Re: [tram] FW: New Version Notification for draft-patil-tram-turn-serv-disc-00.txt

Simon Perreault <simon.perreault@viagenie.ca> Tue, 11 February 2014 14:17 UTC

Return-Path: <simon.perreault@viagenie.ca>
X-Original-To: tram@ietfa.amsl.com
Delivered-To: tram@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 844CE1A0381 for <tram@ietfa.amsl.com>; Tue, 11 Feb 2014 06:17:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.449
X-Spam-Level:
X-Spam-Status: No, score=-2.449 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.548, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JN8wtx8IrUuL for <tram@ietfa.amsl.com>; Tue, 11 Feb 2014 06:17:38 -0800 (PST)
Received: from jazz.viagenie.ca (jazz.viagenie.ca [IPv6:2620:0:230:8000::2]) by ietfa.amsl.com (Postfix) with ESMTP id 08D281A032D for <tram@ietf.org>; Tue, 11 Feb 2014 06:17:37 -0800 (PST)
Received: from porto.nomis80.org (ringo.viagenie.ca [IPv6:2620:0:230:c000:3e97:eff:fe0b:dd8a]) by jazz.viagenie.ca (Postfix) with ESMTPSA id 290D240447 for <tram@ietf.org>; Tue, 11 Feb 2014 09:17:37 -0500 (EST)
Message-ID: <52FA3100.60906@viagenie.ca>
Date: Tue, 11 Feb 2014 09:17:36 -0500
From: Simon Perreault <simon.perreault@viagenie.ca>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.3.0
MIME-Version: 1.0
To: tram@ietf.org
References: <20140211051944.2479.50189.idtracker@ietfa.amsl.com> <913383AAA69FF945B8F946018B75898A242ABB49@xmb-rcd-x10.cisco.com>
In-Reply-To: <913383AAA69FF945B8F946018B75898A242ABB49@xmb-rcd-x10.cisco.com>
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 8bit
Subject: Re: [tram] FW: New Version Notification for draft-patil-tram-turn-serv-disc-00.txt
X-BeenThere: tram@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussing the creation of a Turn Revised And Modernized \(TRAM\) WG, which goal is to consolidate the various initiatives to update TURN and STUN." <tram.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tram>, <mailto:tram-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tram/>
List-Post: <mailto:tram@ietf.org>
List-Help: <mailto:tram-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tram>, <mailto:tram-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Feb 2014 14:17:39 -0000

Le 2014-02-11 00:26, Tirumaleswar Reddy (tireddy) a écrit :
> This document describes two mechanisms to auto discover TURN server. Please review and provide your valuable comments.

Nice. A few comments/questions...

1. Does WPAD play any role in this? Why/why not? (DHCP options are often
inaccessible/very hard to get to from end-user applications, namely
browsers.)

2. About the anycast mechanism:

   When a client requires TURN services, it sends a TURN allocate
   request to the assigned anycast address.  The responding TURN anycast
   server puts its own unicast address as the source address in the
   reply message.

That won't work because it won't get through most firewalls and many
NATs. The response's 5-tuple has to be the same as the request's.

I suggest you look into the 300 (Try Alternate) response mechanism. The
response would contain the unicast address in an ALTERNATE-SERVER
attribute. See also RFC 5766 section 2.9.

3. It would be nice to make anycast work with TCP.

4. In the IANA Considerations section, it seems you are requesting a
single IPv4 address and a single IPv6 address. If we want anycast to
work across AS boundaries, we need to request a /24 and a /48,
respectively. I think we want that, so that TURN service can easily be
provided by a third party. (On the other hand, single addresses are
interesting security-wise in that they won't travel very far in BGP.)

Simon
-- 
DTN made easy, lean, and smart --> http://postellation.viagenie.ca
NAT64/DNS64 open-source        --> http://ecdysis.viagenie.ca
STUN/TURN server               --> http://numb.viagenie.ca