Jeff's comments on Assumptions for L3-discovery #1

Open
opened 2022-02-27 19:41:23 +00:00 by shares · 0 comments

Sue's assumptions:

  1. BGP configuration portion (draft-ymbk-idr-l3nd-ulpc-01) should use common TLVs

  2. multicast is used because there are
    a) fewer transmitters than receivers
    b) many unknown receivers

  3. topologies in DC include the following
    a) CLOS, b) 1000 peering, c) point-to-point, and d) 1000 next-hops

  4. security is necessary for some data centers, but not all
    a) Some DC will want encryption,
    b) some DC need man-in-middle protection

  5. Two types of reliable exchange exist:
    a) reliable exchange without timers
    b) reliable exchange with timers

Implementations vary on what is efficient for #5.

=====

Response on these basic assumptions from Jeff:
#1) Same TLVS in the protocols is not important, but the same information is
important.

#2) Agreement on #2a on multicast.
#3) Agreement on #3a-c, but if 1000 next-hops on DC link, then the people should use a route server.
#4) agreement on basic statement, disagreement on what is reasonable.

"And window congestion attacks, session exhaustion attacks, etc. All of these things are just taking the BGP attack space and making it 2x worse."
This is also Jeff's comment about using tcp-md5/ao is to prevent some of those [attacks].

#5) #5b is what uses less router resources.

Sue's assumptions: 1) BGP configuration portion (draft-ymbk-idr-l3nd-ulpc-01) should use common TLVs 2) multicast is used because there are a) fewer transmitters than receivers b) many unknown receivers 3) topologies in DC include the following a) CLOS, b) 1000 peering, c) point-to-point, and d) 1000 next-hops 4) security is necessary for some data centers, but not all a) Some DC will want encryption, b) some DC need man-in-middle protection 5) Two types of reliable exchange exist: a) reliable exchange without timers b) reliable exchange with timers Implementations vary on what is efficient for #5. ===== Response on these basic assumptions from Jeff: #1) Same TLVS in the protocols is not important, but the same information is important. #2) Agreement on #2a on multicast. #3) Agreement on #3a-c, but if 1000 next-hops on DC link, then the people should use a route server. #4) agreement on basic statement, disagreement on what is reasonable. "And window congestion attacks, session exhaustion attacks, etc. All of these things are just taking the BGP attack space and making it 2x worse." This is also Jeff's comment about using tcp-md5/ao is to prevent some of those [attacks]. #5) #5b is what uses less router resources.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: randy/draft-l3nd#1
No description provided.