Re: [I2nsf] Comparing MIDCOM, PCP with I2NSF
🔓Dan Wing <[email protected]> Mon, 9 Feb 2015 15:46:07 -0800
| Newsgroups | gmane.ietf.midcom |
|---|---|
| Message-ID | <[email protected]> |
--===============6106907054136565094== Content-Type: multipart/alternative; boundary="Apple-Mail=_D65631F3-EEE0-45CC-9C30-B094ABF668C5" --Apple-Mail=_D65631F3-EEE0-45CC-9C30-B094ABF668C5 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 PCP deals with an incoming connection (with its MAP opcode) and with = timeouts of a connection (with its PEER opcode). As they are, those = don't seem to help much a subscriber choosing some network services = function for their traffic. MAP does have a FILTER option, which = provides some filtering (ACL) capabilities, but I expect i2nsf is = looking at more advanced functionality than that? -d On 09-Feb-2015 11:38 AM, Linda Dunbar <[email protected]> wrote:=20= > Melinda, > =20 > (CC=E2=80=99ed PCP group and MIDCOM group for wider review. ) > =20 > After studying RFCs/Charter of MIDCOM and PCP, it seems to me that PCP = is a lot more closely tied with MIDCOM than I2NSF. > =E2=80=9C The PCP working group is chartered to standardize a = client/server Port > Control Protocol (PCP) to enable an explicit dialog with a middlebox > such as a NAT or a firewall to open up and/or forward TCP or UDP port, > regardless of the location of that middlebox=E2=80=9D > =20 > =20 > MIDCOM =E2=80=9Cfocuses its attention on communication with firewalls = and network address translators (including translation between IPv6 and = IPv4).=E2=80=9D > =20 > I noticed that the detailed protocols developed by MIDCOM is quite = different from PCP. For example, the MDCOM protocol is tied closely with = the SIP agent (SIP/RTSP Proxy) to send =E2=80=9CINVITE=E2=80=9D, respond = to =E2=80=9C180Ringing=E2=80=9D or =E2=80=9CPort-BIND=E2=80=9D reply to = Middle Boxes. The MIDCOM protocol is very much SIP protocol oriented, = whereas the PCP is more FW/NAT device oriented. > =20 > =20 > I2NSF will focus on management of many instances of security functions = (virtual security functions), i.e. the use case described by = http://datatracker.ietf.org/doc/draft-pastor-i2nsf-access-usecases/ = <http://datatracker.ietf.org/doc/draft-pastor-i2nsf-access-usecases/>: > =20 > Among the 3 actions listed in the Use Case draft, I can see that #2 = below can utilize some of the mechanisms developed by PCP and MIDCOM. > =20 > =20 > 1. Customer enrollment and cancellation of the subscription to a > vNSF. ( > =20 > 2. Configuration of the vNSF, based on specific configurations or > derived from common security policies defined by the operator. > =20 > 3. Retrieve and list of the vNSF functionalities, extracted from a > manifest or a descriptor. The network operator management = systems > can demand this information to offer detailed information = through > the commercial channels to the customer. > =20 > =20 > What messages & protocols by MIDCOM & PCP do you see that can be used = for I2NSF purpose? > =20 > =20 > Linda > =20 > _______________________________________________ > I2nsf mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/i2nsf --Apple-Mail=_D65631F3-EEE0-45CC-9C30-B094ABF668C5 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html><head><meta http-equiv=3D"Content-Type" content=3D"text/html = charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; = -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" = class=3D""><div><div class=3D"">PCP deals with an incoming connection = (with its MAP opcode) and with timeouts of a connection (with its PEER = opcode). As they are, those don't seem to help much a subscriber = choosing some network services function for their traffic. MAP = does have a FILTER option, which provides some filtering (ACL) = capabilities, but I expect i2nsf is looking at more advanced = functionality than that?</div><div class=3D""><br class=3D""></div><div = class=3D"">-d</div><div class=3D""><br class=3D"">On 09-Feb-2015 11:38 = AM, Linda Dunbar <<a href=3D"mailto:[email protected]" = class=3D"">[email protected]</a>> wrote: <br = class=3D""></div><blockquote type=3D"cite" class=3D""><div class=3D""> <meta http-equiv=3D"Content-Type" content=3D"text/html; = charset=3Dus-ascii" class=3D""> <meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)" = class=3D""> <style class=3D""><!-- /* Font Definitions */ @font-face {font-family:SimSun; panose-1:2 1 6 0 3 1 1 1 1 1;} @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:"\@SimSun"; panose-1:2 1 6 0 3 1 1 1 1 1;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; margin-bottom:.0001pt; font-size:11.0pt; font-family:"Calibri","sans-serif";} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:purple; text-decoration:underline;} span.EmailStyle17 {mso-style-type:personal-compose; font-family:"Calibri","sans-serif"; color:windowtext;} .MsoChpDefault {mso-style-type:export-only;} @page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1 {page:WordSection1;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--> <div lang=3D"EN-US" link=3D"blue" vlink=3D"purple" class=3D""> <div class=3D"WordSection1"><p class=3D"MsoNormal">Melinda, <o:p = class=3D""></o:p></p><p class=3D"MsoNormal"><o:p = class=3D""> </o:p></p><p class=3D"MsoNormal">(CC=E2=80=99ed PCP = group and MIDCOM group for wider review. )<o:p class=3D""></o:p></p><p = class=3D"MsoNormal"><o:p class=3D""> </o:p></p><p = class=3D"MsoNormal">After studying RFCs/Charter of MIDCOM and PCP, it = seems to me that PCP is a lot more closely tied with MIDCOM than I2NSF. <o:p class=3D""></o:p></p><p class=3D"MsoNormal">=E2=80=9C <span = style=3D"font-size:8.0pt;font-family:"Arial","sans-serif&qu= ot;" class=3D""> The PCP working group is chartered to standardize a client/server = Port<br class=3D""> Control Protocol (PCP) to enable an explicit dialog with a middlebox<br = class=3D""> such as a NAT or a firewall to open up and/or forward TCP or UDP = port,<br class=3D""> regardless of the location of that middlebox=E2=80=9D<o:p = class=3D""></o:p></span></p><p class=3D"MsoNormal"><o:p = class=3D""> </o:p></p><p class=3D"MsoNormal"><o:p = class=3D""> </o:p></p><p class=3D"MsoNormal">MIDCOM =E2=80=9C<span = style=3D"font-size:8.0pt;font-family:"Arial","sans-serif&qu= ot;" class=3D"">focuses its attention on communication with firewalls = and network address translators (including translation between IPv6 and = IPv4).=E2=80=9D</span><o:p class=3D""></o:p></p><p = class=3D"MsoNormal"><o:p class=3D""> </o:p></p><p = class=3D"MsoNormal">I noticed that the detailed protocols = developed by MIDCOM is quite different from PCP. For example, the MDCOM = protocol is tied closely with the SIP agent (SIP/RTSP Proxy) to send = =E2=80=9CINVITE=E2=80=9D, respond to =E2=80=9C180Ringing=E2=80=9D or = =E2=80=9CPort-BIND=E2=80=9D reply to Middle Boxes.<span = style=3D"font-size:8.0pt;font-family:"Arial","sans-serif&qu= ot;" class=3D""> </span> The MIDCOM protocol is very much SIP protocol oriented, whereas the PCP = is more FW/NAT device oriented. <o:p class=3D""></o:p></p><p class=3D"MsoNormal"><span = style=3D"font-size:8.0pt;font-family:"Arial","sans-serif&qu= ot;" class=3D""> </span></p><p class=3D"MsoNormal"><span = style=3D"font-size:8.0pt;font-family:"Arial","sans-serif&qu= ot;" class=3D""> </span></p><p class=3D"MsoNormal">I2NSF will focus = on management of many instances of security functions (virtual security = functions), i.e. the use case described by<span style=3D"color:#1F497D" = class=3D""> <a = href=3D"http://datatracker.ietf.org/doc/draft-pastor-i2nsf-access-usecases= /" = class=3D"">http://datatracker.ietf.org/doc/draft-pastor-i2nsf-access-useca= ses/</a>:<o:p class=3D""></o:p></span></p><p class=3D"MsoNormal"><o:p = class=3D""> </o:p></p><p class=3D"MsoNormal">Among the 3 actions = listed in the Use Case draft, I can see that #2 below can utilize = some of the mechanisms developed by PCP and MIDCOM. <o:p class=3D""></o:p></p><p class=3D"MsoNormal" = style=3D"text-autospace:none"><span style=3D"color:#1F497D" = class=3D""> <o:p class=3D""></o:p></span></p><p class=3D"MsoNormal" = style=3D"text-autospace:none"><span = style=3D"font-size:10.0pt;font-family:"Courier New"" = class=3D""> </span></p><p class=3D"MsoNormal" = style=3D"text-autospace:none"><span = style=3D"font-size:10.0pt;font-family:"Courier New"" = class=3D""> 1. Customer enrollment and cancellation of = the subscription to a<o:p class=3D""></o:p></span></p><p = class=3D"MsoNormal" style=3D"text-autospace:none"><span = style=3D"font-size:10.0pt;font-family:"Courier New"" = class=3D""> vNSF. (<o:p = class=3D""></o:p></span></p><p class=3D"MsoNormal" = style=3D"text-autospace:none"><span = style=3D"font-size:10.0pt;font-family:"Courier New"" = class=3D""> </span></p><p class=3D"MsoNormal" = style=3D"text-autospace:none"><span = style=3D"font-size:10.0pt;font-family:"Courier New"" = class=3D""> 2. Configuration of the vNSF, based on = specific configurations or<o:p class=3D""></o:p></span></p><p = class=3D"MsoNormal" style=3D"text-autospace:none"><span = style=3D"font-size:10.0pt;font-family:"Courier New"" = class=3D""> derived from common security = policies defined by the operator.<o:p class=3D""></o:p></span></p><p = class=3D"MsoNormal" style=3D"text-autospace:none"><span = style=3D"font-size:10.0pt;font-family:"Courier New"" = class=3D""> </span></p><p class=3D"MsoNormal" = style=3D"text-autospace:none"><span = style=3D"font-size:10.0pt;font-family:"Courier New"" = class=3D""> 3. Retrieve and list of the vNSF = functionalities, extracted from a<o:p class=3D""></o:p></span></p><p = class=3D"MsoNormal" style=3D"text-autospace:none"><span = style=3D"font-size:10.0pt;font-family:"Courier New"" = class=3D""> manifest or a = descriptor. The network operator management systems<o:p = class=3D""></o:p></span></p><p class=3D"MsoNormal" = style=3D"text-autospace:none"><span = style=3D"font-size:10.0pt;font-family:"Courier New"" = class=3D""> can demand this information to = offer detailed information through<o:p class=3D""></o:p></span></p><p = class=3D"MsoNormal" style=3D"text-autospace:none"><span = style=3D"font-size:10.0pt;font-family:"Courier New"" = class=3D""> the commercial channels to the = customer.<o:p class=3D""></o:p></span></p><p class=3D"MsoNormal"><o:p = class=3D""> </o:p></p><p class=3D"MsoNormal"><o:p = class=3D""> </o:p></p><p class=3D"MsoNormal">What messages & = protocols by MIDCOM & PCP do you see that can be used for I2NSF = purpose?<o:p class=3D""></o:p></p><p class=3D"MsoNormal"><o:p = class=3D""> </o:p></p><p class=3D"MsoNormal"><o:p = class=3D""> </o:p></p><p class=3D"MsoNormal">Linda<o:p = class=3D""></o:p></p><p class=3D"MsoNormal"><o:p = class=3D""> </o:p></p> </div> </div> _______________________________________________<br class=3D"">I2nsf = mailing list<br class=3D""><a href=3D"mailto:[email protected]" = class=3D"">[email protected]</a><br = class=3D"">https://www.ietf.org/mailman/listinfo/i2nsf<br = class=3D""></div></blockquote></div><br class=3D""><div class=3D""><br = class=3D""></div></body></html>= --Apple-Mail=_D65631F3-EEE0-45CC-9C30-B094ABF668C5-- --===============6106907054136565094== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ midcom mailing list [email protected] https://www.ietf.org/mailman/listinfo/midcom --===============6106907054136565094==--