Re: [NSIS] I-D ACTION:draft-rahman-rtg-router-alert-dangerous-00.txt

"Tony Li" <[email protected]>
Newsgroups gmane.ietf.tsvwg,gmane.ietf.nsis
Message-ID <[email protected]>
 
Hi Francois,

|For this reason, Ashok and I have been planning to make a 
|proposal for  
|how RSVP could optionally operate without relying on RAO (e.g. based  
|on PID=46 matching, based directed signaling as already done in a  
|number of scenarios etc). This would avoid the RAO issue even if  
|routers do not yet support the new recommended RAO procedures.
|Any feedback/guidance from this community on that?


It seems to me that this entire area is delving WAY too far into the
implementation side of the world.  Please recall that the whole purpose of
the RAO was to make it easier for the data plane to sort out control plane
packets that would not otherwise be punted.

Prior to RAO existing, folks were already sending those control plane
packets anyway, and we asked the data plane to work much harder.  It seems
to me that you are, in effect, asking to undo this.  That seems
counter-productive to me.

The attacks listed in draft-rahman-rtg-router-alert-dangerous-00.txt exist
*whether or not RAO is used*.  If you ask routers to filter control plane
packets without RAO, then the bad guy simply targets his DoS attack against
those same control plane packets.  Regardless, the same mechanisms for
detecting and surviving DoS attacks must exist in every implementation.

Regards,
Tony
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.