Re: [v6ops] draft-gont-v6ops-ipv6-ehs-in-real-world: clarification text

Mark ZZZ Smith <markzzzsmith@yahoo.com.au> Tue, 21 April 2015 01:22 UTC

Return-Path: <markzzzsmith@yahoo.com.au>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4FFFC1A01AA for <v6ops@ietfa.amsl.com>; Mon, 20 Apr 2015 18:22:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.502
X-Spam-Level:
X-Spam-Status: No, score=0.502 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, FROM_LOCAL_NOVOWEL=0.5, HK_RANDOM_ENVFROM=0.001, HK_RANDOM_FROM=1, HK_RANDOM_REPLYTO=0.999, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BnEOy7SbNxhZ for <v6ops@ietfa.amsl.com>; Mon, 20 Apr 2015 18:22:49 -0700 (PDT)
Received: from nm24-vm0.bullet.mail.bf1.yahoo.com (nm24-vm0.bullet.mail.bf1.yahoo.com [98.139.213.161]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B1C8E1A01A8 for <v6ops@ietf.org>; Mon, 20 Apr 2015 18:22:48 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com.au; s=s2048; t=1429579367; bh=7eXkdmRnyzjxM1ZSmg9hiXUJPGwvFR9xdRq86Zr9CqY=; h=Date:From:Reply-To:To:Cc:In-Reply-To:References:Subject:From:Subject; b=dnJPpi2aZvnRADi3R0047ORqFsVeJ8nuPcEWjFnRHt/j2F3OfeAduuY/OIUxGp0r38kyJ05qcetcBUotgJCTI0v1j/m5ovsw3Ft2/GVYdL9wrukLUIIgc5/vqMQm8/IDz0e9YJN/2hKr6ua/EBzhq26pWqDk+uFO7BZRwABKHRbyzTGXhQ+QCO8gLTK39V5ZWDXpfDaPNNyXR7uR3IYmswJn2/YVNqlSkqTPioKn/SIELayfPb7R48F59lPDxhOpK9EYVK2qlV4gIRycnbEcjk5SVqtvDrF7ePwesYOa7iC4RLxN1ijaCLYU1HHIdPzZa66GlKDgWiVDgqxUzKw0ww==
Received: from [98.139.170.178] by nm24.bullet.mail.bf1.yahoo.com with NNFMP; 21 Apr 2015 01:22:47 -0000
Received: from [98.139.212.243] by tm21.bullet.mail.bf1.yahoo.com with NNFMP; 21 Apr 2015 01:22:47 -0000
Received: from [127.0.0.1] by omp1052.mail.bf1.yahoo.com with NNFMP; 21 Apr 2015 01:22:47 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 940060.75473.bm@omp1052.mail.bf1.yahoo.com
X-YMail-OSG: _LVKo_AVM1md7pTmVqfPA7VRF0tAHyARfLxQTg3ltaHaut95h4PiRe7yVLb3f41 mG80mOZkpDwBBuRFNwlDcpOIsF0LErZUN09TihXxedWpJyNKkTf_8RC1EYfsx124qpvKeEzORF.s yDYaBVruPuqHT5cL2un8.3UJVXZb0LmwY1f1758h3bqccgdEHKr_hLDPpGu5O6IVuuijBcsckmiB yEe6mbY93ZGbIu_x.xNeOVd3.KFp0xB_cyWiZVrc8VsG3ru8MCMfbNM2fbTgf2Nks8yFJqY52Tr8 .IhK7nChsPN8mDsj.ULn7tClcInpleFQE6uk1DHJzBj98e4F8kOLry7HxiI0xIfhAwjlrWTave2F B0XzxkxcaBm_VgJecWpZ7wMvfluDq4yGYN51YPfbpqHs0k0I8sRJgr08k5ntm0cPIXiMRxihjVC_ 04nEQeotppRL79n2WZ8qruq1_Ta1PRm5GlhRGJVi7B8y6IK.xAePOITrYZHKsy.Q3V7i0gC7Sb4h eHEXYq9_YdI45huGFEfhwOD4ZIg6z7sHvds81uV9Z8A--
Received: by 66.196.81.119; Tue, 21 Apr 2015 01:22:47 +0000
Date: Tue, 21 Apr 2015 01:22:46 +0000
From: Mark ZZZ Smith <markzzzsmith@yahoo.com.au>
To: Joe Touch <touch@isi.edu>, Gert Doering <gert@space.net>
Message-ID: <1916486469.1036672.1429579366689.JavaMail.yahoo@mail.yahoo.com>
In-Reply-To: <55356F68.1020605@isi.edu>
References: <55356F68.1020605@isi.edu>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_Part_1036671_185083561.1429579366684"
Archived-At: <http://mailarchive.ietf.org/arch/msg/v6ops/hJ3m3NCyV_-GlPUvQEpl5CrvQ78>
Cc: "draft-gont-v6ops-ipv6-ehs-in-real-world@tools.ietf.org" <draft-gont-v6ops-ipv6-ehs-in-real-world@tools.ietf.org>, "v6ops@ietf.org" <v6ops@ietf.org>, Merike Kaeo <merike@doubleshotsecurity.com>, Fernando Gont <fgont@si6networks.com>
Subject: Re: [v6ops] draft-gont-v6ops-ipv6-ehs-in-real-world: clarification text
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
Reply-To: Mark ZZZ Smith <markzzzsmith@yahoo.com.au>
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 21 Apr 2015 01:22:50 -0000

      From: Joe Touch <touch@isi.edu>
 To: Gert Doering <gert@space.net> 
Cc: "v6ops@ietf.org" <v6ops@ietf.org>; Merike Kaeo <merike@doubleshotsecurity.com>; "draft-gont-v6ops-ipv6-ehs-in-real-world@tools.ietf.org" <draft-gont-v6ops-ipv6-ehs-in-real-world@tools.ietf.org>; Fernando Gont <fgont@si6networks.com> 
 Sent: Tuesday, 21 April 2015, 7:28
 Subject: Re: [v6ops] draft-gont-v6ops-ipv6-ehs-in-real-world: clarification text
   


On 4/20/2015 2:21 PM, Gert Doering wrote:
> Hi,
> 
> On Mon, Apr 20, 2015 at 08:43:28AM -0700, Joe Touch wrote:
>>> If for some reasons, a router in the middle needs access to layer-4
>>                                              ^^^^^
>>> information (IPFIX? DDoS mitigation? ... ?), then the EH chain must be
>>> parsed which can cause a performance impact.
> [..]
>>     1) this is the router vendor's decision, not a requirement
>>     of Internet routers
> 
> So, please tell me how you build an Internet router that is able to
> defend itself against control plane abuse and does not need to look into
> L4 to do so?

A router can protect its own control plane by looking at the packet
contents, but then it is acting as a host at that point and should be
looking there only for packets addressed to interfaces of that router.
That's not a forwarding function and thus doesn't limit the forwarding
plane.

/ I agree with this. It is easy to forget that a "router" is in actually a packet router at the forwarding plane and a host at the control plane.

It is not a requirement that one router protect the control planes of
other routers from abuse. That is a feature - and if you want to sell
that as a feature, your device should support doing so at rate.


 

Joe


_______________________________________________
v6ops mailing list
v6ops@ietf.org
https://www.ietf.org/mailman/listinfo/v6ops