Re: [v6ops] draft-linkova-v6ops-nd-cache-init to working group draft

David Lamparter <equinox@diac24.net> Wed, 24 July 2019 14:44 UTC

Return-Path: <equinox@diac24.net>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2F3DF1202C4; Wed, 24 Jul 2019 07:44:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id F_OZPPjilAco; Wed, 24 Jul 2019 07:44:43 -0700 (PDT)
Received: from eidolon.nox.tf (eidolon.nox.tf [IPv6:2a07:2ec0:2185::]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 94B77120284; Wed, 24 Jul 2019 07:44:43 -0700 (PDT)
Received: from equinox by eidolon.nox.tf with local (Exim 4.92) (envelope-from <equinox@diac24.net>) id 1hqIVJ-000mqU-Ii; Wed, 24 Jul 2019 16:44:29 +0200
Date: Wed, 24 Jul 2019 16:44:29 +0200
From: David Lamparter <equinox@diac24.net>
To: "Pascal Thubert (pthubert)" <pthubert@cisco.com>
Cc: Brian E Carpenter <brian.e.carpenter@gmail.com>, David Lamparter <equinox@diac24.net>, Fernando Gont <fernando@gont.com.ar>, IPv6 Operations <v6ops@ietf.org>, 6man Chairs <6man-chairs@ietf.org>
Message-ID: <20190724144429.GL258193@eidolon.nox.tf>
References: <351E8A83-734C-448D-B0C6-212C09D564F4@gmail.com> <ea7438f2-b917-60eb-88bc-a375246a0cf9@gmail.com> <8f1c6206-6057-5ab0-c16c-ad8ff67c9457@gont.com.ar> <20190723191925.GF258193@eidolon.nox.tf> <1b6ce7f8-07d1-bb1e-7533-637cfd4ae85b@gmail.com> <3074B072-EA8C-427C-8ED1-55C5D5BE9448@cisco.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
In-Reply-To: <3074B072-EA8C-427C-8ED1-55C5D5BE9448@cisco.com>
User-Agent: Mutt/1.10.1 (2018-07-13)
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/gm61jjlX1h44Mbz4P4FmnhPls2g>
Subject: Re: [v6ops] draft-linkova-v6ops-nd-cache-init to working group draft
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Jul 2019 14:44:46 -0000

On Wed, Jul 24, 2019 at 11:05:38AM +0000, Pascal Thubert (pthubert) wrote:
> I’ve participated to multiple corridor discussions on that topic and
> seen agreement that NA(O) to ff02::2 that proactively sets the cache
> in the routers is better than the current state of affairs which is a
> NS from the router that is broadcasted to all hosts at L2.

I would like to argue that our approach to this issue should be
"additive", and if we can easily run fixes from multiple angles it might
be worth doing so.

In particular:
- DAD gleaning is a router-only fix for this issue that requires no host
  changes
- sending any kind of unicast probe that triggers a response is a
  host-only fix for this issue that requires no router changes
- sending NA(O) to ff02::2 is a router and host change

The fact that any of these may not work in some particular setup (e.g.
wifi controller crapping on ND, shitty multicast snooping) is all the
more reason to do more than one.

>From a privacy perspective I'm fine with sending NA(O) to ff02::2 since
that is theoretically "only routers" in a network that were to limit
multicast propagation.  It's not ff02::1, which is all I ask.

I'm also happy if we document NA(O) to ff02::2 as the "long-term" fix
while doing DAD gleaning and/or unicast probes as "short-term" fixes.

Lastly, NA(O) to ff02::2 should go through 6man IMHO.  Whether either of
the other 2 options I listed above needs that I don't know.

Cheers,


-David