Re: WGLC: draft-ietf-nsis-nslp-natfw-16.txt

Martin Stiemerling <[email protected]>
Newsgroups gmane.ietf.nsis
Message-ID <C3C3A533.E898%[email protected]>
Just as an addendum:

IPsec SPI has been changed to IPsec-SPI.

  Martin

Am 24.01.2008 16:24 Uhr schrieb "Martin Stiemerling" unter
<[email protected]>:

> Hi Lauri,
> 
> Am 13.12.2007 um 01:08 schrieb Lauri J T Liuhto:
> 
>> On Fri, 23 Nov 2007, Martin Stiemerling wrote:
>>  
>>> The authors believe that the NATFW NSLP
>>> (draft-ietf-nsis-nslp-natfw-16.txt) is ready for WGLC.
>>> The WGLC starts today and will run until December 14th.
>>>  
>> 
>>  Hi, 
>> 
>>  I have read the document, and I did not find any big issues, mainly 
>> just some editorial things. I did not repeat findings already 
>> provided by Jukka or Niklas.
>> 
>>  Some parts of the text, mainly Section 3 (Protocol Description), was 
>> such, that I can not be sure whether I understood it completely. The 
>> text itself was quite easy to read, but I think those who have 
>> implemented this protocol can say more accurately how well the protocol 
>> actually is described. 
>> 
>>  To make it short: I think the specification is in quite nice state, and 
>> needs just some editorial fixes.
> 
> Thanks! :)
> 
>> 
>> Here are my comments on the draft:
>> 
>>  * At page 11, line 571: 'routeable' --> 'routable' (?)
> 
> Fixed.
> 
>> 
>>  * Examples in Section 2 use mainly 'MB' in figures to represent NAT
>>    and/or FW nodes. However, I think the use is not always
>>    consistent. For example, in the figure 2 'FW' is used (and I think
>>    it is ok, because the text explicitly states that this example is
>>    about FW-only cases), but figure 9 in section 2.8 has 'MB's
>>    instead. If those middle boxes in scenario 2.8 may be also NATs, I
>>    think it would be nice to have it in text. If those middle boxes
>>    are always firewalls as I think the text states, then the figure
>>    should be changed.
>> 
>>    However, I think that the text is clear enough already, and the
>>    easy fix would be to change the 'FW' boxes to 'MB' boxes in the 
>>    figure 2 :)
> 
> 2.8 and 2.7 have a subtle difference and it is better to change MB to FW in
> figure 9.
> 
>> 
>>  * Section 3.1 Policy Rules, first paragraph:
>> 
>>  "For firewalls the policy rule usually consists of a 5-tuple, source/
>>   destination addresses, transport protocol, and source/destination
>>   port numbers, plus an action, such as allow or deny."
>> 
>>   At least before reading the rest of the document, the word 'usually'
>>   seems a bit odd here. Do real alternative policy rules that do not
>>   contain the 5-tuple and action exist?
>> 
>>   I also think this sentence is not too clear, some kind of
>>   reformatting would be nice. For example, something like this (still
>>   having the word 'usually'):
>> 
>>  "For firewalls the policy rule usually consists of a 5-tuple and an
>>   action such as allow or deny. The information contained in the tuple
>>   includes source/destination addresses, transport protocol and
>>   source/destination port numbers."
> 
> This reads better! Replaced it.
> 
>> 
>>  * In addition to comments Niklas already gave on figure 11 on page
>>    24, I want to add that the figure and its legend do not
>>    match. There is no MB2 in the figure, and NF is present in the
>>    legend only in the text. As Niklas, I also think that it would be
>>    good to point out which node belongs to which network.
> 
> Fixed.
> 
>> 
>>  * Page 28, last bullet:
>>   "the lease time of the NI's IP address.  The chosen NATFW NSLP
>>    signaling session lifetime must be larger than the lease time,
>>    otherwise the IP address can be re-assigned to a different node.
>>    This node may receive unwanted traffic, although it never has
>>    requested a NAT/firewall configuration, which might be an issue in
>>    mobile environments.
>> 
>>    I just can not get the idea :) Should it be 'must be smaller than
>>    the lease time' ? If not, then I think some more text is needed.
> 
> Yep, you're right, it must be smaller. I also bumped in this when reading.
> Fixed.
> 
>> 
>>  * Page 45, middle bullet:
>>    "and outbound messages MUST be forwarded further inbound." 
>>    ->
>>    "and outbound messages MUST be forwarded further outbound." ?
> 
> Fixed to outbound.
> 
>> 
>>   * Table 1 on page 50, the last row, capitalization:
>>     left column: "IPsec SPI", right column: "ipsec-SPI"
> 
> That is intentionally, as the NATFW NSLP uses IPsec SPI as name and GIST uses
> ipsec-SPI.
> 
> Thanks a lot, 
> 
>   Martin
> 
>  
> [email protected]
> 
> NEC Laboratories Europe - Network Research Division
> 
> NEC Europe Limited | Registered Office: NEC House, 1 Victoria Road, London W3
> 6BL | Registered in England 2832014
>  
> 
> 
> 
> _______________________________________________
> nsis mailing list
> [email protected]
> https://www1.ietf.org/mailman/listinfo/nsis

_______________________________________________
nsis mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/nsis
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.