Re: [v6ops] draft-pref64folks-6man-ra-pref64

Fred Baker <fredbaker.ietf@gmail.com> Wed, 17 October 2018 19:29 UTC

Return-Path: <fredbaker.ietf@gmail.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6CA0B130D7A for <v6ops@ietfa.amsl.com>; Wed, 17 Oct 2018 12:29:22 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Rpdn5Xg8VA2G for <v6ops@ietfa.amsl.com>; Wed, 17 Oct 2018 12:29:18 -0700 (PDT)
Received: from mail-ed1-x52c.google.com (mail-ed1-x52c.google.com [IPv6:2a00:1450:4864:20::52c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 53949130EED for <v6ops@ietf.org>; Wed, 17 Oct 2018 12:29:18 -0700 (PDT)
Received: by mail-ed1-x52c.google.com with SMTP id l14-v6so17015726edq.0 for <v6ops@ietf.org>; Wed, 17 Oct 2018 12:29:18 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=CXUFliJnGrThd8T7cB0/LTDBw0pzi/21/95DEdMriHc=; b=d+zFJByFJR4q2XMhygbR4ph1oz/iX3qJHvJFXuyu4xkFIxUtMIrSg9fKD9a3s96vi/ nhFGIFxa5FuQqpV0VllzS8vdA3p2pjrXjU5hQu8mpYuzg3P8pgg729KvT/Zc2r///Q7P F4KxUIbLnJwOZgPJlorySpqnYoN8t/qt3xg14VNw7qsGqsDZdfzbT1hWhXnyQzwCn+Q2 CHmvHbmxYFdy5dgWqpgYFvjkYAzObHzdgZ8zDha7jeyT9YgWACaCg9d9xwOcEQm4TfQu A3uCUUrQLzdt90nPWNsEQRiPUOqqXN200ZcTkw9Yzj+tk0+YXPvNYKIPOxkDHWuG95dE teIA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=CXUFliJnGrThd8T7cB0/LTDBw0pzi/21/95DEdMriHc=; b=pO9vB6AvHTChN8lNUiZvSQxSBNkD/vS+CdExcTqB5PQd7DzjklaaPfOPeNf3xpZkgf RQv5wVeMLfwxnzoP0mbme4u0yNy8E7IEzMjnXxa8AWzu9lMuufgKxATMl/38/DhDxJap HbogmGRQ9kRAHFSBM7YJG8MEjp7uKJe3HXHROFXtvFzc57LAkKf/mDfs8MtlmeqYqRse UqT+Gug3Wgq1xmj01mtnw1Gdh2rXAvdCIFI/yBB4OoaLIpcEP0Qdr90KmYSfFYpW+aBI tdUjQZmXyKWEBvNATMhoBlRynyHen7H1OGC3576aQzKX2jCGFnfObdLlhIQGyPdWs1+p 1/lA==
X-Gm-Message-State: ABuFfoiGsjVIX4b4X88oe6K18rdymbKdXhAsabcU8MliWpapt+WlsLdS dkCBvWEZDlzcxNBJeQbqLJjqP4pr
X-Google-Smtp-Source: ACcGV61EJJbQsjIXnxfpn78uMzcssbjoMQsndPczD5/8s+gnBrCEKfrovqWXB1n3FHeMspGRoz0yww==
X-Received: by 2002:a17:906:4e03:: with SMTP id z3-v6mr26677801eju.187.1539804556691; Wed, 17 Oct 2018 12:29:16 -0700 (PDT)
Received: from ?IPv6:2600:8802:5600:1546::1004? ([2600:8802:5600:1546::1004]) by smtp.gmail.com with ESMTPSA id q12-v6sm8013787edd.35.2018.10.17.12.29.14 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 17 Oct 2018 12:29:15 -0700 (PDT)
From: Fred Baker <fredbaker.ietf@gmail.com>
Message-Id: <735F51BC-5AE4-4C42-8E99-A61CC2D83B31@gmail.com>
Content-Type: multipart/signed; boundary="Apple-Mail=_20182D35-C295-4C47-A720-CA456871DCD8"; protocol="application/pgp-signature"; micalg="pgp-sha512"
Mime-Version: 1.0 (Mac OS X Mail 11.5 \(3445.9.1\))
Date: Wed, 17 Oct 2018 12:29:11 -0700
In-Reply-To: <CAJE_bqfibpCXHYpVvzp3vGtiymn94Gv+2ky+oa5OMo=ZGY=tYg@mail.gmail.com>
Cc: Jen Linkova <furry13@gmail.com>, v6ops@ietf.org
To: 神明達哉 <jinmei@wide.ad.jp>
References: <BYAPR05MB424561F343F1D9980BA8BADBAEFD0@BYAPR05MB4245.namprd05.prod.outlook.com> <CAJE_bqcg7jzeUQv75zQZm8OwiysM55O75bEqNhfXTwtNkhjadw@mail.gmail.com> <CAFU7BARTd9jD3tPWEy9t_Wqxvfr_vAWr+4ZPSKPoQc7AS30Ndw@mail.gmail.com> <CAJE_bqfibpCXHYpVvzp3vGtiymn94Gv+2ky+oa5OMo=ZGY=tYg@mail.gmail.com>
X-Mailer: Apple Mail (2.3445.9.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/0j08DAMG1tTdELOcsSu7IBCO4fI>
Subject: Re: [v6ops] draft-pref64folks-6man-ra-pref64
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 Oct 2018 19:29:22 -0000

I'm not sure we disagree on your point. However, there is also the issue of shadowing services. For example, in my home I use an OpenDNS resolver; it's built into my router and I said "yes". If my ISP were implementing 464XLAT (they're not to my knowledge, but imagine) and wanted me to use a prefix of their choosing, OpenDNS could either have no record or give me something different. So the DNS approach has a fairly fundamental flaw.

What might be interesting on routers that want you to configure it manually would be a "use RFC 7050" configuration, in which the router got the record from DNS and advertised it in its RA.

> On Oct 17, 2018, at 11:22 AM, 神明達哉 <jinmei@wide.ad.jp> wrote:
> 
> At Tue, 16 Oct 2018 21:28:37 +1100,
> Jen Linkova <furry13@gmail.com> wrote:
> 
> > > - In section 2 (or somewhere else like in the introduction) I think
> > >   it's fair to point out that the RA approach has a drawback of
> > >   configuring local routers of each end subnet (where ordinary clients
> > >   reside).  It's unlike the advertisement of on-link/addrconf prefix
> > >   for which the router should inherently know and be configured with
> > >   anyway, so it looks to me to be a tradeoff between the router
> > >   configuration overhead and the advantages described in this section.
> >
> > Well....Some vendors still require the prefix to be explicitly
> > configured under router-advertisement section to be included in PIOs
> > (just configuring /64 on the interface is not enough) so SLAAC does
> > require some explicit configuration anyway (and RDNSS and timers etc).
> > On the other hand, some vendor allow the configuration to be inherited
> > so in real life it will be one-line config to enable this option on
> > multiple interfaces...So, to be honest, I do not see much difference
> > between this option and any other SLAAC parameter...
> 
> I'm afraid we're talking about different issues...maybe I wasn't clear
> enough in the above comment, so let me rephrase it: assume if you have
> 100 leaf subnets, each of which has an RA-advertising router.  If you
> want to deploy draft-pref64folks-6man-ra-pref64, you'll need to
> configure those 100 routers separately; if the prefix is changed,
> you'll need to update the config on these 100 routers.  On the other
> hand, if you use a DNS-based approach (RFC7050) you'll only have to
> configure/update the DNS(64) server (there may be multiple instances
> of such server and you may have to configure each of them by hand, but
> I assume the number of such instances is generally much smaller than
> the number of leaf subnets).
> 
> This is different from other SLAAC parameters such as PIO, since the
> information is different for different subnets and each router needs
> to be configured separately anyway.
> 
> To be clear, I'm not making this comment to say that ra-pref64 is
> inferior to existing ways.  I just thought there's some tradeoff
> between different approaches and it's fair to explain both pros and
> cons.
> 
> > >   Similarly, we might want to note that this case in Section 5 should
> > >   be (very?) atypical even if not forbidden:
> > >
> > >    o  The pref64 option presents in a single RA more than once;
> >
> > It would be necessary for renumbering from one pref64 to another.
> > The old pref64 needs to be advertised with zero Lifetime, while the
> > new pref64 would have non-zero lifetime.
> 
> Ah, okay.  Perhaps that was just my bad reading, but the intent wasn't
> clear to me from the draft's context.  In fact, it looks like the
> other two bullets talk about the case of multiple usable prefixes
> (right?)  Also, if I understand it correctly, "the recommendations
> given in Section 3 of [RFC7050]" also discusses the case of multiple
> usable prefixes:
> 
>    When multiple Pref64 were discovered via RA Pref64 Option [...],
>    host behaviour with regards to synthesizing IPv6 addresses from IPv4
>    addresses SHOULD follow the recommendations given in Section 3 of
>    [RFC7050], limited to the NAT64 prefixes that have non-zero
>    lifetime..
> 
> Only the above one bullet should mean the renumbering case since the
> pref64 option should only support at most one usable prefix.  And then
> the above paragraph still looks awkward: since "this option specifies
> exactly one NAT64 prefix for all IPv4 destinations" (from Section 3)
> I'd expect we only have at most one prefix that has non-zero
> lifetime.  And then there's no point of applying the above
> "recommendation" since it's "limited to the NAT64 prefixes that have
> non-zero lifetime" (btw there's a redundant period here).
> 
> Perhaps I'm still misunderstanding something fundamental, but I
> personally see some need for editorial clarification.
> 
> > > - Section 3: these two don't read very consistently:
> > >    This option may appear more than once in a Router Advertisement.
> > > [...]
> > >    This option specifies exactly one NAT64 prefix for all IPv4
> > >    destinations.
> >
> > Sorry, I'm not sure I understand why. For example, a PIO contains
> > exactly one prefix. However Prefix Information Option may appear more
> > than once in a Router Advertisement.
> > The same here.
> >
> > >   If it intends to specify *exactly one* prefix, what's the point of
> > >   having more than one options (unless these options include exactly
> > >   the same prefix, which also makes no sense).  I guess this is rather
> > >   an editorial matter than a protocol problem - perhaps in this
> > >   context we just don't have to say the "may appear more than once"
> > >   sentence.
> >
> > See the renumbering example above.
> 
> See above.  Now I see how these two can coexist, but at least to me
> it's not so obvious for fresh readers just from this text.  More
> explanation to clarify the intent would help.
> 
> --
> JINMEI, Tatuya
> _______________________________________________
> v6ops mailing list
> v6ops@ietf.org
> https://www.ietf.org/mailman/listinfo/v6ops

--------------------------------------------------------------------------------
The fact that there is a highway to hell and a stairway to heaven is an interesting comment on projected traffic volume...