Draft Minutes of MIDCOM IETF-59 Session - Part 2

"Mary Barnes" <[email protected]>
Newsgroups gmane.ietf.midcom
Message-ID <[email protected]>
Below is Part 2 of the minutes.  Please direct any comments to the list.

Regards,
Mary H. Barnes
[email protected]


Part 2 - Minutes of the midcom session at IETF59
---------------------------------------

AGENDA ITEM: What do we do with draft-ietf-midcom-mib-analysis-01.txt? (Mary
Barnes)

  - We had two MIBs, now we have one. 

  - WG MIB analysis document updated prior to IETF-58 to reflect the 
    current status (2 MIBs) and additional detailed analysis of the 
    applicability of the MIDCOM semantics to the NAT mib: 
      - Draft-ietf-midcom-mib-analysis-01.txt 

  - Progress since IETF-58:
    -NATMIB under IESG review
    -FW config split from IPSEC policy config MIB
    -Single MIB document
             
  - Proposal: do some clean up, and combine the 
    two as one document going forward.

  - Discussion: 
             
    - Juergen Quittek: I think the there is some relationship with NAT 
      MIB...
             
    - Mary Barnes (Chair): We didn't get a lot of reusability of the 
      other MIB. 
             
    - Result of brief discussion: No objections. 

             
AGENDA ITEM: MIB document draft-ietf-midcom-mib-00.txt (Juergen Quittek)

  - What we did was to take the three individual MIBs 
    and integrate them into one big MIB. 
  - The general approach was to start from the MIDCOM semantics. 
    - Tried to map the semantics to a MIB module. 
    - Added: 
       - Means for firewall configuration 
       - Resource usage information 
       - Statistics 
    - Structured into tables 
       - The major means provided by SMI (Structure of Management
Information) 
    - MIB Module Overview: 
       - Session Tbale, Rule table, group table, capabilities 
         table (IP interface configuration) filed uder 
         implementing MIDCOM semantics. 
   - Summary of the basics: 
     - A MIDCOM entry needs to insert it's own entry in the 
       session table before opening a session. Without this entry, 
       MIDCOM agent cannot act on policy rules. 
     - Rule table has one entry for each policy rule. Indexed by 
       session owner, groupindex, rule index. Objects in entry 
       cover all parameters of PER and PRR transactions. Explains 
       that if a NAT is involved, what the interface is. Added a 
       max idle time to describe how long the NAT session will be 
       left idle before closing. Added rule storage time to allow 
       rules to expire out of the table (they're left in there, 
       but inactive after expiry for a period of time). 
     - Group table: one entry per policy rule group, just a 
       shortcut for the rule table. 
     - Notifications: Informing the MIDCOM agnet about state 
       changes at the middlebox. Session termination, policy rule 
       event (lifetime change, etc).... 
     - Interface Config table: provides middlebox capability 
       information per IP interface (IP version, wildcarding 
       support, firewall, NAT). 
     - Firewall config table: config of the enforcement of policy 
       rules into firewalls. 
        - Group ID and priority of FW rules derived from MIDCOM 
          policy rules. 
        - Should be read-only for MIDCOM agents. 
        - Would be writable for middlebox admin. 
     - Resource Table: links MIDCOM policy rules in the rules 
       table to resources in the NAT MIB. 
     - MIDCOM statistics: session statistics: rejected, current, 
       total sessions. Policy rule stats, etc.. 

   - Open Issues: 
      - Security considerations not complete! 
      - Firewall config and resource usage indication is 
        generic (waiting for input form firewall community, 
        eager to hear back). Don't know if this is 
        representative of what's out there. Need to have 
        firewall community to speak up, currently generic. 
      - Explain use of USM and its relation to 
        midcomSessionOwner and clarify that the MIDCOM agent 
        authenticates, not the SNMP manager. How SNMP 
        security is exploited will be improved in next version. 
      - Is MaxIdleTime an input parameter to PRR? Question 
        was raised by Suresh, not present, so it's left open. 

  - Questions: 
     - Rohan Mahy: What was the overall.. what was the reaction 
       from the firewall community, are they interested? 
     - Juergen Quittek: yes. Suvesh is from the NAT community. Do 
       you mean the manufacturers or standards? 
     - Rohan Mahy: Manufacturers. 
     - Cedric Aoun: In which context is this thing targeted for, 
       management or monitoring, perhaps they're not clear on what 
       this is for? 
     - Jurgen Quittek: People with NATs want something like this, 
       but perhaps not a MIDCOM MIB. Couldn't tell. 
     - Mary Barnes (Chair): Please take a look at this, even if you're 
       not a MIB expert. Look at the data model. If you wanted to 
       implement it could you do what you need to do for MIDCOM.
                            
AGENDA ITEM: Way forward (Mary Barnes)

  - Completing the MIB will complete the MIDCOM charter at this 
    time. We need people to look at it, might want to wait for 
    next rev before the review due to security considerations. 
    (Dave Harrington volunteers) 
  - I will contact folks to read it on the long plane ride 
    back. Probably will be finished up in May. 

 Discussion:
  - Mary Barnes: Any other business?        
  - Rohan Mahy: I think there are a number of folks that are 
    interested in non-MIB MIDCOM like protocols. I was planning 
    something in after talking with a couple of folks. 
    Procedurally, should I bother or not? Are others interested? 
  - Jurgen Quittek: Maybe how many have seen the SIMCO draft 
    (complete implementation of the MIDCOM semantics), so maybe 
    we're interested. 
  - Jon Peterson (Area Director): Procedurally speaking, 
    charter and criteria were extraordinarily well documented. 
    Probably does not fit. However, at such time the IESG has 
    reviewed the the MIDCOM MIB, then we can look at 
    alternative approaches. I don't think we should put an 
    alternative approach at this time. 
  - Eric Burger: Exactly when is this cut-off be able to happen. 
  - Mary Barnes (Chair): Propose that you must contribute to the MIB before 
    you can contribute to an alternative. 
  - Jon Peterson (Area Director): Wishes he could authorize that proposal. 
    RFC editor has to have published the MIB before an alternative could 
    become a WG document. Individual contributions could proceed in 
    parallel, but RFC editor isn't going to want to see two 
    things at the same time. 
  - Jurgen Quittek: We'll submit something next week (SIMCO). 
  - Jon Peterson (Area Director): It's not that I can't stop 
    you, but I don't want to. Not appropriate to charter non-
    MIB approaches, however after MIB is approved, may be 
    reasonable to request individual publication of other 
    approaches. 
  - Mary Barnes (Chair): Final plea, please look at this document. 
  - Jonathan Rosenberg: While on subject of controvertial activities, 
    can someone send references to ITU-T activities for NAT/FW 
    traversal. 
  - Eric Burger: As well, ETSI is looking at this for H.248. 
  - Roni Even: It may be that they end with BCP document, but may 
    also be that it specifies solutions around H.323, H.245 
    signalling that SIP doesn't have. New question in SG.16, still 
    very early. 
             
--- MEETING CONCLUDES ---
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.