Re: New iTrace proposal

Mikael Olsson <[email protected]> Fri, 17 Oct 2003 20:47:31 +0200
Newsgroups gmane.ietf.itrace
Organization Clavister AB
Message-ID <[email protected]>
First out: the WG is officially dead. I doubt (though this isn't=20
really for me to say) that the cleaned-up (experimental!) RFC will=20
contain anything of material value that isn't already in it.

Tomasz Grabowski wrote:
>=20
> So, mode 1 (generate iTrace messages, don't forward any others iTrace
> messages) is designed for [nincompoops].

Mandating such a mode means that suddenly all routers need to=20
apply ACLish behavior on all traffic.  This was unlikely in
the first place, and even less likely now.

> their network *can't* be flooded with iTrace messages=20

No, but their internet connection can.


> Pekka Savola wrote:
> > I think just using the TTL=3D255 when originating packets should be e=
nough.
>=20
> TTL can be easily spoofed. There need to be a way to check if particula=
r
> iTrace messages was sent by particular router.

You're missing the point. If I receive a packet with TTL 252, I
know for a fact that it was generated by a host no more than three
hops out. This is undeniable. Using this logic, you can reconstruct
itrace chains with a "fair" degree of probability.  This was the=20
essence of the original itrace proposal.


--=20
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 =D6RNSK=D6LDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com