[ippm] Re: WG Last Call: draft-ietf-ippm-alt-mark-deployme nt-05 (Ends 2026-05-28)
"Pinkert, Tjeerd" <tjeerd.pinkert=40siemens.com-Tr9gZwTxerDR74oF6e/[email protected]> Thu, 28 May 2026 16:12:41 +0000
| Newsgroups | gmane.ietf.ippm,gmane.ietf.bmwg |
|---|---|
| Message-ID | <DB9PR10MB59314877654629661A44EBB686092@DB9PR10MB5931.EURPRD10.PROD.OUTLOOK.COM> |
--===============1081513057947601024== Content-Language: en-US Content-Type: multipart/related; boundary="_004_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_"; type="multipart/alternative" --_004_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_ Content-Type: multipart/alternative; boundary="_000_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_" --_000_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Dear Guiseppe, A clarification in the draft would be appreciated. VPNs or IPsec tunnels are rigid methods of creating user-domains, so that i= s always possible. When asking the question, I was thinking about something else, namely, the = cases where such virtual networks are not used or not necessarily needed. E.g. in situations where the network is controlled by entity A and entity B= uses that network. When entity B, partially trusts entity A (e.g. that the network provided is= private), but still has need to check the quality. When entity A and B use the same alternate marker technology (and B signs),= what measures must the network owner (A) take to honour the network user (= B) his alternate markers? Is that possible with the currently designed methods? (Should it be?) Slightly OT some thoughts on use of the DSCP field: When using DSCP, or the reserved Flag on IPv4 (these were exactly the field= s I had in mind as usable). A signature over the IP header, added as IP option could be a possibility f= or the user to ensure that the packet was not manipulated. Internal to the controlled domain, the DSCP field should than not be change= d uncontrolled (e.g. it should be reset to the original value on exit of th= e controlled domain). DSCP has the disadvantage of being designed to be changed by nodes an-route= , especially when certain traffic classes are used. The DSCP field is thus basically only possible for a controlled domain, not= for an end-user, unless this would be explicitly specified by the network = owner how to do this. In my I-D for the IP measurement option, I added a flag field as alternate = marker, that could be used when the DSCP field is not feasible. All other fields can be zeroed out in that case. Next to that, it contains = the possibility of adding a cryptographic signature. In that sense it would be usable for both controlled and end-user domains. Best regards, Tjeerd From: Giuseppe Fioccola <[email protected]> Sent: Donnerstag, 28. Mai 2026 16:20 To: Pinkert, Tjeerd (SMO RI ML COC SM 2) <[email protected]>; draf= [email protected]; IPPM Chairs <[email protected]= >; [email protected]; [email protected]; [email protected] Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Hi Tjeerd, I agree with you regarding the use of cryptography for the controlled domai= n. Indeed, if you look at section 2.1 of RFC9343, it is also mentioned that= multiple domains can create a whole controlled domain while traversing the= external domain by employing IPsec authentication and encryption or other = VPN technology. I can clarify this point in draft-ietf-ippm-alt-mark-deploy= ment too. Regarding the AltMark encapsulations, note that RFC9343 defines the extensi= on for IPv6, while in RFC9714 it is defined the extension for MPLS. There i= s no standard extension for IPv4, but, just to satisfy your curiosity, we i= nitially experimented the method by marking the DSCP field (see RFC8321) or= the last reserved bit of the Flag field (see draft-chen-ippm-coloring-base= d-ipfpm-framework). Other extensions are in progress, as you can notice in section 8 of draft-i= etf-ippm-alt-mark-deployment. Regards, Giuseppe From: Pinkert, Tjeerd <[email protected]<mailto:tjeerd.pinkert@sie= mens.com>> Sent: Wednesday, May 27, 2026 3:10 PM To: Giuseppe Fioccola <[email protected]<mailto:giuseppe.fioccol= [email protected]>>; [email protected]<mailto:draft-i= [email protected]>; IPPM Chairs <[email protected]<m= ailto:[email protected]>>; [email protected]<mailto:[email protected]>; bmwg@iet= f.org<mailto:[email protected]>; [email protected]<mailto:[email protected]= rg> Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Dear Guiseppe, OK, so that scenario is possible. You may notice that I am interested in the network performance from the net= work user perspective. It is the question if the user domain could form such a controlled domain, = and the packets are allowed to travel though a foreign domain. >From a security perspective, one needs to know one thing: was my packet (th= e alternate marker) manipulated by the foreign domain? This can be achieved with cryptographic signatures, so that would need to b= e designed into the measurement protocols (alternate marker data). (Removal of alternate marker data is also a manipulation of the packet and = can be detected by the user.) I think a controlled user domain would be characterised by a shared secret = for signing / encryption. A user on the network edge, owning ten- to hundred-thousand machines formin= g a distributed system, is a common use-case. In particular, when the distributed system must be capable of adjusting to = the network conditions, alternate marking methods could also be used. Then the use of alternate markers by the user and the network owner should = not collide. One (off topic) thing I would be interested in, is what fields are typicall= y used for alternate marking methods, and if signatures come into question = for that? Best regards, Tjeerd From: Giuseppe Fioccola <[email protected]<mailto:giuseppe.fiocc= [email protected]>> Sent: Donnerstag, 21. Mai 2026 10:32 To: Pinkert, Tjeerd (SMO RI ML COC SM 2) <[email protected]<mailto= :[email protected]>>; [email protected]= <mailto:[email protected]>; IPPM Chairs <ippm-ch= [email protected]<mailto:[email protected]>>; [email protected]<mailto:ippm@ietf= .org>; [email protected]<mailto:[email protected]>; [email protected]<mailto:bmw= [email protected]> Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Hi Tjeerd, Thank you for the question. Yes, it would be possible. But, for security reasons, In-Data-Packet OAM me= thods, such as Alternate-Marking and IOAM, should be applied to limited/con= trolled domains. You can find more details about this requirement in RFC 93= 41 and RFC 9197. It was initially discussed in RFC 8799. Regards, Giuseppe From: Pinkert, Tjeerd <[email protected]<mailto:tjeerd.pinkert@sie= mens.com>> Sent: Wednesday, May 20, 2026 4:19 PM To: [email protected]<mailto:draft-ietf-ippm-alt= [email protected]>; IPPM Chairs <[email protected]<mailto:ippm-c= [email protected]>>; [email protected]<mailto:[email protected]>; [email protected]<mailto= :[email protected]>; [email protected]<mailto:[email protected]> Subject: Re: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202= 6-05-28) Dear all, I'm just wondering, can internet users form a controlled (boundary) domain = and apply the alternate marking method independently of the controlled netw= ork domain? This should be possible, but is not very deeply explored? (Or maybe I'm just missing the point, and the remarks on encapsulating traf= fic cover this sufficiently?) With best regards, Dr. Tjeerd Pinkert Siemens Mobility GmbH Mobility Rail Infrastructure System Management 2 SMO RI ML COC SM 2 Ackerstr. 22 38126 Braunschweig, Germany Phone: +49 (1520) 2884088 Mobile: +49 (1520) 2884088 mailto:[email protected] www.siemens.com<https://www.siemens.com> [Logo] Siemens Mobility GmbH; Chairman of the Supervisory Board: Roland Busch; Man= agement Board: Beatrice Bock, Michael Peter; Registered office: Munich, Ger= many; Commercial registry Munich, HRB 237219; WEEE-Reg.-No. DE 92917817 --_000_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr= osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:= //www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"= > <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)"> <!--[if !mso]><style>v\:* {behavior:url(#default#VML);} o\:* {behavior:url(#default#VML);} w\:* {behavior:url(#default#VML);} .shape {behavior:url(#default#VML);} </style><![endif]--><style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Aptos;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; font-size:10.0pt; font-family:"Calibri",sans-serif; mso-ligatures:standardcontextual;} a:link, span.MsoHyperlink {mso-style-priority:99; color:#0563C1; text-decoration:underline;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt; mso-ligatures:none;} @page WordSection1 {size:612.0pt 792.0pt; margin:72.0pt 72.0pt 72.0pt 72.0pt;} div.WordSection1 {page:WordSection1;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--> </head> <body lang=3D"EN-GB" link=3D"#0563C1" vlink=3D"#954F72" style=3D"word-wrap:= break-word"> <div class=3D"WordSection1"> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Dear Guiseppe,<o:p>= </o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">A clarification in = the draft would be appreciated.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">VPNs or IPsec tunne= ls are rigid methods of creating user-domains, so that is always possible.<= o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When asking the que= stion, I was thinking about something else, namely, the cases where such vi= rtual networks are not used or not necessarily needed.<o:p></o:p></span></p= > <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">E.g. in situations = where the network is controlled by entity A and entity B uses that network.= <o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When entity B, part= ially trusts entity A (e.g. that the network provided is private), but stil= l has need to check the quality.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When entity A and B= use the same alternate marker technology (and B signs), what measures must= the network owner (A) take to honour the network user (B) his alternate ma= rkers?<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Is that possible wi= th the currently designed methods? (Should it be?)<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Slightly OT some th= oughts on use of the DSCP field:<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When using DSCP, or= the reserved Flag on IPv4 (these were exactly the fields I had in mind as = usable).<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">A signature over th= e IP header, added as IP option could be a possibility for the user to ensu= re that the packet was not manipulated.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Internal to the con= trolled domain, the DSCP field should than not be changed uncontrolled (e.g= . it should be reset to the original value on exit of the controlled domain= ).<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">DSCP has the disadv= antage of being designed to be changed by nodes an-route, especially when c= ertain traffic classes are used.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">The DSCP field is t= hus basically only possible for a controlled domain, not for an end-user, u= nless this would be explicitly specified by the network owner how to do thi= s.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">In my I-D for the I= P measurement option, I added a flag field as alternate marker, that could = be used when the DSCP field is not feasible.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">All other fields ca= n be zeroed out in that case. Next to that, it contains the possibility of = adding a cryptographic signature.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">In that sense it wo= uld be usable for both controlled and end-user domains.<o:p></o:p></span></= p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Best regards,<o:p><= /o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><br> Tjeerd<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><o:p> </o:p></p> <div> <div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm = 0cm 0cm"> <p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;ms= o-ligatures:none">From:</span></b><span lang=3D"EN-US" style=3D"font-size:1= 1.0pt;mso-ligatures:none"> Giuseppe Fioccola <[email protected]= om> <br> <b>Sent:</b> Donnerstag, 28. Mai 2026 16:20<br> <b>To:</b> Pinkert, Tjeerd (SMO RI ML COC SM 2) <tjeerd.pinkert@siemens.= com>; [email protected]; IPPM Chairs <ippm= [email protected]>; [email protected]; [email protected]; [email protected]<br= > <b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (E= nds 2026-05-28)<o:p></o:p></span></p> </div> </div> <p class=3D"MsoNormal"><o:p> </o:p></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Hi T= jeerd,<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p= > </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">I ag= ree with you regarding the use of cryptography for the controlled domain. I= ndeed, if you look at section 2.1 of RFC9343, it is also mentioned that mul= tiple domains can create a whole controlled domain while traversing the external domain by employing IPsec authenticat= ion and encryption or other VPN technology. I can clarify this point in dra= ft-ietf-ippm-alt-mark-deployment too.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p= > </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Rega= rding the AltMark encapsulations, note that RFC9343 defines the extension f= or IPv6, while in RFC9714 it is defined the extension for MPLS. There is no= standard extension for IPv4, but, just to satisfy your curiosity, we initially experimented the method by marking= the DSCP field (see RFC8321) or the last reserved bit of the Flag field (s= ee draft-chen-ippm-coloring-based-ipfpm-framework).<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Othe= r extensions are in progress, as you can notice in section 8 of draft-ietf-= ippm-alt-mark-deployment.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p= > </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p= > </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Rega= rds,<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p= > </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Gius= eppe<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p= > </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p= > </o:p></span></p> <div> <div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm = 0cm 0cm"> <p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;ms= o-ligatures:none">From:</span></b><span lang=3D"EN-US" style=3D"font-size:1= 1.0pt;mso-ligatures:none"> Pinkert, Tjeerd <<a href=3D"mailto:tjeerd.pin= [email protected]">[email protected]</a>> <br> <b>Sent:</b> Wednesday, May 27, 2026 3:10 PM<br> <b>To:</b> Giuseppe Fioccola <<a href=3D"mailto:giuseppe.fioccola@huawei= .com">[email protected]</a>>; <a href=3D"mailto:[email protected]">draft-ietf-= [email protected]</a>; IPPM Chairs <<a href=3D"mailto:ip= [email protected]">[email protected]</a>>; <a href=3D"mailto:[email protected]">[email protected]</a>; <a href=3D"mailto:bmwg@= ietf.org"> [email protected]</a>; <a href=3D"mailto:[email protected]">bmwg-chairs@ietf= .org</a><br> <b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (E= nds 2026-05-28)<o:p></o:p></span></p> </div> </div> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Dear Guiseppe,<o:p>= </o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">OK, so that scenari= o is possible.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">You may notice that= I am interested in the network performance from the network user perspecti= ve.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">It is the question = if the user domain could form such a controlled domain, and the packets are= allowed to travel though a foreign domain.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">From a security per= spective, one needs to know one thing: was my packet (the alternate marker)= manipulated by the foreign domain?<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">This can be achieve= d with cryptographic signatures, so that would need to be designed into the= measurement protocols (alternate marker data).<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">(Removal of alterna= te marker data is also a manipulation of the packet and can be detected by = the user.)<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">I think a controlle= d user domain would be characterised by a shared secret for signing / encry= ption.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">A user on the netwo= rk edge, owning ten- to hundred-thousand machines forming a distributed sys= tem, is a common use-case.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">In particular, when= the distributed system must be capable of adjusting to the network conditi= ons, alternate marking methods could also be used.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Then the use of alt= ernate markers by the user and the network owner should not collide.<o:p></= o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">One (off topic) thi= ng I would be interested in, is what fields are typically used for alternat= e marking methods, and if signatures come into question for that?<o:p></o:p= ></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Best regards,<o:p><= /o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Tjeerd<o:p></o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><o:p> </o:p></p> <div> <div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm = 0cm 0cm"> <p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;ms= o-ligatures:none">From:</span></b><span lang=3D"EN-US" style=3D"font-size:1= 1.0pt;mso-ligatures:none"> Giuseppe Fioccola <</span><span lang=3D"EN-US= "><a href=3D"mailto:[email protected]"><span style=3D"font-size:= 11.0pt;mso-ligatures:none">[email protected]</span></a></span><s= pan lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">> <br> <b>Sent:</b> Donnerstag, 21. Mai 2026 10:32<br> <b>To:</b> Pinkert, Tjeerd (SMO RI ML COC SM 2) <</span><span lang=3D"EN= -US"><a href=3D"mailto:[email protected]"><span style=3D"font-size= :11.0pt;mso-ligatures:none">[email protected]</span></a></span><sp= an lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">>; </span><span lang=3D"EN-US"><a href=3D"mailto:draft-ietf-ippm-alt-mark-depl= [email protected]"><span style=3D"font-size:11.0pt;mso-ligatures:none">draft-= [email protected]</span></a></span><span lang=3D"EN-US= " style=3D"font-size:11.0pt;mso-ligatures:none">; IPPM Chairs <</span><span lang=3D"EN-US"><a href=3D"mailto:ippm-chairs@= ietf.org"><span style=3D"font-size:11.0pt;mso-ligatures:none">ippm-chairs@i= etf.org</span></a></span><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso= -ligatures:none">>; </span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span style=3D= "font-size:11.0pt;mso-ligatures:none">[email protected]</span></a></span><span = lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">; </span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span style=3D= "font-size:11.0pt;mso-ligatures:none">[email protected]</span></a></span><span = lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">; </span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span s= tyle=3D"font-size:11.0pt;mso-ligatures:none">[email protected]</span></a= ></span><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">= <br> <b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (E= nds 2026-05-28)<o:p></o:p></span></p> </div> </div> <p class=3D"MsoNormal"><o:p> </o:p></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Hi T= jeerd,<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Than= k you for the question.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Yes,= it would be possible. But, for security reasons,</span><span lang=3D"EN-US= "> </span><span lang=3D"EN-US" style=3D"font-size:11.0pt">In-Data-Packet OAM m= ethods, such as Alternate-Marking and IOAM, should be applied to limited/co= ntrolled domains. You can find more details about this requirement in RFC 9= 341 and RFC 9197. It was initially discussed in RFC 8799.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p= > </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Rega= rds,<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p= > </o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Gius= eppe<o:p></o:p></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p= > </o:p></span></p> <div> <div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm = 0cm 0cm"> <p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;ms= o-ligatures:none">From:</span></b><span lang=3D"EN-US" style=3D"font-size:1= 1.0pt;mso-ligatures:none"> Pinkert, Tjeerd <</span><span lang=3D"EN-US">= <a href=3D"mailto:[email protected]"><span style=3D"font-size:11.0= pt;mso-ligatures:none">[email protected]</span></a></span><span la= ng=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">> <br> <b>Sent:</b> Wednesday, May 20, 2026 4:19 PM<br> <b>To:</b> </span><span lang=3D"EN-US"><a href=3D"mailto:draft-ietf-ippm-al= [email protected]"><span style=3D"font-size:11.0pt;mso-ligatures:n= one">[email protected]</span></a></span><span la= ng=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">; IPPM Chairs <</span><span lang=3D"EN-US"><a href=3D"mailto:ippm-chairs@= ietf.org"><span style=3D"font-size:11.0pt;mso-ligatures:none">ippm-chairs@i= etf.org</span></a></span><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso= -ligatures:none">>; </span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span style=3D= "font-size:11.0pt;mso-ligatures:none">[email protected]</span></a></span><span = lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">; </span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span style=3D= "font-size:11.0pt;mso-ligatures:none">[email protected]</span></a></span><span = lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">; </span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span s= tyle=3D"font-size:11.0pt;mso-ligatures:none">[email protected]</span></a= ></span><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">= <br> <b>Subject:</b> Re: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (E= nds 2026-05-28)<o:p></o:p></span></p> </div> </div> <p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p> </o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Dear all,<o:p></o:p= ></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">I’m just wond= ering, can internet users form a controlled (boundary) domain and apply the= alternate marking method independently of the controlled network domain?<o= :p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">This should be poss= ible, but is not very deeply explored?<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">(Or maybe I’m= just missing the point, and the remarks on encapsulating traffic cover thi= s sufficiently?)<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"font-family:"Arial",sans-se= rif;color:black;mso-ligatures:none">With best regards,<br> Dr. Tjeerd Pinkert<br> <br> Siemens Mobility GmbH<br> Mobility<br> Rail Infrastructure<br> System Management 2<br> SMO RI ML COC SM 2<br> Ackerstr. 22<br> 38126 Braunschweig, Germany<br> Phone: +49 (1520) 2884088<br> Mobile: +49 (1520) 2884088<br> </span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><= span lang=3D"EN-GB" style=3D"font-family:"Arial",sans-serif;color= :blue;mso-ligatures:none">mailto:[email protected]</span></a></spa= n><span style=3D"font-family:"Arial",sans-serif;color:black;mso-l= igatures:none"><br> </span><span lang=3D"EN-US"><a href=3D"https://www.siemens.com" target=3D"_= blank"><span lang=3D"EN-GB" style=3D"font-family:"Arial",sans-ser= if;color:blue;mso-ligatures:none">www.siemens.com</span></a></span><span st= yle=3D"font-family:"Arial",sans-serif;color:black;mso-ligatures:n= one"><br> <img border=3D"0" width=3D"202" height=3D"80" style=3D"width:2.1041in;heigh= t:.8333in" id=3D"Picture_x0020_1" src=3D"cid:image001.gif-I/[email protected]= " alt=3D"Logo"><br> </span><span style=3D"font-size:8.0pt;font-family:"Arial",sans-se= rif;color:black;mso-ligatures:none">Siemens Mobility GmbH; Chairman of the = Supervisory Board: Roland Busch; Management Board: Beatrice Bock, Michael P= eter; Registered office: Munich, Germany; Commercial registry Munich, HRB 237219; WEEE-Reg.-No. DE 92917817</span><o:p></o:p></= p> </div> </body> </html> --_000_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_-- --_004_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_ Content-Type: image/gif; name="image001.gif" Content-Description: image001.gif Content-Disposition: inline; filename="image001.gif"; size=2730; creation-date="Thu, 28 May 2026 16:12:40 GMT"; modification-date="Thu, 28 May 2026 16:12:41 GMT" Content-ID: <image001.gif-I/[email protected]> Content-Transfer-Encoding: base64 R0lGODlhygBQAPcAAAAAAP///wCZmQCamgCYmACXlwCUlACTkwCRkQCOjgCNjQCLiwKamgKZmQKT kwOXlwSZmQSVlQWamgWXlwabmwaXlweZmQiYmAmbmwmXlwqdnQqamgqWlguZmQ2eng2amg6cnA2X lw6amhCfnxGcnBGbmxKcnBOenhKWlhSfnxWdnRafnxeiohehoRednRihoRmfnxqiohugoBygoBub mx2jox6kpB6ioiCkpB+hoSCjoyChoSKlpSKioiWnpySkpCenpyelpSqrqymoqCmnpyikpCqoqCun pyqlpSqjoyyqqiypqS6pqS+qqi6npzCrqzKrqzGoqDOsrDStrTWurjatrTWrqzeurjeqqjmtrTuw sDqsrD2xsT+ysj2trT+xsT6urj+vr0Kzs0GxsUCurkCtrUO0tEKxsUOyska0tEe1tUezs0m2tkex sUm1tUiysku2tky3t0y1tU+4uE63t020tE2zs1C4uE+1tVG3t1K4uFW7u1W5uVe6ule5uVq8vFu7 u129vV27u1+9vWC+vmG/v2C9vWK/v2TBwWPAwGfDw2bAwGnCwmvDw2nAwGrAwG3ExGzCwm/FxXPH x3HDw3XGxn3Ly3rGxn3JyYDMzH/Ly4HLy4XOzofPz4XMzIfNzYnPz4jNzYrPz43S0ovQ0IzQ0I7R 0ZHS0pHR0ZTU1JPT05LR0ZfW1pXT05fV1ZjV1ZnW1prW1prU1J3Y2J3X15/Y2J7X153V1aLa2qHY 2KXb26PZ2afb26nc3Kve3qnb263f36vd3azd3a/f37Lh4bHg4LDf37Xh4bfi4rbg4Lvk5L3m5rvj 473l5b/m5r7l5cHn58Ln58bp6cTn58nq6sbn58rq6sjo6Mzr687s7NHt7dPt7dXu7tnw8Nrw8Nnv 793y8tzx8d/z8+H09OL09OHz8+T19eLz8+f29un39+f19ev4+Or39+75+fH6+u/4+PH5+fX8/PP6 +vX7+/f8/Pb7+/n9/fv+/vr9/fz+/v7//////wAAAAAAAAAAAAAAACH/C05FVFNDQVBFMi4wAwEA AAAh+QQFAAD7ACwAAAAAygBQAAAI/wADCBxIsKDBgwgTKlzIsKHDhxAjSpxIsaLFixgzatzIsaPH jyBDihxJsqTJkyhTqlzJsqXLlzBjypxJs6bNmzhz6tzJs6fPn0CDCh1KtKjRo0iTKl3KtKnTp1Cj Sp1KtarVq1izat3KtavXr2DDih1LtqzZs2gh5ku37Zo2cvX0GcxHt27Bunjz0pUrMN+9vAv16b37 V29evgEEA55rF6G7btaseWuXbym2UGhaUIBAYcQQOpe0EZwEBg0aL47aDUwnqLTp17DRlME1sNQW 2GEI2UPYrc6X12H8mBt4D5OX2MjBWBqIjMyZ115q3V0U5ksd0QTR2QLEQwMECRpsfP95FAypKBMI DhQgwL5AgQMKQBHkksCAgQRO0A0Ul6O+/f8A3qfJQIQoAOABByCDkCUG/oeACt0MZI8dDQYIYAJs DMRKAgf8l8AQ9BB0DxEIIMDBMwQpEwWC67FHQAEGKEDFUad0OIAABnQIo30ImEKQGgYIIMABVqQz EDlBBCnAADsGmEAmAyFygJBUGqDHQflMYcCNQhpwQzgS5jHlkgRYeB8cA81iAAFU4piKiFAYUEAJ 0QyEzQkILPnefx0i0IVR2qgQ5ItMaNJLMKxAUgUKpfyoJJFGCoSkkgS0sIQRmGaaxCtRjkllASZQ Y9AzD7SJ45dhjkmAB5dmimkSkKT/uWabBuCgDnFxzllnAPjAkacABazAyC7C5GKJGzT8WVQnB7Bp ABD6EUTPNN84KiSkRyZ5rSbyvOPtt++EKJCUpg65XEF6eNolqgLZI2aXcXQLrrfzyMomlQQcgAmu ctIpEDYqFADsB8MYxM00RiHyqwFUVLYQkNcWme2jnTBELrBUHnBGvXaSIPC9p4LZ7rtDXrmQmmyC fMARkd6Tq78B+DKBwAWoYI1TiqhKAB7VPPyoxJJqOyQnFjfLgBD3FvAAigNZggB7PkiwrsgBuDvm AXcwhLIAFAh8bcUBuNzvrsNU4HUBRNjiDlM1qrzBIcSIaxDEQwIdwKTXNrqQlC9y/+KD1wcEMpA8 Y6jXAiMXTJ3qtXtovaYBd1yhZAEtgBP2y7tyA4OSOGoMSzlKmaODp0wicEEWvSA2EN3YBj35FIkU Irvsf0hDELkHAPPJmAVgUG0AyERAAAKE6FJqyIsDa0PssxcCiC4EoXxAJcQ0KyQCklw+tkD6JPKr kPka0IMm7yQVTAfqAtshHzdbW3ekdwutPoL0K0DL7VMe4Is2D9x7wLnpIkAEiCEMJXmJalb7FP3q 54jorekAjEjHEcZkAB7cCnMDOQcTEFAALgmgTAhgwi7wgRRkYKFDpspXCWizup/BD29Ces8C4TML /A0JF/OowtW4oA9tWKBMVaAHLf8oyK6qkWx+C1TAIxyYr0MEgBUOSJm+AiCF7Q0EHIEwwNNMlaNF qOYo7IhFFuzjtSUd4ALKaGHEXii0AiyhD3qIYxzrwLRx5a+GprBeATogjVLkr1GxICICSVaAGPBB jnG0wy2YeABCBGAeX5hcCrLBBSsOJB/HAMQF1AOyAiTgXEipRy64kIFZXW8RfGGd3WB4gIrp45Ww LAjuaiiOGxjwD1xYjwW4EYBAKm5kV7sSLGPJSEcGoBeeQkAlxGDJgkwjEC5QT8Z+QI6l2OMYfVjP taqwDoGoko2PItre7igQSHCuAWbsg1x8iTxgXitrJ3ugMd1hhS0B6wUseBHMEIL/jUyA4GwFaEZT 6OEGAwZhHN504cSuJU6FzFIgyiijiwrADIGw84DJw5rj8mXMABjDlNrUFUNOQSkDAIMo+FDdaK62 hfIF4JsLHZKPxjmkGgaAHk3g3JDWwLGLFjGBQ2pcPDlKHD58L4Ywy8duDoKN/n2wANAgCjUM4Qpl ZIMc7niHN3pRA68hoBFqfF9MDTCHWMDirGhNhYLsWNOB1AhfBxjFQHw6SAo+waxoPWsqeBEPgUiv o8DLQBmBBTN6SMISxaBGON4BD3I4g3VHiJZQlHEABHwABj9QghFuMLNrhUCgCV1jTIFlpgSYoVNt FUg5eGDAE2Cnl4JMHmkthIAd/0Trr9JKg7pEetMhJOACKtCBEZbwgxJM7pNFWYYI5OQeMhKgdCS4 X1hbFz/Ouei6+coQWw9gU4FMYkoDCBxB6CrbD2K3TD+IFG4JEo0ffgpm9piCeppLxmsdwIvJrQCH EGQfBHGwDVEliBYUgCAFIEGy4pABgWc4QwWIYSCBWAB8WEGQYZQIAQaw3UBaseAEnMAbEnqDhBm8 wATMIFobQsAC+mCQQiz4AAmIAGjxIYX98jdHCCqCKo4Cj2KcAhOGkMMYxiCHSJQCGfIwiDFQoQpV rOIXfRWIPHaxiiZb+cpNXkUxBtIMJqOClwNpxycoQQlSqI4bVXZyLeBxyWQwGXTLWF7FLjiGZidX tCDgeLMqTiGL4QjkGq/wRCTugIYvpGEQm9DFOZqiGJWmZSCKcdijJ03pSlv60pjOtKY3zelOe/rT oA61qEdN6lKb+tSoTrWqV83qVrv61bCOtaxnTeta2/rWuM61rnfN6177+tfAtklAAAA7 --_004_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_-- --===============1081513057947601024== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KaXBwbSBtYWls aW5nIGxpc3QgLS0gaXBwbUBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv IGlwcG0tbGVhdmVAaWV0Zi5vcmcK --===============1081513057947601024==--