> > This ID currently recommends “ Validation SHOULD be performed on the ICMP
> >    packet as specified in [RFC8085].”
> > - Since this is a method above UDP, I think this implicitly also checks the
> > UDP port information, hence this recommendation actually is an unavoidable
> > consequence when using a normal stack - if you have one that forwards ICMP
> > to the socket.
> > This becomes a requirement (or is always true) in dplpmtud:
> > - “Any received PTB message MUST be validated before it is used to update
> > the PLPMTU discovery information”.
> > - Should this be a requirement in this spec, to avoid off-path attack?
> > 
> > _______________________________________________
> > tram mailing list
> > tram@ietf.org
> > https://www.ietf.org/mailman/listinfo/tram
-- 
Cheers

Magnus Westerlund 


----------------------------------------------------------------------
Networks, Ericsson Research
----------------------------------------------------------------------
Ericsson AB                 | Phone  +46 10 7148287
Torshamnsgatan 23           | Mobile +46 73 0949079
SE-164 80 Stockholm, Sweden | mailto: magnus.westerlund@ericsson.com
----------------------------------------------------------------------