Re: WGLC: draft-ietf-nsis-nslp-natfw-16.txt
Martin Stiemerling <[email protected]>
| Newsgroups | gmane.ietf.nsis |
|---|---|
| Message-ID | <[email protected]> |
Hi Lauri, Am 13.12.2007 um 01:08 schrieb Lauri J T Liuhto: > On Fri, 23 Nov 2007, Martin Stiemerling wrote: >> The authors believe that the NATFW NSLP >> (draft-ietf-nsis-nslp-natfw-16.txt) is ready for WGLC. >> The WGLC starts today and will run until December 14th. > > Hi, > > I have read the document, and I did not find any big issues, mainly > just some editorial things. I did not repeat findings already > provided by Jukka or Niklas. > > Some parts of the text, mainly Section 3 (Protocol Description), was > such, that I can not be sure whether I understood it completely. The > text itself was quite easy to read, but I think those who have > implemented this protocol can say more accurately how well the > protocol > actually is described. > > To make it short: I think the specification is in quite nice > state, and > needs just some editorial fixes. Thanks! :) > > Here are my comments on the draft: > > * At page 11, line 571: 'routeable' --> 'routable' (?) Fixed. > > * Examples in Section 2 use mainly 'MB' in figures to represent NAT > and/or FW nodes. However, I think the use is not always > consistent. For example, in the figure 2 'FW' is used (and I think > it is ok, because the text explicitly states that this example is > about FW-only cases), but figure 9 in section 2.8 has 'MB's > instead. If those middle boxes in scenario 2.8 may be also NATs, I > think it would be nice to have it in text. If those middle boxes > are always firewalls as I think the text states, then the figure > should be changed. > > However, I think that the text is clear enough already, and the > easy fix would be to change the 'FW' boxes to 'MB' boxes in the > figure 2 :) 2.8 and 2.7 have a subtle difference and it is better to change MB to FW in figure 9. > > * Section 3.1 Policy Rules, first paragraph: > > "For firewalls the policy rule usually consists of a 5-tuple, source/ > destination addresses, transport protocol, and source/destination > port numbers, plus an action, such as allow or deny." > > At least before reading the rest of the document, the word 'usually' > seems a bit odd here. Do real alternative policy rules that do not > contain the 5-tuple and action exist? > > I also think this sentence is not too clear, some kind of > reformatting would be nice. For example, something like this (still > having the word 'usually'): > > "For firewalls the policy rule usually consists of a 5-tuple and an > action such as allow or deny. The information contained in the tuple > includes source/destination addresses, transport protocol and > source/destination port numbers." This reads better! Replaced it. > > * In addition to comments Niklas already gave on figure 11 on page > 24, I want to add that the figure and its legend do not > match. There is no MB2 in the figure, and NF is present in the > legend only in the text. As Niklas, I also think that it would be > good to point out which node belongs to which network. Fixed. > > * Page 28, last bullet: > "the lease time of the NI's IP address. The chosen NATFW NSLP > signaling session lifetime must be larger than the lease time, > otherwise the IP address can be re-assigned to a different node. > This node may receive unwanted traffic, although it never has > requested a NAT/firewall configuration, which might be an issue in > mobile environments. > > I just can not get the idea :) Should it be 'must be smaller than > the lease time' ? If not, then I think some more text is needed. Yep, you're right, it must be smaller. I also bumped in this when reading. Fixed. > > * Page 45, middle bullet: > "and outbound messages MUST be forwarded further inbound." > -> > "and outbound messages MUST be forwarded further outbound." ? Fixed to outbound. > > * Table 1 on page 50, the last row, capitalization: > left column: "IPsec SPI", right column: "ipsec-SPI" That is intentionally, as the NATFW NSLP uses IPsec SPI as name and GIST uses ipsec-SPI. Thanks a lot, Martin [email protected] NEC Laboratories Europe - Network Research Division NEC Europe Limited | Registered Office: NEC House, 1 Victoria Road, London W3 6BL | Registered in England 2832014 _______________________________________________ nsis mailing list [email protected] https://www1.ietf.org/mailman/listinfo/nsis