RE: I-D on SAFENeT

Martin Stiemerling <[email protected]> Mon, 11 Jul 2005 18:02:54 +0200
Newsgroups gmane.ietf.midcom
Message-ID <F46596D91E7439AFA14FCDD0@753F3B888A9969457862729D>
Hi Rick,

--On Freitag, 8. Juli 2005 11:29 Uhr -0400 "Townsend, Richard L, JR (Rick)" 
<[email protected]> wrote:

| Hi Martin,
| I'm not sure how to answer your question directly so let me take a
| slightly different approach that I intend to be a helpful way to go.
|
| The main difference between SAFENeT and existing MIDCOM work is that
| SAFENeT provides a complete solution, whereas existing work defines
| mostly the architecture, but not implementation.  Another difference is

I see now your starting point for SAFENeT and need to point an important
issue before going ahead. The charter page of the MIDCOM working group
(<http://www.ietf.org/html.charters/midcom-charter.html>) lists indeed
the architecture, framework, protocol semantics, STUN, and the MIB only.
This may give the impression that a protocol is still missing and to be
done. However, the MIDCOM WG has chosen to use SNMP MIBs to define the
MIDCOM protocol. The MIB module defines the MIDCOM protocol and is not
a "regular" MIB module you will encounter in other working groups. This
MIB module implements the protocol semantics defined in RFC 3989.

A second implementation of the MIDCOM semantics is the Simple Middlebox
Configuration (SIMCO) protocol (see draft-stiemerling-midcom-simco-07.txt)

| that SAFENeT provides a close secure relationship between the manager and
| agent (e.g., call server and middlebox)(they are both owned by the
| enterprise), whereas the other architectures provide for the case where
| there is no a priori relationship between the components (which may have
| security implications).  I believe the configuration where the server can
| reserve resources (e.g., ports for NAT mappings) is new, and critical for
| high-performance.   While SAFENeT may provide a somewhat limited scope,
| i.e., an enterprise solution, I believe it will provide useful insights
| in attacking the NAT/FW problem.

This is actually what the MIB module and SIMCO are "doing".

|
| My intention is to help the development of MIDCOM protocols, not to
| replace them.  And that we feel that it will be useful for MIDCOM to have
| a working implementation (in draft form) to learn from before finalizing
| future MIDCOM standards.

Indeed, it is good for MIDCOM to have a working implementation as a draft
and running code. The MIDCOM MIB and SIMCO are working drafts and SIMCO
is implemented and tested for interoperability (see announcement
on this list from date 2004-08-13 by me.)

With best regards

  Martin

|
| 	Rick
|
|  -----Original Message-----
| From: 	Martin Stiemerling [mailto:[email protected]]
| Sent:	Friday, July 08, 2005 8:02 AM
| To:	Townsend, Richard L, JR (Rick); '[email protected]'
| Subject:	Re: [midcom] I-D on SAFENeT
|
| Hi Richard,
|
| I have read the draft but still do not know what the difference to the
| usage of the MIDCOM MIB or SIMCO is?
|
| Thanks
|
|   Martin
|
| --On Mittwoch, 6. Juli 2005 15:46 Uhr -0400 "Townsend, Richard L, JR
| (Rick)" <[email protected]> wrote:
|
|| Hi all,
|| After several discussions with ADs and others, we have reached the view
|| that MIDCOM should be the group to discuss the I-D on SAFENeT, an
|| enterprise solution to the NAT/FW traversal problem.  Melinda has asked
|| me to advise you that the I-D is published as
|| <draft-stott-behave-safenet-00.txt>.
||
|| To see how SAFENeT addresses the NAT/FW traversal problem differently,
|| let me refer you to sections of the I-D rather than rewrite them here.
||
|| Section 1.5 describes what SAFENeT is trying to accomplish.
|| Section 2 describes existing views/solutions of the NAT/FW traversal.
|| Section 3.1 gives an overview of SAFENeT.
||
|| We believe SAFENeT could be fit within other developing
|| architectures/protocols if that's what the group desires and it is
|| reasonable simple, in part, because it carves out a niche in that it
|| addresses enterprise networks and does not try to solve the general
|| problem.
||
|| Comments are welcome.
||
|| 	Rick
||
|| _______________________________________________
|| midcom mailing list
|| [email protected]
|| https://www1.ietf.org/mailman/listinfo/midcom
|
|
| _______________________________________________
| midcom mailing list
| [email protected]
| https://www1.ietf.org/mailman/listinfo/midcom
|