Re: [v6ops] draft-ietf-v6ops-balanced-ipv6-security WGLC

Tarko Tikan <tarko@lanparty.ee> Wed, 13 November 2013 21:25 UTC

Return-Path: <tarko@lanparty.ee>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0882321E80B4 for <v6ops@ietfa.amsl.com>; Wed, 13 Nov 2013 13:25:18 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.499
X-Spam-Level:
X-Spam-Status: No, score=-2.499 tagged_above=-999 required=5 tests=[AWL=0.100, BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZKae3G82RpSt for <v6ops@ietfa.amsl.com>; Wed, 13 Nov 2013 13:25:12 -0800 (PST)
Received: from valgus.lanparty.ee (valgus.lanparty.ee [194.126.124.108]) by ietfa.amsl.com (Postfix) with ESMTP id 15F0921E80B3 for <v6ops@ietf.org>; Wed, 13 Nov 2013 13:25:11 -0800 (PST)
Received: from hg.lanparty.ee ([194.126.106.156] helo=[10.10.10.22]) by valgus.lanparty.ee with esmtpsa (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.72) (envelope-from <tarko@lanparty.ee>) id 1Vghvy-000098-2E; Wed, 13 Nov 2013 23:25:10 +0200
Message-ID: <5283EE36.5060607@lanparty.ee>
Date: Wed, 13 Nov 2013 23:25:10 +0200
From: Tarko Tikan <tarko@lanparty.ee>
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:24.0) Gecko/20100101 Thunderbird/24.0
MIME-Version: 1.0
To: Ted Lemon <Ted.Lemon@nominum.com>
References: <201311101900.rAAJ0AR6025350@irp-view13.cisco.com> <CAB0C4xOfz_JAjEEJZ-Zz7MBEyZhVzrAE+8Ghf1ggC3+9pyHmNg@mail.gmail.com> <989B8ED6-273E-45D4-BFD8-66A1793A1C9F@cisco.com> <52833B8F.10708@lanparty.ee> <A453058E-C40C-4D3A-83F0-FB6851A501DD@nominum.com> <5283A1AF.1070806@lanparty.ee> <0B7E8354-F5DE-4E18-A4A5-2D2E6B999CBB@nominum.com>
In-Reply-To: <0B7E8354-F5DE-4E18-A4A5-2D2E6B999CBB@nominum.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 7bit
X-SA-Exim-Connect-IP: 194.126.106.156
X-SA-Exim-Mail-From: tarko@lanparty.ee
X-SA-Exim-Version: 4.2.1 (built Mon, 22 Mar 2010 06:51:10 +0000)
X-SA-Exim-Scanned: Yes (on valgus.lanparty.ee)
Cc: "v6ops@ietf.org WG" <v6ops@ietf.org>
Subject: Re: [v6ops] draft-ietf-v6ops-balanced-ipv6-security WGLC
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Nov 2013 21:25:18 -0000

hey,

> You completely missed my point.   Do you really want your ISP filtering your data stream?

No I didn't.

As a provider I worry about DOS hitting my ANs and worms/viruses 
spreading in my network.

As a customer I worry about getting hacked (which didn't happen with v4 
NAT - not a strong argument ofc as customers mostly get infected via 
drive-by malware these days). I also want to manage it myself to some 
level, minimally just enable/disable.

We currently provide stateless filter for our broadband customers. 
Filtering is done in edge routers and not CPE. Unfortunately customers 
can't customize the rules because it just wouldn't scale today (would 
need to create ACL for every customer).

-- 
tarko