Re: New WG Last Call on the Threats Assessment

"Randall R. Stewart (home)" <[email protected]>
Newsgroups gmane.ietf.rserpool
Message-ID <[email protected]>
[email protected] wrote:

>It seems to me that the only way to solve this is to have the PU send a
>message to the ENRP server and have the ENRP server check it out.  If they
>agree that the PE is down, then it should be removed; there is no problem
>with this case.
>
>The second case in which the PU thinks the PE is down, but the ENRP server
>can reach it, well, I think the ENRP server has to keep the entry for two
>reasons:
>
>1) the message from the PU might be malicious
>2) just because one PU can't reach the PE doesn't mean that other PUs can't
>reach it.
>
>In my opinion it doesn't matter if the PU is authenticated or not.  So
>again, I would change the actions of the ENRP server rather than the actions
>of the PU.
>
>By the way, it is not the application layer that is sending this message,
>but the ASAP protocol.  I do understand that the ASAP layer could be hacked
>to change the code.  
>
>Comments?
>  
>
Maureen:

I think that only the ENRP server reaching something or not has any weight
in determining when to remove a PE.

Just because one PU cannot reach a PE does not mean it is unreachable if 
the ENRP
server can get at it... hey you KNOW at least ONE subnet can reach it.. 
i.e. those
clients on the same sub-net as the ENRP server.... should they be denied 
access just
because someone else can't get to that particualr PE? I don't think so.. 
especially when
you consider that the local PU that can not access the PE will pick 
another one and
NOT try to reach the unreachable guy agaion....

I don't see this as an issue.. it is something that happens in the 
internet.. all are supposed
to be reachable but that is not necessarily how the real world works .. 
its imperfect but
it does frunction :--0

R


-- 
Randall R. Stewart
[email protected] 815-342-5222 (cell phone)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.