Re: [v6ops] draft-ietf-v6ops-ula-usage-recommendations - work or abandon?

Lorenzo Colitti <lorenzo@google.com> Fri, 13 November 2015 11:12 UTC

Return-Path: <lorenzo@google.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BFAD81AC40C for <v6ops@ietfa.amsl.com>; Fri, 13 Nov 2015 03:12:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.388
X-Spam-Level:
X-Spam-Status: No, score=-1.388 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MIxqQPSuGShr for <v6ops@ietfa.amsl.com>; Fri, 13 Nov 2015 03:12:33 -0800 (PST)
Received: from mail-yk0-x229.google.com (mail-yk0-x229.google.com [IPv6:2607:f8b0:4002:c07::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 28F661AC406 for <v6ops@ietf.org>; Fri, 13 Nov 2015 03:12:33 -0800 (PST)
Received: by ykba77 with SMTP id a77so139982039ykb.2 for <v6ops@ietf.org>; Fri, 13 Nov 2015 03:12:32 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type; bh=q6NTUe/1DbHNuVlCyjDJIRF42p4QSy81kIIPNkrzbpU=; b=BPaf929zZPQ888L5/XpyhzY7PAC5YFcfmkjjJAS6RA+TOHgbg08ePJJHVtGTwADRPs 68YvQgTupDR/ywL+KdSZknQbLPufxWv9eiz2Bwb7A/zNdV2Z2rsWJE9cPKilNLacafW0 T3TWHfq3NDK7i7eBcMPTREyHNGvMLEAum9lWBGuiqSu9kro70SQD5+7KOeTnaGlvFgLM 7BB+wHMw6C0/bX+OSED70xOagvgAxH7bUTZaFD1id97POF8rwsvKhf8UvrOHd8A8YrPV FoCGk963xGNL18q7A2Q/ZunBc4e0GYCgFyt4C7A++K+blWLbj4KzzAR+DnE1yiji0mJa jaAQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=q6NTUe/1DbHNuVlCyjDJIRF42p4QSy81kIIPNkrzbpU=; b=ZYG52qaky1O5OyC9bPlKtpFiFnmPuIbvIKKQHiiIAaHX5DQObVMn4kA4PNVpWy0LfY ozTVOCWffTFZEgK4bSX4PPH5dQYdkWRK1DmWokyelokFH2N+A2sGS82heK4d7iK7jFfA VWJgF/+kXiwPHPVRNiEtzfaGtnopIuKAlfb26ChZk21BpKdX2ZMVgBDtc/Pvg7zMyHU5 D4boRWD1wmtbVpWhq5m0OsWQZpDx/zNcP12GBbc296hMezh18WZ3dFmX14B6hHVo+Kfi wgo79lEeW8RtPkQTV6IlLRxkCVvA2mH/0rT0QjmX+EOVaZ7UTLnqErY1X/e+ZXmsWanB t5kQ==
X-Gm-Message-State: ALoCoQnztleVnOVUWvR+JnTbmgf5Dq+1yB1Ga5LxYG93jitZZN+USsTqbp/fnvL6LOZmknEE2pio
X-Received: by 10.13.204.2 with SMTP id o2mr16785385ywd.160.1447413152369; Fri, 13 Nov 2015 03:12:32 -0800 (PST)
MIME-Version: 1.0
Received: by 10.37.115.131 with HTTP; Fri, 13 Nov 2015 03:12:12 -0800 (PST)
In-Reply-To: <D26B5654.5DE76%evyncke@cisco.com>
References: <D25D5920.C914E%Lee.Howard@twcable.com> <CAKD1Yr3jip0NBkDxg=MvgZXg0LMS+PtREDw2jSRx0xJLqHwhGQ@mail.gmail.com> <563C7C01.6010703@foobar.org> <CAKD1Yr1rKjkDhhuD9L=R_MJ+ofOAZ2Nt+5mszZKQxCh-kH4vqw@mail.gmail.com> <563FA84C.7030601@si6networks.com> <CAKD1Yr0F888Aw0opSigtC8HV6esUrE1JECKQ4gT737s+43ayfw@mail.gmail.com> <CAG6TeAs8ie=c0F8RMioBpemCw949Bf9c7ZTNvqgaZP=10rmNcQ@mail.gmail.com> <CAKD1Yr1EqbiGJ8EZo8E909zujUt49skcz1SNe8stEWfHnbUsTw@mail.gmail.com> <CAG6TeAsHMTyhbRrOenb1kA9XEDdOCBBbuN3ZGF3LJ=8ToyGtiQ@mail.gmail.com> <CAKD1Yr3RUc9FEw7VyJ=ENH_sJY85m1BESo77v_maShPvCkj6rA@mail.gmail.com> <CAG6TeAv9DPYUCsNG_vHCTOpwwJ8KdhjWeGE=-s6dEuMgaVHf1g@mail.gmail.com> <CAKD1Yr2VXVFareTk-J_+pcr_UW9Do-zf_uYcyjNW-MTPts6hRQ@mail.gmail.com> <CAG6TeAt2JJJmALy=pJFaojbnZrQRE0e0i-D=XtTce=rmbf08tQ@mail.gmail.com> <CAKD1Yr1H2HgxBNOZBrx-ttoB6z6caLAck3csF=ti6CDUzW57ng@mail.gmail.com> <D267B9E3.5DB8C%evyncke@cisco.com> <CAKD1Yr2zY9qr76f-KO7DTnYXQEmMJ0O6M22nFczfjGfL5Dk=dA@mail.gmail.com> <564537A7.90102@si6networks.com> <CAKD1Yr3dUMEoG-De5YWDFyjGehhxBq-uyN-NSqbYgvinDUy8Wg@mail.gmail.com> <D26B5654.5DE76%evyncke@cisco.com>
From: Lorenzo Colitti <lorenzo@google.com>
Date: Fri, 13 Nov 2015 20:12:12 +0900
Message-ID: <CAKD1Yr3PaEojRyXzhmdJ+mnXOe6eGi38dBkdjXC=jHL98Eo2sg@mail.gmail.com>
To: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
Content-Type: multipart/alternative; boundary="001a114f136acac04205246a22c1"
Archived-At: <http://mailarchive.ietf.org/arch/msg/v6ops/7JsgguwHOUZ5BQUpOvz9BreA3AM>
Cc: Fernando Gont <fgont@si6networks.com>, IPv6 Operations <v6ops@ietf.org>
Subject: Re: [v6ops] draft-ietf-v6ops-ula-usage-recommendations - work or abandon?
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Nov 2015 11:12:34 -0000

On Fri, Nov 13, 2015 at 4:59 PM, Eric Vyncke (evyncke) <evyncke@cisco.com>
wrote:

> I agree with Lorenzo: ports are 'just' an extension of the IP address and
> can be negotiated (SDP for example). Also agree with Fernando: add a 3rd
> party (or a 4th one -- double NAT) and your problems come.
>
> And there are at least one firewall which checks the TCP sequence numbers,
> so, any attempt to 'bypass' the diode-like function by sending SYN on one
> side and SYN+ACK on the other side will also require to negotiate the TCP
> sequence numbers... And those are outside the realm of the user space
> application
>

Absolutely. There are firewalls that only allow through pink packets on
Tuesdays. But checking the sequence number won't help with UDP.