Re: [v6ops] draft-palet-v6ops-464xlat-opt-cdn-caches **Call for Adoption**

Ca By <cb.list6@gmail.com> Thu, 09 January 2020 14:22 UTC

Return-Path: <cb.list6@gmail.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9584C1200B9 for <v6ops@ietfa.amsl.com>; Thu, 9 Jan 2020 06:22:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.748
X-Spam-Level:
X-Spam-Status: No, score=-1.748 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JqxrVQfdyDJG for <v6ops@ietfa.amsl.com>; Thu, 9 Jan 2020 06:22:15 -0800 (PST)
Received: from mail-il1-x131.google.com (mail-il1-x131.google.com [IPv6:2607:f8b0:4864:20::131]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 79356120026 for <v6ops@ietf.org>; Thu, 9 Jan 2020 06:22:15 -0800 (PST)
Received: by mail-il1-x131.google.com with SMTP id t2so5808419ilq.9 for <v6ops@ietf.org>; Thu, 09 Jan 2020 06:22:15 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=1sW2EoanzFSqV1YY1VzqC5b64/EgK2GK8D0T2Vigi4w=; b=htbZG8RT/ZK9ud6q8T3HaG7E6nWTCRgJFVrnQ6vcdwAEv6JY4fk9k+e8wRahhIN9Kk zF73o4ZmIDtmVCuvVvrbYT5jfFYi/cR8VZsj53aISC51h/Bk0vPB0uXorLJfrwkPS33U GUR2sdLJnMwA+5ytytsqTLA9TDEiIEjZh6BxgmKCiWpdxJfl62ArcCndHtGkvMPoWUjC l1mkvGvR45qTZtIt0o8y+HyqevTgqDPXYJPVa7ezM3yC1rEDxFuDXDIeuZShdIXZOatY Ug0XrRr3HyhTfaAuSJl5ZIUFF5gcrbKAMAjEP6/309gbxDLd3N9Y+42EnTPYkMnUqZqa RM8Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=1sW2EoanzFSqV1YY1VzqC5b64/EgK2GK8D0T2Vigi4w=; b=G014TZ28D9zNReLe0eA7vGEHkbhNyLiNdTSa6YktSJ9JH/lFqSpuIXzmxj5znerspw SIErRjNvKdtBVXW+/6Jk1j2NTPgGHIf01dq7iNKjgAqXXaShTybbwVayLquiqLwZEmf4 9uIGl6Z63VCcdkRy84ffM18B1ZYgs9/L+QVgZaVG3EHWui2+85wP/YkSBRtd0mSFbDyB 9uvllwz3ih2kmSncAepX3s44wGpd9MLpVQdR9Ncfv1i/LzQZSVrqHuo379U+Ur+YTH+l y7k/YSVqFtkm3O/hvKGiSjG4XC32YClOLBIEnEm41etc9swtu4ExWLH8P0ka5fXpI5eT WO0w==
X-Gm-Message-State: APjAAAWXylhp+mXqXLxqI9j4SB/K0HrmPjuYxYZvvXaRX52+5g+y0Ize Qu77hAeeNZcPIFsu/s60VHSqkgIMDnGLMZCGZST8cA==
X-Google-Smtp-Source: APXvYqzXPcknxvZkZ//IYr2VNgEiZlm3L1wTXgSP2EZtJe2M/uRqhuzun9Eeo0Te/2uN3s0kSKwqL/eRi5AUyQL0vsw=
X-Received: by 2002:a92:7e0a:: with SMTP id z10mr7542191ilc.190.1578579734808; Thu, 09 Jan 2020 06:22:14 -0800 (PST)
MIME-Version: 1.0
References: <FFB9FE6E-D2D2-46A2-8F2A-DB4E5534FE3E@consulintel.es> <2020010616354842655859@chinatelecom.cn> <3d68d660-0b61-cfe3-43e7-14563c47413d@gmail.com> <2020010722094585159928@chinatelecom.cn> <4A39BB6A-6711-4B31-8122-3698FDD4AAAB@consulintel.es> <740e446e-a7f1-1b35-764d-98b26644fa01@si6networks.com>
In-Reply-To: <740e446e-a7f1-1b35-764d-98b26644fa01@si6networks.com>
From: Ca By <cb.list6@gmail.com>
Date: Thu, 09 Jan 2020 06:22:03 -0800
Message-ID: <CAD6AjGSAuukvhWqtgV99aGYENeV+5LD3GyryYyugNHFct6RZww@mail.gmail.com>
To: Fernando Gont <fgont@si6networks.com>
Cc: JORDI PALET MARTINEZ <jordi.palet=40consulintel.es@dmarc.ietf.org>, v6ops <v6ops@ietf.org>
Content-Type: multipart/alternative; boundary="00000000000057cf24059bb5bcbe"
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/n82qykysdYBCd8nZ6aaKMhjCeSA>
Subject: Re: [v6ops] draft-palet-v6ops-464xlat-opt-cdn-caches **Call for Adoption**
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Jan 2020 14:22:17 -0000

On Thu, Jan 9, 2020 at 5:09 AM Fernando Gont <fgont@si6networks.com> wrote:

> On 8/1/20 11:11, JORDI PALET MARTINEZ wrote:
> > Hi Chongfeng,
> >
> >
> >
> > In 464XLAT, the way you allocate ports to customers in the NAT64 is
> > typically much more efficient than in pre-allocation as done commonly in
> > CGN or even MAP.
>
> How do you mitigate the potential of DoS if you don't pre-allocate a
> range or number of ports to each customer?
>

Same way you do it in NAT44, you set an upper bounds on number of sessions
a user can dynamically create.



> Thanks,
> --
> Fernando Gont
> SI6 Networks
> e-mail: fgont@si6networks.com
> PGP Fingerprint: 6666 31C6 D484 63B2 8FB1 E3C4 AE25 0D55 1D4E 7492
>
>
>
>
> _______________________________________________
> v6ops mailing list
> v6ops@ietf.org
> https://www.ietf.org/mailman/listinfo/v6ops
>