Re: Some suggestions for draft-ietf-v6ops-cpe-simple-security-03

Gert Doering <gert@space.net> Tue, 26 August 2008 11:55 UTC

Return-Path: <owner-v6ops@ops.ietf.org>
X-Original-To: ietfarch-v6ops-archive@core3.amsl.com
Delivered-To: ietfarch-v6ops-archive@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 16C9A28C12E for <ietfarch-v6ops-archive@core3.amsl.com>; Tue, 26 Aug 2008 04:55:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.052
X-Spam-Level: *
X-Spam-Status: No, score=1.052 tagged_above=-999 required=5 tests=[BAYES_05=-1.11, FH_RELAY_NODNS=1.451, HELO_MISMATCH_NET=0.611, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hrLjoXLWu1qn for <ietfarch-v6ops-archive@core3.amsl.com>; Tue, 26 Aug 2008 04:55:29 -0700 (PDT)
Received: from psg.com (psg.com [IPv6:2001:418:1::62]) by core3.amsl.com (Postfix) with ESMTP id 7014228C11B for <v6ops-archive@lists.ietf.org>; Tue, 26 Aug 2008 04:55:29 -0700 (PDT)
Received: from majordom by psg.com with local (Exim 4.69 (FreeBSD)) (envelope-from <owner-v6ops@ops.ietf.org>) id 1KXx3I-0007QO-NG for v6ops-data@psg.com; Tue, 26 Aug 2008 11:49:36 +0000
Received: from [195.30.1.100] (helo=moebius2.Space.Net) by psg.com with smtp (Exim 4.69 (FreeBSD)) (envelope-from <gert@Space.Net>) id 1KXx35-0007OQ-Rq for v6ops@ops.ietf.org; Tue, 26 Aug 2008 11:49:27 +0000
Received: (qmail 8011 invoked by uid 1007); 26 Aug 2008 11:49:19 -0000
Comment: DomainKeys? See http://antispam.yahoo.com/domainkeys
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=testkey; d=space.net; b=WdBl4IU1haBkMZR0IXVEDdGpfTaPuEoK5Kh5PxcmLUeeFM6O1tRQ8DjAzLm7CSUf ;
Date: Tue, 26 Aug 2008 13:49:19 +0200
From: Gert Doering <gert@space.net>
To: Dan Wing <dwing@cisco.com>
Cc: 'Truman Boyes' <truman@suspicious.org>, 'Brian E Carpenter' <brian.e.carpenter@gmail.com>, 'Mark Smith' <ipng@69706e6720323030352d30312d31340a.nosense.org>, jhw@apple.com, 'IPv6 Operations' <v6ops@ops.ietf.org>
Subject: Re: Some suggestions for draft-ietf-v6ops-cpe-simple-security-03
Message-ID: <20080826114919.GN19694@Space.Net>
References: <01af01c9065b$b4602440$c2f0200a@cisco.com> <48B23391.1090503@gmail.com> <01cd01c90672$a57c8790$c2f0200a@cisco.com> <48B31DA3.6080001@gmail.com> <07d201c906f7$50a85e30$c2f0200a@cisco.com> <48B32B43.5010103@gmail.com> <084c01c906fe$f9bf1840$c2f0200a@cisco.com> <48B33430.40704@gmail.com> <A31EB889-2BD9-4283-A408-AB6DCC1D568A@suspicious.org> <08be01c90712$d876cd40$c2f0200a@cisco.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <08be01c90712$d876cd40$c2f0200a@cisco.com>
User-Agent: Mutt/1.4.2.1i
X-NCC-RegID: de.space
Sender: owner-v6ops@ops.ietf.org
Precedence: bulk
List-ID: <v6ops.ops.ietf.org>

Hi,

On Mon, Aug 25, 2008 at 05:29:47PM -0700, Dan Wing wrote:
> Internalt to external is permitted, by default, in the current document.
> 
> We are discussing external to internal.  

What is "internal to external" is inevitably "external to internal" to
someone else.

How do you solve "tunneling is permitted if solicited from the inside" for 
the

  Host A --- CPE A ----[Internet]---- CBE B --- Host B

case?

Gert Doering
        -- NetMaster
-- 
Total number of prefixes smaller than registry allocations:  128645

SpaceNet AG                        Vorstand: Sebastian v. Bomhard
Joseph-Dollinger-Bogen 14          Aufsichtsratsvors.: A. Grundner-Culemann
D-80807 Muenchen                   HRB: 136055 (AG Muenchen)
Tel: +49 (89) 32356-444            USt-IdNr.: DE813185279