1 Feb 2010 17:25
Re: [MEXT] WGLC for firewall drafts
Yuri Ismailov <yuri <at> ismailov.eu>
2010-02-01 16:25:17 GMT
2010-02-01 16:25:17 GMT
Hi, I reviewed the draft draft-ietf-mext-firewall-admin-02. The document looks quite solid and addresses all important issues. However, there is one issue, in my opinion, which was left aside in the draft. I think that the section 6.2 should be completed with the recommendations about letting specific ICMPv4 error messages to pass through firewalls. This has to do with the path MTU discovery. Because this draft is concerned the firewall traversal, there is no need to talk about MTU tuning, however, I believe that firewall traversal is worth while mentioning. There is a reference to RFC 4890 at the end, which is concerned with ICMPv6 only. When using DSMIPv6 with NAT traversal, ICMPv4 error messages regarding MTU size could be sent as well. Thus the suggestion is to additionally refer the specifications RFC1191 and RFC1981, specifying path MTU discovery for IPv4 and IPv6 correspondingly. I suggest to add some text (see proposal below) at the end of the section 6.2, which specifically addresses data packets for DSMIPv6. Signaling packets probably not that important as MTU sizes will not be exceeded, or in case it will happen, the result will be anyway ICMPv4 error messages as signaling will be UDP encapsulated as well. Proposed text at the end of the section 6.2(Continue reading)
RSS Feed