Re: [v6ops] Implementation Status of PREF64

Lorenzo Colitti <lorenzo@google.com> Thu, 30 September 2021 05:43 UTC

Return-Path: <lorenzo@google.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CCACF3A149B for <v6ops@ietfa.amsl.com>; Wed, 29 Sep 2021 22:43:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -18.097
X-Spam-Level:
X-Spam-Status: No, score=-18.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.499, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Fqm_HJVcs-YB for <v6ops@ietfa.amsl.com>; Wed, 29 Sep 2021 22:42:55 -0700 (PDT)
Received: from mail-io1-xd2a.google.com (mail-io1-xd2a.google.com [IPv6:2607:f8b0:4864:20::d2a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D259F3A13D3 for <v6ops@ietf.org>; Wed, 29 Sep 2021 22:42:54 -0700 (PDT)
Received: by mail-io1-xd2a.google.com with SMTP id 134so6053542iou.12 for <v6ops@ietf.org>; Wed, 29 Sep 2021 22:42:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=Ri2XUB0Ejzhl8kBIjVOyojQKfrlL2N7Xf4AbWC2mGio=; b=Pn7w1ShfmBsEKHt1I5JiK7b6NE80rSRfOYTiHLPBbrDrj0R+V5p2VN6ZtzE0wEu0Dh 1XMc4uzq/L0UI5b3g0BCgr9aWPB682c7985Gi1PHsX7tA1whbtcpHqPknM+2gfa+LdU0 W2u/JLbUb7UrLSInk8aW8H2QGQjTeIK0W16wUn8I33dwueOjJWO2AqGWAz8EwhlcOXox whmLnHoUl+s2tZcFD6O+QEo22+eONEKUGWJCf7STcarkTTJ7pY3fJf5Z+uIA+vnREvXJ o+r7FlahLotb9lhVFSoRPIuQSnB/MAn3BvxvQ42XT4mn9GFZhPpCXxIfbKfyJvxt9ND7 XNMw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=Ri2XUB0Ejzhl8kBIjVOyojQKfrlL2N7Xf4AbWC2mGio=; b=gCBcM2mQtPLUShy+ZaswJb9G76txQUOk6EIqm5ogHOKfaWGbuhMY4CSkZmahytMgF6 Ie3PhYQj+gZW1DevRVX8IRn1c7ciamWG04Aur+9TvoHOJI23YIfdSFyLJBys6wGszt6j tNIf3rHiTwrHdY0MDwN8w0F9FlxQ8NmzDDWVajgko3MHVTs7qMh/wFPGdqFX3uDSLjaZ rTN8FiVVx4GWcfUO1KhUlcjrwPxv1/4sAr4Dw5wOvNFj2SE2JVPKDYKk0W5gx2oDw3st lVY290tLf0fNxgLoDqCJxK2bUwVnV1uqbb1XHeifANypZuLJLRJME5Ob8KC1dA6TU3gA U/dQ==
X-Gm-Message-State: AOAM532dJntkudPrHsc9XntiAuq53mVXzs1ETsmnN9CDKoBUWaPMvUoY /nDyPwID6Q98IKKNN6NK04KDOx5lkYhX3NdEx9yWgA==
X-Google-Smtp-Source: ABdhPJz/a7DyLs0abXPrWrAZt6G2jBBGdN7/LRrhz5rtPeGNIiasnVYq/Z/mFgKAj9LDK8Z6RiuJ/KI/DKXYEm8014I=
X-Received: by 2002:a05:6638:f8b:: with SMTP id h11mr3168123jal.141.1632980573458; Wed, 29 Sep 2021 22:42:53 -0700 (PDT)
MIME-Version: 1.0
References: <CAN-Dau2in52xSUkqKEXu=2AAiR4O_jLhna7hY-hshYDORfGtcQ@mail.gmail.com> <CAMGpriWFp4JPtqDK5tEj1RkS-SzEfvscfUUnxgK+o6qP2pusRA@mail.gmail.com> <6E95834D-12B3-447B-8326-8EDE9DC6FFB1@delong.com> <CAO42Z2zA-4cK489nxKsWUN8vvU0eAiz-jS0e-_eWPg+OmP8wLw@mail.gmail.com> <DDA36020-90CC-471B-83AD-3D98950F1164@delong.com> <CAO42Z2wdoSdJDOB2Zo0=ZK0ecOARRsdg2nbHZGSDOhryPbLfDw@mail.gmail.com> <F2BD0A42-E9AD-45DD-999A-638E73BE1177@delong.com> <CAKD1Yr2K3Gd3JD=NJFOoH6GYgs-8ACxRQB9-sKJ7cbF4_hxsow@mail.gmail.com> <0B533C71-5DB0-410D-A5A3-7E8FD559F214@delong.com> <CAKD1Yr3NoYfNT7+OVJoCCdgdif6AHHw29tNCPttS=-NuRZKv3w@mail.gmail.com> <DM6PR02MB692426B0EEDDC2C4D78D8EC0C3A89@DM6PR02MB6924.namprd02.prod.outlook.com>
In-Reply-To: <DM6PR02MB692426B0EEDDC2C4D78D8EC0C3A89@DM6PR02MB6924.namprd02.prod.outlook.com>
From: Lorenzo Colitti <lorenzo@google.com>
Date: Thu, 30 Sep 2021 14:42:40 +0900
Message-ID: <CAKD1Yr25dtinLBeJpAuJ17NfLg7-ewM9QPvnXNuEJ8wiBQV9ig@mail.gmail.com>
To: "STARK, BARBARA H" <bs7652@att.com>
Cc: Owen DeLong <owen@delong.com>, V6 Ops List <v6ops@ietf.org>, Jen Linkova <furry@google.com>
Content-Type: multipart/alternative; boundary="00000000000001f68605cd2febad"
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/eXsYYJikgJEkezOgoeWPNharDIA>
Subject: Re: [v6ops] Implementation Status of PREF64
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Sep 2021 05:43:01 -0000

On Wed, Sep 29, 2021 at 1:01 AM STARK, BARBARA H <bs7652@att.com> wrote:

> I’m not aware of widely-deployed equipment that supports good RADIUS/RA
> integration for similar device configuration via RA.
>

ISTR building a network that did this circa 2011, but it was not enterprise
hardware, it was a Juniper BNG. It supported dynamic VLAN creation based on
first-sign-of-life (or maybe RS), and got prefix information from RADIUS:
Framed-IPv6-Prefix for the PIO in the RA, Delegated-IPv6-Prefix for
subsequent PD requests.


> <bhs> I mostly agree. Unfortunately, some governments are putting
> pressure on enterprises and government networks (which are just a type of
> enterprise network) to support IPv6. This is largely due to messaging
> coming from the IETF. Maybe IETF should produce a Best Practice
> recommendation that enterprise and government networks not support IPv6
> until all tools they need to properly secure an IPv6-enabled network are
> widely available as software updates to legacy equipment.
>

Do you actually think it's the equipment that's the issue here? Even if the
equipment isn't capable of logging neighbour table bindings via syslog
(which most vendors have for a while), scraping ND tables isn't that hard
to do. I think the issue is more around operational familiarity and the
idea that because we do things this way in IPv4 we must to do them the same
way in IPv6 as well.