6 Nov 17:48
TCP Authentication discussion: tcpm wg, Thursday 1300-1500
Bill Fenner <fenner <at> research.att.com>
2006-11-06 16:48:15 GMT
2006-11-06 16:48:15 GMT
Hi, I'd like to draw your attention to the tcpm working group agenda; it begins with a discussion of draft-bellovin-tcpsec, whose abstract reads: The TCP-MD5 option, commonly used to secure BGP sessions between routers, has many serious deficiencies. We present here justifications for designing a new, more capable version of that option; we also discuss some of the design criteria for one. I'd encourage those with thoughts and experience in this area to attend if you can. Thanks, Bill _______________________________________________ Idr mailing list Idr <at> ietf.org https://www1.ietf.org/mailman/listinfo/idr
.
Regards,
Juanjo
----- Remitido por JUAN JOSE ADAN LUENGO/GISS/SEG-SOCIAL con fecha
10/11/2006 10:39 -----
Robert Raszuk <raszuk <at> cisco.com> escribió el 09/11/2006 00:56:33:
> Hi Juan,
>
> Below are my more detailed comments. You have a choice to ignore them or
> attempt to work together to simplify the current proposal to be much
> more easy to deploy both from vendor as well as customers point of view.
>
> Comments:
> ---------
>
> > I sent a draft in October on "Tunneled Inter-domain Routing" (TIDR):
> > draft-adan-idr-tidr-00.txt.
.
> The idea of having an IP address for an AS is something that
> I also considered but I think it is much more interesting to
> have a prefix so that we could even specify a specific entry
> point in the AS por traffic directed to a specific "identifier
> prefix". And a specific locator could be configured as an anycast
> IP address so that in case of a problem in an entry point, the
> tunneled traffic could be delivered through another entry point.
+
> Don't you think it is better to have several AS IPs instead of just
> one?.
I think we both agree on the anycasting model. I also think we all agree
on the need for more then one dst for end AS. Most practical need is
triggered for a prefix group based inbound traffic engineering.
The only disconnects are I think minor reg the allocation model of those
destinations and their choice of signaling.
> I think my proposal is much more general. Most of the value-added
> services are based on tunnels (mobility, VPNs, TE,...). I think
> there is a need for a richer routing paradigm, and in my opinion
RSS Feed