Re: [v6ops] new draft: draft-elkins-v6ops-multicast-virtual-nodes

Ray Hunter <v6ops@globis.net> Wed, 11 February 2015 15:07 UTC

Return-Path: <v6ops@globis.net>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 88A6D1A0377 for <v6ops@ietfa.amsl.com>; Wed, 11 Feb 2015 07:07:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.911
X-Spam-Level:
X-Spam-Status: No, score=-1.911 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uQe_-tEWKFP1 for <v6ops@ietfa.amsl.com>; Wed, 11 Feb 2015 07:07:27 -0800 (PST)
Received: from globis01.globis.net (mail.globis.net [IPv6:2001:470:1f15:62e::2]) by ietfa.amsl.com (Postfix) with ESMTP id 7193B1A00A7 for <v6ops@ietf.org>; Wed, 11 Feb 2015 07:07:27 -0800 (PST)
Received: from localhost (localhost [127.0.0.1]) by globis01.globis.net (Postfix) with ESMTP id 0279C871625; Wed, 11 Feb 2015 16:07:26 +0100 (CET)
Received: from globis01.globis.net ([127.0.0.1]) by localhost (mail.globis.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2CfHyDnAqQ7J; Wed, 11 Feb 2015 16:07:25 +0100 (CET)
Received: from Rays-iMac.local (092-111-140-211.static.chello.nl [92.111.140.211]) (Authenticated sender: Ray.Hunter@globis.net) by globis01.globis.net (Postfix) with ESMTPSA id C8975871617; Wed, 11 Feb 2015 16:07:25 +0100 (CET)
Message-ID: <54DB702B.1050409@globis.net>
Date: Wed, 11 Feb 2015 16:07:23 +0100
From: Ray Hunter <v6ops@globis.net>
User-Agent: Postbox 3.0.11 (Macintosh/20140602)
MIME-Version: 1.0
To: v6ops@ietf.org
References: <201502111247.t1BCl1vO003446@irp-lnx1.cisco.com>
In-Reply-To: <201502111247.t1BCl1vO003446@irp-lnx1.cisco.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/v6ops/2dWQs-jQvkF6TfK71x-fYzGI-sA>
Cc: draft-elkins-v6ops-multicast-virtual-nodes@tools.ietf.org
Subject: Re: [v6ops] new draft: draft-elkins-v6ops-multicast-virtual-nodes
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 11 Feb 2015 15:07:39 -0000

fred@cisco.com wrote:
> A new draft has been posted, at http://tools.ietf.org/html/draft-elkins-v6ops-multicast-virtual-nodes. Please take a look at it and comment.
>
>

I've read this draft.

IMHO It should be blindingly obvious to anyone configuring up an IPv6 
network, whether physical or virtual, that if you connect up multiple 
customers at L2, then they will be able to communicate with both unicast 
and multicast.

"Works as designed."

Now perhaps good-practice design-experience for IPv6 might need to be 
re-learned from IPv4 hosting, but I don't see anything earth-shaking in 
the problem description.

Existing mitigation mechanisms could include: assigning a SVI/VLAN with 
a unique /64 per customer ± uRPF ± ACL's ± PBR, or L2 Private VLANs.

All  are already widely available from a vendor near you, both in real 
and virtual form.

-- 
Regards,
RayH