Re: [Netconf] I-D Action: draft-ietf-netconf-reverse-ssh-00.txt

t.petch <[email protected]>
Newsgroups gmane.ietf.secsh
Message-ID <[email protected]>
----- Original Message -----
From: "Kent Watsen" <[email protected]>
To: "t.petch" <[email protected]>; "Jeffrey Hutzelman" <[email protected]>
Cc: <[email protected]>
Sent: Tuesday, June 25, 2013 11:06 PM
On 6/25/13 10:44 AM, "t.petch" <[email protected]> wrote:
>It seems to me that call home needs a Signal, like an answerphone
>message (Please Call) and that that signal can be any PDU over any
>protocol but must specify the protocols to be used for the call -
>Netconf over SSH, SNMP over TLS, etc.
>
>Here the signal seems to be a 3-way handshake, in which case the
>destination port would have to differentiate between the protocol
>combinations and so this cannot be a generic mechanism.  The security
>consideration that then comes first to me is a DoS attack via the 3-way
>handshake, nothing to do with SAAG but rather TCPM territory.

I'm not following your analogy, but I agree that there is a DoS attack,
as
there is with any open TCP port, perhaps worse because it can start
expensive asymmetric key algs.  Of course, many people I know claim that
they'd rather see the app get DoS-ed over the device, since it can more
easily overcome such an event.


>It would seem from the I-D that whether the TCP connection is reused,
or
>whether the Netconf client fires up a fresh connection is unspecified;
I
>would assume the latter, to the regular port on the Netconf server.

We (Juniper) have also explored this - using SNMP Traps actually.  It
works fairly well for automating the discovery of devices with static
IPs
on a reachable network, but not at all when the devices are behind a
firewall that won't allow inbound SSH connections.

<tp>

I am really confused.  If the device/netconf server will not allow
inbound SSH connections,  then I cannot see how your I-D can work.  It
has the device setting up a TCP connection on a port which signals to
the Netconf client/NMS to make an SSH connection to the Netconf
server/device - which cannot succeed because the devices are behind a
firewall which won't allow inbound SSH connections.

So as I understand the design it cannot meet what I understand to be the
requirements.

Tom Petch
</tp>
Thanks,
Kent
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.