Re: WGLC: draft-ietf-nsis-nslp-natfw-16.txt
Lauri J T Liuhto <[email protected]>
| Newsgroups | gmane.ietf.nsis |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 23 Nov 2007, Martin Stiemerling wrote:
> The authors believe that the NATFW NSLP
> (draft-ietf-nsis-nslp-natfw-16.txt) is ready for WGLC.
> The WGLC starts today and will run until December 14th.
Hi,
I have read the document, and I did not find any big issues, mainly
just some editorial things. I did not repeat findings already
provided by Jukka or Niklas.
Some parts of the text, mainly Section 3 (Protocol Description), was
such, that I can not be sure whether I understood it completely. The
text itself was quite easy to read, but I think those who have
implemented this protocol can say more accurately how well the protocol
actually is described.
To make it short: I think the specification is in quite nice state, and
needs just some editorial fixes.
Here are my comments on the draft:
* At page 11, line 571: 'routeable' --> 'routable' (?)
* Examples in Section 2 use mainly 'MB' in figures to represent NAT
and/or FW nodes. However, I think the use is not always
consistent. For example, in the figure 2 'FW' is used (and I think
it is ok, because the text explicitly states that this example is
about FW-only cases), but figure 9 in section 2.8 has 'MB's
instead. If those middle boxes in scenario 2.8 may be also NATs, I
think it would be nice to have it in text. If those middle boxes
are always firewalls as I think the text states, then the figure
should be changed.
However, I think that the text is clear enough already, and the
easy fix would be to change the 'FW' boxes to 'MB' boxes in the
figure 2 :)
* Section 3.1 Policy Rules, first paragraph:
"For firewalls the policy rule usually consists of a 5-tuple, source/
destination addresses, transport protocol, and source/destination
port numbers, plus an action, such as allow or deny."
At least before reading the rest of the document, the word 'usually'
seems a bit odd here. Do real alternative policy rules that do not
contain the 5-tuple and action exist?
I also think this sentence is not too clear, some kind of
reformatting would be nice. For example, something like this (still
having the word 'usually'):
"For firewalls the policy rule usually consists of a 5-tuple and an
action such as allow or deny. The information contained in the tuple
includes source/destination addresses, transport protocol and
source/destination port numbers."
* In addition to comments Niklas already gave on figure 11 on page
24, I want to add that the figure and its legend do not
match. There is no MB2 in the figure, and NF is present in the
legend only in the text. As Niklas, I also think that it would be
good to point out which node belongs to which network.
* Page 28, last bullet:
"the lease time of the NI's IP address. The chosen NATFW NSLP
signaling session lifetime must be larger than the lease time,
otherwise the IP address can be re-assigned to a different node.
This node may receive unwanted traffic, although it never has
requested a NAT/firewall configuration, which might be an issue in
mobile environments.
I just can not get the idea :) Should it be 'must be smaller than
the lease time' ? If not, then I think some more text is needed.
* Page 45, middle bullet:
"and outbound messages MUST be forwarded further inbound."
->
"and outbound messages MUST be forwarded further outbound." ?
* Table 1 on page 50, the last row, capitalization:
left column: "IPsec SPI", right column: "ipsec-SPI"
Best Regards,
Lauri
--
Lauri Liuhto