Re: AD Review of draft-ietf-idr-rfc5575bis-17 -> Updated Version -18 and Flowspec v6

Jeffrey Haas <[email protected]> Wed, 18 Dec 2019 11:54:35 -0500
Newsgroups gmane.ietf.idr
Message-ID <[email protected]>
Alvaro,

[choosing the most terse response]

On Wed, Dec 18, 2019 at 08:17:05AM -0800, Alvaro Retana wrote:
> > On Wed, Dec 18, 2019 at 08:11:37AM +0100, Christoph Loibl wrote:
> > > > You can't parse it, therefore it's malformed.
> =

> Jeff: I interpreted this response as agreeing that if the NLRI can't
> be parsed then it should be discarded (even maybe buying the Typed
> NLRI argument). =A0It sounds like we're agreeing. =A0Is that true?

[...]

> Personal opinion: =A0If we (WG) don't buy into the Typed NLRI-like
> argument, then we deal with the "entire NLRI field", but we're also
> stuck with AFI/SAFI disable (or session reset). =A0If we buy into the
> Typed NLRI-like argument, then it seems like we have the option to
> specify either discard behavior.

IMO, the typed NLRI argument was poorly thought through.  It effectively
devolves into a form of the issues above.  The issue in both cases is that
it's impossible to tell that you're dealing with garbage or not.  The choice
made in that section was discard with exactly the same risks I mentioned.

If the WG converges on discard, so be it.  If an implementation and a
network roll the dice in a lucky fashion, they only encounter such issues
for well-formed unknowns that are discarded.  If not, they get to manually
bounce their peering session.

The fix for flowspec really should be flowspec v2 or capabilities based fix
for later extensions.  The fix for the typed NLRI is effectively similar.

-- Jeff

_______________________________________________
Idr mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/idr