Re: [v6ops] 464xlat case study (was reclassify 464XLAT as standard instead of info)

Ole Troan <otroan@employees.org> Thu, 28 September 2017 08:15 UTC

Return-Path: <otroan@employees.org>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 13EC31344E9 for <v6ops@ietfa.amsl.com>; Thu, 28 Sep 2017 01:15:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MvZIsIJMN_z9 for <v6ops@ietfa.amsl.com>; Thu, 28 Sep 2017 01:14:59 -0700 (PDT)
Received: from accordion.employees.org (accordion.employees.org [198.137.202.74]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 35427133074 for <v6ops@ietf.org>; Thu, 28 Sep 2017 01:14:59 -0700 (PDT)
Received: from h.hanazo.no (96.51-175-103.customer.lyse.net [51.175.103.96]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by accordion.employees.org (Postfix) with ESMTPSA id 75C002D5063; Thu, 28 Sep 2017 08:14:58 +0000 (UTC)
Received: from [IPv6:::1] (localhost [IPv6:::1]) by h.hanazo.no (Postfix) with ESMTP id E9DE110F996C0; Thu, 28 Sep 2017 10:14:56 +0200 (CEST)
From: Ole Troan <otroan@employees.org>
Message-Id: <F127627E-8F6C-4E62-A4E6-63D0864F407A@employees.org>
Content-Type: multipart/signed; boundary="Apple-Mail=_6328DB19-32A5-4219-9A2A-713B314EF12E"; protocol="application/pgp-signature"; micalg="pgp-sha512"
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Thu, 28 Sep 2017 10:14:56 +0200
In-Reply-To: <alpine.DEB.2.20.1709280955490.18564@uplift.swm.pp.se>
Cc: Mark Andrews <marka@isc.org>, IPv6 Ops WG <v6ops@ietf.org>
To: Mikael Abrahamsson <swmike@swm.pp.se>
References: <LO1P123MB01168388285206BB7C26F029EA7A0@LO1P123MB0116.GBRP123.PROD.OUTLOOK.COM> <46045DAA-9096-43BA-A5FD-571232767726@google.com> <CAKD1Yr3vziaHfkR+hQ7QHXaz7QraKH2HLUVXUW63GpnOAj4JoQ@mail.gmail.com> <E72C3FBE-57A4-4058-B9E5-F7392C9E9101@google.com> <LO1P123MB0116805F9A18932E2D0694FEEA780@LO1P123MB0116.GBRP123.PROD.OUTLOOK.COM> <1496304E-54BE-47FA-A7F1-1AA6E163DAB1@employees.org> <CAD6AjGQdMFgv4727wHm41HmEyo2Z-PCabPHPSRSVwOi_rey7OQ@mail.gmail.com> <CAKD1Yr03zsuSBqPegs6RNbBqnJizUOLZwH+rNDi1Ocg4k+mARQ@mail.gmail.com> <20170928030630.DD2D08867238@rock.dv.isc.org> <alpine.DEB.2.20.1709280753080.18564@uplift.swm.pp.se> <20170928074105.BCB99886E538@rock.dv.isc.org> <alpine.DEB.2.20.1709280955490.18564@uplift.swm.pp.se>
X-Mailer: Apple Mail (2.3273)
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/UMHaHWPDppCRr-5pfzlZF3v9qS4>
Subject: Re: [v6ops] 464xlat case study (was reclassify 464XLAT as standard instead of info)
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Sep 2017 08:15:05 -0000

>> You do know the RFC 7050 doesn't work with DNSSEC validation enabled. RFC 7050 specifies CD=0.
> 
> Correct. I don't get your point. This is the local resolver on the device trying to figure out where the NAT64 prefix is. Of course it can't do validation on this specific query.
> 
> We all know DNS64+NAT64(+464XLAT) isn't optimal, but neither is your suggestion to "just run dual stack".

I believe you are misrepresenting Mark's position.

It's perfectly fine to run an "IPv4 life extension mechanism" + IPv6, but without NAT64/DNS64.

Ole