Re: Should ASAP be splitted?

Manuel Urueña <[email protected]>
Newsgroups gmane.ietf.rserpool
Organization Universidad Carlos III de Madrid
Message-ID <[email protected]>
Hi Qiaobing,

Good suggestion, two ports would be enough if ENRP Servers only accept
Register operations from the PE port. That port should be filtered for
IP addresses outside the Pool range to provide an additional security
level.

Just another question, I was not able to go to the IETF #58 Rserpool
meeting. Does anybody raise the MAX-BAD-PE-REPORT DoS issue?

Thanks,
--Manuel


Quiaobing Xie wrote:
>
> Hi, Manuel,
>
> I think you have raised a quite interesting point. But to further split
> ASAP seems not a good idea, since we already see the difficult for
> people to have to read two documents (ENRP and ASAP) at the same time in
> order to under RSERPOOL operations. This is because they are tightly
> related. Further split of ASAP will make this even harder.
> 
> We may be able to achieve the same thing you described by asking for two
> separate ports for PU and PE. Just a though.
>
> regards,
> -Qiaobing
>
> Manuel Urueña wrote:
> > 
> > Hi,
> > 
> > Reading the ASAP draft I felt that it seems a little overloaded. In
> > particular, registration operations are just employed by PEs.
> > 
> > Maybe it would be good to put those operations in another protocol. Or
> > exactly the same ASAP protocol but without PU related operations. Of
> > course PE would require both protocols.
> > 
> > This will ease firewall protection, I mean, with ASAP firewalls should
> > allow ASAP connections to both PEs and NSs. Therefore, remote PUs are
> > able to send Registration operations to NSs. With two separate
> > protocols, registration port could be filtered.
> > 
> > Has been this discussed before? comments?
> > 
> > Regards,
> > --Manuel
-- 
Manuel Uruen~a - Universidad Carlos III de Madrid
GPG FP: 68A1 164B EE28 52C9 87CB  EBF9 616E 52B5 451A B6B2
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQA/uiWzYW5StUUatrIRAkNeAJ9lTwW5OTXCmBjVfVHBO/KyX/sjkgCdHJSR
nG2TGji+GsePghVQ3TXw5aY=
=M5uV
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.