Re: [v6ops] new draft: draft-taylor-v6ops-fragdrop

Lorenzo Colitti <lorenzo@google.com> Thu, 01 November 2012 00:59 UTC

Return-Path: <lorenzo@google.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 89BCF21F889B for <v6ops@ietfa.amsl.com>; Wed, 31 Oct 2012 17:59:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.976
X-Spam-Level:
X-Spam-Status: No, score=-102.976 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SNlNy7E7MD0n for <v6ops@ietfa.amsl.com>; Wed, 31 Oct 2012 17:59:09 -0700 (PDT)
Received: from mail-oa0-f44.google.com (mail-oa0-f44.google.com [209.85.219.44]) by ietfa.amsl.com (Postfix) with ESMTP id EF81721F86BE for <v6ops@ietf.org>; Wed, 31 Oct 2012 17:59:08 -0700 (PDT)
Received: by mail-oa0-f44.google.com with SMTP id n5so2223256oag.31 for <v6ops@ietf.org>; Wed, 31 Oct 2012 17:59:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type:x-system-of-record; bh=I85GN4madcMhoKiO+NsI6JGTGVfdni1ijpbIqDJ/gjI=; b=EkOS4ApIP5U54NopZrq3dbmz0r1HSG3Y9TcuD163q2G8U5lv/vgRLtHXRs8TYBxRhV wyVtKJsWyykymHn8cI4QIuTupv/aYnTslFj14guOl0ZJt2R4nvCHrH4zPEfZSsdIwHbF M6bWdE+KvyyfZQoLTCUt/thAkx8JuspdAGuiRvJXz7mMpO8ODOymEJhoaY/E6ALA4mgo /gfZmFicVoWaHcN1H8rXbs8BMul/VLJwcHkTzRJDW0YdmAptF6CU9Zeje5cudDjaWpLz Je043Gv6mbIJd12YMiJ9wsUXDIkUnq5NSs6Gmhxo2jUDUG+L6oA+sb8WKH/Ov8LluR9r ubww==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type:x-system-of-record:x-gm-message-state; bh=I85GN4madcMhoKiO+NsI6JGTGVfdni1ijpbIqDJ/gjI=; b=IffJyuvqMUwErLlljeJvY/1BS2NuU49wO4B0tOpRJnY5yX0d91xDH5qUcbELFzm/5U WbPXsTvDYDr5+mZJ8Nts1E4Ys5MJlmbNorSphhi5bBQabzBjgU0DVFnf+6ZSRJkMVQkx zGgZxUfz7DovVw4oYA+n6gLL8KqKOYBJZmGtTW25kC+fJywpYmfm452KhPo2N2J8w8+l EhMeMmVBLCyko5qNCd3+JTwhVGAi0xN/YcwWLPB2AyZK00CwAR6TBk6UFsUyo8kYgBC/ cLydSBu0QzCnMsZCHKbxLH8LL7F7F2Z2ZdYv2rKHfjroa2sgI+3GS7nmPI1zGhZbjwT0 2njg==
Received: by 10.182.188.36 with SMTP id fx4mr7749475obc.6.1351731548466; Wed, 31 Oct 2012 17:59:08 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.182.176.106 with HTTP; Wed, 31 Oct 2012 17:58:48 -0700 (PDT)
In-Reply-To: <5091C787.6060403@isi.edu>
References: <201210161245.q9GCj0i26478@ftpeng-update.cisco.com> <E1829B60731D1740BB7A0626B4FAF0A65E0DEDF3A2@XCH-NW-01V.nw.nos.boeing.com> <507DA6A3.20807@inex.ie> <E1829B60731D1740BB7A0626B4FAF0A65E0DEDF3C3@XCH-NW-01V.nw.nos.boeing.com> <507DAB13.2010704@inex.ie> <E1829B60731D1740BB7A0626B4FAF0A65E0DEDF3CE@XCH-NW-01V.nw.nos.boeing.com> <507DDF8A.9010607@inex.ie> <E1829B60731D1740BB7A0626B4FAF0A65E0DEDF5AB@XCH-NW-01V.nw.nos.boeing.com> <BB219517-B488-4777-AE9C-35C57BE91263@kumari.net> <E1829B60731D1740BB7A0626B4FAF0A65E0DEDF778@XCH-NW-01V.nw.nos.boeing.com> <507F265E.6030000@inex.ie> <E1829B60731D1740BB7A0626B4FAF0A65E0DF5BFAE@XCH-NW-01V.nw.nos.boeing.com> <507F32DA.30600@inex.ie> <E1829B60731D1740BB7A0626B4FAF0A65E0DF5BFC3@XCH-NW-01V.nw.nos.boeing.com> <E1829B60731D1740BB7A0626B4FAF0A65E0DF5C234@XCH-NW-01V.nw.nos.boeing.com> <8C48B86A895913448548E6D15DA7553B18E941@xmb-rcd-x09.cisco.com> <5091907E.3090206@isi.edu> <CAKD1Yr2nzYmH07b=FXC4wQmYjC85vc6Sp2SzCsLVc8p7o_ayrg@mail.gmail.com> <5091C787.6060403@isi.edu>
From: Lorenzo Colitti <lorenzo@google.com>
Date: Thu, 01 Nov 2012 09:58:48 +0900
Message-ID: <CAKD1Yr1BvZQudt8nrcTaFtJRTVXWH6m5M68jJ2=rQmpG8i+KcQ@mail.gmail.com>
To: Joe Touch <touch@isi.edu>
Content-Type: multipart/alternative; boundary="f46d04463168c72fdc04cd648615"
X-System-Of-Record: true
X-Gm-Message-State: ALoCoQkGgEBEktzyf4hDZI45RvXsUcFoQ0EOzYtHqwiCm8jcVdXfHLOjAscqxeRE8TgB04RTmUG+lk/pNzE5dZDn6e9kOL6elV+wj7kUF/8oaEQPEPolqfl53gPL2x0dYWtpbkYJohiZdfdRa1XegjeD9+WxSZsvKuFPpxTVTbl0k95cYnCwzT9PJYvYmA3CgGZiQx7DwfDl
Cc: "v6ops@ietf.org" <v6ops@ietf.org>, "draft-taylor-v6ops-fragdrop@tools.ietf.org" <draft-taylor-v6ops-fragdrop@tools.ietf.org>
Subject: Re: [v6ops] new draft: draft-taylor-v6ops-fragdrop
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 Nov 2012 00:59:09 -0000

On Thu, Nov 1, 2012 at 9:51 AM, Joe Touch <touch@isi.edu> wrote:

> However, you've answered the key issue - this is not about fragments, but
> rather about two things:
>
> a) DPI
>         DPI cannot be done on packets with any options
>         so this either means operators need to ignore DPI
>         on such packets or drop them
>

I don't think we should use the term DPI, because we don't really have
consensus on what it means. I suspect some would assert that just looking
at layer 4 headers is not DPI and that it's only DPI if you look into layer
4 payloads as well.


> There are certainly places where DPI is expected (e.g., by a government),
> and so only DPI-capable packets are permitted, but this doesn't seem
> tenable anywhere except at the boundaries of customer networks (otherwise
> all encrypted traffic would be dropped all over the place, and that doesn't
> appear to be happening)
>

... and saying that looking at layer 4 headers is "DPI" will also lead to
this kind of confusion.