[Int-area] Re: [IPv6]ICMP Query and ICMP Query for IOAM

"Bonica, Ron" <[email protected]> Thu, 26 Feb 2026 16:25:32 +0000
Newsgroups gmane.ietf.int,gmane.ietf.ipv6
Message-ID <DM4PR84MB2310D30484F0AA741AC921B7F472A@DM4PR84MB2310.NAMPRD84.PROD.OUTLOOK.COM>
--===============8447395306282590160==
Content-Language: en-US
Content-Type: multipart/alternative;
 boundary="_000_DM4PR84MB2310D30484F0AA741AC921B7F472ADM4PR84MB2310NAMP_"

--_000_DM4PR84MB2310D30484F0AA741AC921B7F472ADM4PR84MB2310NAMP_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

Paul,

Because this issue touches many ICMP messages, I think that it belongs in a=
 separate document.

Do you want to produce the first draft or should I?

                                                                           =
                     Ron



________________________________
From: Paul Vixie <[email protected]>
Sent: Thursday, February 26, 2026 3:20 AM
To: Bonica, Ron <[email protected]>
Cc: Sebastian Moeller <[email protected]>; [email protected]=
om.cn <[email protected]>; [email protected] <[email protected]>; ipv6@i=
etf.org <[email protected]>
Subject: Re: [Int-area] Re: [IPv6]ICMP Query and ICMP Query for IOAM

Yes, at a minimum.
Paul Vixie

Feb 25, 2026 16:23:33 Bonica, Ron <[email protected]>:

Hi Paul,

I think that your statement applies even more globally.

Would it make sense to apply the following rate limits:


  *
A less strict rate limit, applied to all ICMP messages. (Already recommende=
d in RFC 1812 and widely deployed).
  *
A more strict rate limit, applied to some informational messages (e.g., Ech=
o, Extended Echo, Query)

                                                                           =
                            Ron
________________________________
From: Paul Vixie <[email protected]>
Sent: Wednesday, February 25, 2026 7:47 AM
To: Sebastian Moeller <[email protected]>
Cc: [email protected] <[email protected]>; [email protected] <int-are=
[email protected]>; [email protected] <[email protected]>
Subject: [Int-area] Re: [IPv6]ICMP Query and ICMP Query for IOAM

I think relative request to response size is the wrong control point. Here'=
s how we reasoned it for DNS RRL:

<<One important principle of DNS RRL's design is that it makes a DNS server=
 into a DDoS attenuator=97it causes not just lack of amplification, but als=
o an actual reduction in traffic volume compared with what an attacker coul=
d achieve by sending the packets directly. Just as importantly, this attenu=
ation is not only in the number of bits per second, but also in the number =
of packets per second. That's important in a world full of complex stateful=
 firewalls where the bottleneck is often in the number of packets, not bits=
, and processing a small packet costs just as much in terms of firewall cap=
acity as processing a larger packet.>>

https://queue.acm.org/detail.cfm?id=3D2578510
Paul Vixie

Feb 25, 2026 11:14:06 Sebastian Moeller <[email protected]=
>:

Hi,

quick note:

The draft states:
To prevent denial of service attacks, the ICMP Query Response message MUST =
NOT be longer than the corresponding ICMP Query Request message.

IMHO this reasonable requirement does prevent amplification more than it in=
hibits denial of service attacks... How well this lends itself to denial of=
 service attacks (on the queried host), IMHO, depends more on how costly th=
e requested pieces of information are to gather... and since the draft refe=
rs to another (not yet written?) draft for the actual queries this is hard =
to assess.
For using this to create reflection attacks on other hosts this size limit =
really also only affects the effective amplification when using that attack=
 vector, but if an attacker commands enough nodes no amplification is requi=
red to create a denial of service attack. So I would just rephrase that sen=
tence from "To prevent denial of service attacks,..." to "To remove to pote=
ntial of abusing this as a means of attack amplification,..."

Regards
    Sebastian




On 25. Feb 2026, at 09:10, [email protected] wrote:

Dear all,

A new document draft-xbm-intarea-icmp-query-00 has been submitted. This dra=
ft introduces two new ICMP messages (ICMP Query Request/Response) for the p=
urpose of IP node information query.
After that, draft-ietf-6man-icmpv6-conf-state was updated and its basis was=
 changed from RFC 4620 to draft-xbm-intarea-icmp-query.
Links for the two drafts are as below.
https://datatracker.ietf.org/doc/html/draft-xbm-intarea-icmp-query-00<https=
://urldefense.com/v3/__https://datatracker.ietf.org/doc/html/draft-xbm-inta=
rea-icmp-query-00__;!!NpxR!jcvjxz74Nqli0wiCVJeYtlGyloSUFmiTwk2Hkfe5eSG0Xi1Z=
C2_Or5zb9hhYJyuGpNyIHc7_RAoQQw$> https://datatracker.ietf.org/doc/html/draf=
t-ietf-6man-icmpv6-ioam-conf-state-10<https://urldefense.com/v3/__https://d=
atatracker.ietf.org/doc/html/draft-ietf-6man-icmpv6-ioam-conf-state-10__;!!=
NpxR!jcvjxz74Nqli0wiCVJeYtlGyloSUFmiTwk2Hkfe5eSG0Xi1ZC2_Or5zb9hhYJyuGpNyIHc=
7mgrouEQ$>
Looking forward to your review and comments.

Cheers,
Xiao Min
--------------------------------------------------------------------
IETF IPv6 working group mailing list
[email protected]
List Info: https://mailman3.ietf.org/mailman3/lists/[email protected]/<https://=
urldefense.com/v3/__https://mailman3.ietf.org/mailman3/lists/[email protected]/=
__;!!NpxR!jcvjxz74Nqli0wiCVJeYtlGyloSUFmiTwk2Hkfe5eSG0Xi1ZC2_Or5zb9hhYJyuGp=
NyIHc6nqx4i7w$>
--------------------------------------------------------------------

_______________________________________________
Int-area mailing list -- [email protected]
To unsubscribe send an email to [email protected]

--_000_DM4PR84MB2310D30484F0AA741AC921B7F472ADM4PR84MB2310NAMP_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
Paul,</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
Because this issue touches many ICMP messages, I think that it belongs in a=
 separate document.</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
Do you want to produce the first draft or should I?</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp=
; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nb=
sp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &=
nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;=
 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; Ron</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div><br>
</div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<hr style=3D"display: inline-block; width: 98%;">
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);">
<b>From:</b>&nbsp;Paul Vixie &lt;[email protected]&gt;<br>
<b>Sent:</b>&nbsp;Thursday, February 26, 2026 3:20 AM<br>
<b>To:</b>&nbsp;Bonica, Ron &lt;[email protected]&gt;<br>
<b>Cc:</b>&nbsp;Sebastian Moeller &lt;[email protected]&gt=
;; [email protected] &lt;[email protected]&gt;; [email protected] &lt=
;[email protected]&gt;; [email protected] &lt;[email protected]&gt;<br>
<b>Subject:</b>&nbsp;Re: [Int-area] Re: [IPv6]ICMP Query and ICMP Query for=
 IOAM </div>
<div style=3D"font-family: Calibri, Arial, Helvetica, sans-serif; font-size=
: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div>Yes, at a minimum.</div>
<div>Paul Vixie</div>
<p style=3D"direction: ltr; margin-top: 1em; margin-bottom: 1em;">Feb 25, 2=
026 16:23:33 Bonica, Ron &lt;[email protected]&gt;:</p>
<blockquote style=3D"margin: 0px; padding-left: 10px; border-left: 3px soli=
d rgb(204, 204, 204);">
<div style=3D"direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0);">
Hi Paul,</div>
<div style=3D"direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0);">
<br>
</div>
<div style=3D"direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0);">
I think that your statement applies even more globally.</div>
<div style=3D"direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0);">
<br>
</div>
<div style=3D"direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0);">
Would it make sense to apply the following rate limits:</div>
<div style=3D"direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0);">
<br>
</div>
<ul style=3D"direction: ltr; margin-top: 0px; margin-bottom: 0px;" data-edi=
ting-info=3D"{&quot;applyListStyleFromLevel&quot;:false,&quot;unorderedStyl=
eType&quot;:2}">
<li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, C=
alibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); list-s=
tyle-type: &quot;- &quot;;">
<div style=3D"direction: ltr;" role=3D"presentation">A less strict rate lim=
it, applied to all ICMP messages. (Already recommended in RFC 1812 and wide=
ly deployed).</div>
</li><li style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontServi=
ce, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); l=
ist-style-type: &quot;- &quot;;">
<div style=3D"direction: ltr;" role=3D"presentation">A more strict rate lim=
it, applied to some informational messages (e.g., Echo, Extended Echo, Quer=
y)</div>
</li></ul>
<div style=3D"direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0);">
<br>
</div>
<div style=3D"direction: ltr; font-family: Aptos, Aptos_EmbeddedFont, Aptos=
_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb=
(0, 0, 0);">
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp=
; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nb=
sp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &=
nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;=
 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Ron</div>
<hr style=3D"direction: ltr; display: inline-block; width: 98%;">
<div id=3D"x_divRplyFwdMsg">
<div style=3D"direction: ltr; font-family: Calibri, sans-serif; font-size: =
11pt; color: rgb(0, 0, 0);">
<b>From:</b>&nbsp;Paul Vixie &lt;[email protected]&gt;<br>
<b>Sent:</b>&nbsp;Wednesday, February 25, 2026 7:47 AM<br>
<b>To:</b>&nbsp;Sebastian Moeller &lt;[email protected]&gt=
;<br>
<b>Cc:</b>&nbsp;[email protected] &lt;[email protected]&gt;; int-area=
@ietf.org &lt;[email protected]&gt;; [email protected] &lt;[email protected]&gt;<br=
>
<b>Subject:</b>&nbsp;[Int-area] Re: [IPv6]ICMP Query and ICMP Query for IOA=
M</div>
<div style=3D"direction: ltr;">&nbsp;</div>
</div>
<div style=3D"direction: ltr;">I think relative request to response size is=
 the wrong control point. Here's how we reasoned it for DNS RRL:<br>
<br>
&lt;&lt;One important principle of DNS RRL's design is that it makes a DNS =
server into a DDoS attenuator=97it causes not just lack of amplification, b=
ut also an actual reduction in traffic volume compared with what an attacke=
r could achieve by sending the packets directly.
 Just as importantly, this attenuation is not only in the number of bits pe=
r second, but also in the number of packets per second. That's important in=
 a world full of complex stateful firewalls where the bottleneck is often i=
n the number of packets, not bits,
 and processing a small packet costs just as much in terms of firewall capa=
city as processing a larger packet.&gt;&gt;<br>
<br>
<a data-auth=3D"NotApplicable" class=3D"OWAAutoLink" id=3D"OWAae89ef08-d13a=
-9853-b5a7-368d1bc9d63e" href=3D"https://queue.acm.org/detail.cfm?id=3D2578=
510">https://queue.acm.org/detail.cfm?id=3D2578510</a></div>
<div style=3D"direction: ltr;">Paul Vixie</div>
<p style=3D"direction: ltr; margin-top: 0px; margin-bottom: 0px;">Feb 25, 2=
026 11:14:06 Sebastian Moeller &lt;[email protected]&gt;:<=
/p>
<blockquote style=3D"margin: 0px; padding-left: 10px; border-left: 3px soli=
d rgb(204, 204, 204);">
<div style=3D"direction: ltr;">Hi,<br>
<br>
quick note:<br>
<br>
The draft states:<br>
To prevent denial of service attacks, the ICMP Query Response message MUST =
NOT be longer than the corresponding ICMP Query Request message.<br>
<br>
IMHO this reasonable requirement does prevent amplification more than it in=
hibits denial of service attacks... How well this lends itself to denial of=
 service attacks (on the queried host), IMHO, depends more on how costly th=
e requested pieces of information
 are to gather... and since the draft refers to another (not yet written?) =
draft for the actual queries this is hard to assess.<br>
For using this to create reflection attacks on other hosts this size limit =
really also only affects the effective amplification when using that attack=
 vector, but if an attacker commands enough nodes no amplification is requi=
red to create a denial of service
 attack. So I would just rephrase that sentence from &quot;To prevent denia=
l of service attacks,...&quot; to &quot;To remove to potential of abusing t=
his as a means of attack amplification,...&quot;<br>
<br>
Regards<br>
&nbsp;&nbsp;&nbsp; Sebastian<br>
<br>
<br>
<br>
<br>
</div>
<blockquote style=3D"margin: 0px; padding-left: 10px; border-left: 3px soli=
d rgb(204, 204, 204);">
<div style=3D"direction: ltr;">On 25. Feb 2026, at 09:10, [email protected]=
.cn wrote:<br>
<br>
Dear all,<br>
<br>
A new document draft-xbm-intarea-icmp-query-00 has been submitted. This dra=
ft introduces two new ICMP messages (ICMP Query Request/Response) for the p=
urpose of IP node information query.<br>
After that, draft-ietf-6man-icmpv6-conf-state was updated and its basis was=
 changed from RFC 4620 to draft-xbm-intarea-icmp-query.<br>
Links for the two drafts are as below.<br>
<a data-auth=3D"NotApplicable" class=3D"OWAAutoLink" id=3D"OWA3b2412a7-4c2f=
-d9db-5b11-7b7a48a27b67" href=3D"https://urldefense.com/v3/__https://datatr=
acker.ietf.org/doc/html/draft-xbm-intarea-icmp-query-00__;!!NpxR!jcvjxz74Nq=
li0wiCVJeYtlGyloSUFmiTwk2Hkfe5eSG0Xi1ZC2_Or5zb9hhYJyuGpNyIHc7_RAoQQw$">http=
s://datatracker.ietf.org/doc/html/draft-xbm-intarea-icmp-query-00</a>
<a data-auth=3D"NotApplicable" class=3D"OWAAutoLink" id=3D"OWAa63afa87-d165=
-b742-5f7a-7217b134fc56" href=3D"https://urldefense.com/v3/__https://datatr=
acker.ietf.org/doc/html/draft-ietf-6man-icmpv6-ioam-conf-state-10__;!!NpxR!=
jcvjxz74Nqli0wiCVJeYtlGyloSUFmiTwk2Hkfe5eSG0Xi1ZC2_Or5zb9hhYJyuGpNyIHc7mgro=
uEQ$">
https://datatracker.ietf.org/doc/html/draft-ietf-6man-icmpv6-ioam-conf-stat=
e-10</a><br>
Looking forward to your review and comments.<br>
<br>
Cheers,<br>
Xiao Min<br>
--------------------------------------------------------------------<br>
IETF IPv6 working group mailing list<br>
[email protected]<br>
List Info: <a data-auth=3D"NotApplicable" class=3D"OWAAutoLink" id=3D"OWA97=
c3c435-f71a-5a8c-5b04-546b3d30f187" href=3D"https://urldefense.com/v3/__htt=
ps://mailman3.ietf.org/mailman3/lists/[email protected]/__;!!NpxR!jcvjxz74Nqli0=
wiCVJeYtlGyloSUFmiTwk2Hkfe5eSG0Xi1ZC2_Or5zb9hhYJyuGpNyIHc6nqx4i7w$">
https://mailman3.ietf.org/mailman3/lists/[email protected]/</a><br>
--------------------------------------------------------------------</div>
</blockquote>
<div style=3D"direction: ltr;"><br>
_______________________________________________<br>
Int-area mailing list -- [email protected]<br>
To unsubscribe send an email to [email protected]</div>
</blockquote>
</blockquote>
</body>
</html>

--_000_DM4PR84MB2310D30484F0AA741AC921B7F472ADM4PR84MB2310NAMP_--


--===============8447395306282590160==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KSW50LWFyZWEg
bWFpbGluZyBsaXN0IC0tIGludC1hcmVhQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4g
ZW1haWwgdG8gaW50LWFyZWEtbGVhdmVAaWV0Zi5vcmcK

--===============8447395306282590160==--