Re: WGLC: draft-ietf-nsis-nslp-natfw-16.txt
Martin Stiemerling <[email protected]>
| Newsgroups | gmane.ietf.nsis |
|---|---|
| Message-ID | <C3C3A533.E898%[email protected]> |
Just as an addendum: IPsec SPI has been changed to IPsec-SPI. Martin Am 24.01.2008 16:24 Uhr schrieb "Martin Stiemerling" unter <[email protected]>: > Hi Lauri, > > Am 13.12.2007 um 01:08 schrieb Lauri J T Liuhto: > >> On Fri, 23 Nov 2007, Martin Stiemerling wrote: >> >>> The authors believe that the NATFW NSLP >>> (draft-ietf-nsis-nslp-natfw-16.txt) is ready for WGLC. >>> The WGLC starts today and will run until December 14th. >>> >> >> Hi, >> >> I have read the document, and I did not find any big issues, mainly >> just some editorial things. I did not repeat findings already >> provided by Jukka or Niklas. >> >> Some parts of the text, mainly Section 3 (Protocol Description), was >> such, that I can not be sure whether I understood it completely. The >> text itself was quite easy to read, but I think those who have >> implemented this protocol can say more accurately how well the protocol >> actually is described. >> >> To make it short: I think the specification is in quite nice state, and >> needs just some editorial fixes. > > Thanks! :) > >> >> Here are my comments on the draft: >> >> * At page 11, line 571: 'routeable' --> 'routable' (?) > > Fixed. > >> >> * Examples in Section 2 use mainly 'MB' in figures to represent NAT >> and/or FW nodes. However, I think the use is not always >> consistent. For example, in the figure 2 'FW' is used (and I think >> it is ok, because the text explicitly states that this example is >> about FW-only cases), but figure 9 in section 2.8 has 'MB's >> instead. If those middle boxes in scenario 2.8 may be also NATs, I >> think it would be nice to have it in text. If those middle boxes >> are always firewalls as I think the text states, then the figure >> should be changed. >> >> However, I think that the text is clear enough already, and the >> easy fix would be to change the 'FW' boxes to 'MB' boxes in the >> figure 2 :) > > 2.8 and 2.7 have a subtle difference and it is better to change MB to FW in > figure 9. > >> >> * Section 3.1 Policy Rules, first paragraph: >> >> "For firewalls the policy rule usually consists of a 5-tuple, source/ >> destination addresses, transport protocol, and source/destination >> port numbers, plus an action, such as allow or deny." >> >> At least before reading the rest of the document, the word 'usually' >> seems a bit odd here. Do real alternative policy rules that do not >> contain the 5-tuple and action exist? >> >> I also think this sentence is not too clear, some kind of >> reformatting would be nice. For example, something like this (still >> having the word 'usually'): >> >> "For firewalls the policy rule usually consists of a 5-tuple and an >> action such as allow or deny. The information contained in the tuple >> includes source/destination addresses, transport protocol and >> source/destination port numbers." > > This reads better! Replaced it. > >> >> * In addition to comments Niklas already gave on figure 11 on page >> 24, I want to add that the figure and its legend do not >> match. There is no MB2 in the figure, and NF is present in the >> legend only in the text. As Niklas, I also think that it would be >> good to point out which node belongs to which network. > > Fixed. > >> >> * Page 28, last bullet: >> "the lease time of the NI's IP address. The chosen NATFW NSLP >> signaling session lifetime must be larger than the lease time, >> otherwise the IP address can be re-assigned to a different node. >> This node may receive unwanted traffic, although it never has >> requested a NAT/firewall configuration, which might be an issue in >> mobile environments. >> >> I just can not get the idea :) Should it be 'must be smaller than >> the lease time' ? If not, then I think some more text is needed. > > Yep, you're right, it must be smaller. I also bumped in this when reading. > Fixed. > >> >> * Page 45, middle bullet: >> "and outbound messages MUST be forwarded further inbound." >> -> >> "and outbound messages MUST be forwarded further outbound." ? > > Fixed to outbound. > >> >> * Table 1 on page 50, the last row, capitalization: >> left column: "IPsec SPI", right column: "ipsec-SPI" > > That is intentionally, as the NATFW NSLP uses IPsec SPI as name and GIST uses > ipsec-SPI. > > Thanks a lot, > > Martin > > > [email protected] > > NEC Laboratories Europe - Network Research Division > > NEC Europe Limited | Registered Office: NEC House, 1 Victoria Road, London W3 > 6BL | Registered in England 2832014 > > > > > _______________________________________________ > nsis mailing list > [email protected] > https://www1.ietf.org/mailman/listinfo/nsis _______________________________________________ nsis mailing list [email protected] https://www1.ietf.org/mailman/listinfo/nsis