Re: [NSIS] I-D ACTION:draft-rahman-rtg-router-alert-dangerous-00.txt
"Tony Li" <[email protected]>
| Newsgroups | gmane.ietf.tsvwg,gmane.ietf.nsis |
|---|---|
| Message-ID | <[email protected]> |
Hi Francois, |For this reason, Ashok and I have been planning to make a |proposal for |how RSVP could optionally operate without relying on RAO (e.g. based |on PID=46 matching, based directed signaling as already done in a |number of scenarios etc). This would avoid the RAO issue even if |routers do not yet support the new recommended RAO procedures. |Any feedback/guidance from this community on that? It seems to me that this entire area is delving WAY too far into the implementation side of the world. Please recall that the whole purpose of the RAO was to make it easier for the data plane to sort out control plane packets that would not otherwise be punted. Prior to RAO existing, folks were already sending those control plane packets anyway, and we asked the data plane to work much harder. It seems to me that you are, in effect, asking to undo this. That seems counter-productive to me. The attacks listed in draft-rahman-rtg-router-alert-dangerous-00.txt exist *whether or not RAO is used*. If you ask routers to filter control plane packets without RAO, then the bad guy simply targets his DoS attack against those same control plane packets. Regardless, the same mechanisms for detecting and surviving DoS attacks must exist in every implementation. Regards, Tony