
From nobody Fri Mar  3 15:55:58 2017
Return-Path: <agenda@ietf.org>
X-Original-To: opsec@ietf.org
Delivered-To: opsec@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id D4DB6128874; Fri,  3 Mar 2017 15:55:19 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: "\"IETF Secretariat\"" <agenda@ietf.org>
To: <opsec-chairs@ietf.org>, <gunter@vandevelde.cc>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.46.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <148858531986.15846.4842543589731005298.idtracker@ietfa.amsl.com>
Date: Fri, 03 Mar 2017 15:55:19 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/kApUhjRTMKngmXuInUubgQeRtZk>
Cc: opsec@ietf.org
Subject: [OPSEC] opsec - Requested session has been scheduled for IETF 98
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.17
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Mar 2017 23:55:20 -0000

Dear Gunter Van de Velde,

The session(s) that you have requested have been scheduled.
Below is the scheduled session information followed by
the original request. 

opsec Session 1 (1:30:00)
    Tuesday, Afternoon Session III 1640-1840
    Room Name: Zurich A size: 115
    ---------------------------------------------
    


Request Information:


---------------------------------------------------------
Working Group Name: Operational Security Capabilities for IP Network Infrastructure
Area Name: Operations and Management Area
Session Requester: Gunter Van de Velde

Number of Sessions: 1
Length of Session(s):  1.5 Hours
Number of Attendees: 75
Conflicts to Avoid: 
 First Priority: 6man sidrops v6ops
 Second Priority: opsawg
 Third Priority: acme homenet quic


People who must be present:
  Joel Jaeggli
  Eric Vyncke
  Gunter Van de Velde

Resources Requested:

Special Requests:
  
---------------------------------------------------------


From nobody Mon Mar 13 05:28:44 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: opsec@ietf.org
Delivered-To: opsec@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 8F1741295A7; Mon, 13 Mar 2017 05:28:39 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.47.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <148940811955.16995.9644742747165941512@ietfa.amsl.com>
Date: Mon, 13 Mar 2017 05:28:39 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/WxoNM4SGFaX9lPpkkWytEir0AC0>
Cc: opsec@ietf.org
Subject: [OPSEC] I-D Action: draft-ietf-opsec-v6-10.txt
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.17
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Mar 2017 12:28:39 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Operational Security Capabilities for IP Network Infrastructure of the IETF.

        Title           : Operational Security Considerations for IPv6 Networks
        Authors         : Kiran K. Chittimaneni
                          Merike Kaeo
                          Eric Vyncke
	Filename        : draft-ietf-opsec-v6-10.txt
	Pages           : 46
	Date            : 2017-03-13

Abstract:
   Knowledge and experience on how to operate IPv4 securely is
   available: whether it is the Internet or an enterprise internal
   network.  However, IPv6 presents some new security challenges.  RFC
   4942 describes the security issues in the protocol but network
   managers also need a more practical, operations-minded document to
   enumerate advantages and/or disadvantages of certain choices.

   This document analyzes the operational security issues in all places
   of a network (enterprises, service providers and residential users)
   and proposes technical and procedural mitigations techniques.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-opsec-v6/

There's also a htmlized version available at:
https://tools.ietf.org/html/draft-ietf-opsec-v6-10

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-opsec-v6-10


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Wed Mar 29 11:22:10 2017
Return-Path: <wwwrun@rfc-editor.org>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DDFE3128854; Wed, 29 Mar 2017 11:22:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.202
X-Spam-Level: 
X-Spam-Status: No, score=-4.202 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xpgO44vJ9kj1; Wed, 29 Mar 2017 11:21:58 -0700 (PDT)
Received: from rfc-editor.org (rfc-editor.org [4.31.198.49]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 742521267BB; Wed, 29 Mar 2017 11:21:58 -0700 (PDT)
Received: by rfc-editor.org (Postfix, from userid 30) id BF8F8B80D6F; Wed, 29 Mar 2017 11:21:47 -0700 (PDT)
To: hugocanalli@gmail.com, dave@juniper.net, cpignata@cisco.com, rodunn@cisco.com
X-PHP-Originating-Script: 30:errata_mail_lib.php
From: RFC Errata System <rfc-editor@rfc-editor.org>
Cc: joelja@bogus.com, iesg@ietf.org, opsec@ietf.org, rfc-editor@rfc-editor.org
Content-Type: text/plain; charset=UTF-8
Message-Id: <20170329182147.BF8F8B80D6F@rfc-editor.org>
Date: Wed, 29 Mar 2017 11:21:47 -0700 (PDT)
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/e9Iok_fBFklg138C3m1cmzIx7XY>
Subject: [OPSEC] [Errata Verified] RFC6192 (4851)
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Mar 2017 18:22:01 -0000

The following errata report has been verified for RFC6192,
"Protecting the Router Control Plane". 

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=6192&eid=4851

--------------------------------------
Status: Verified
Type: Technical

Reported by: Hugo Leonardo Canalli <hugocanalli@gmail.com>
Date Reported: 2016-11-01
Verified by: joel jaeggli (IESG)

Section: A.2

Original Text
-------------
   term ebgp-reply {
                   from {
                       source-prefix-list {
                           EBGP-NEIGHBORS;
                       }
                       protocol tcp;
                       port bgp;
                   }
                   then accept;
               }

Corrected Text
--------------
   term ebgp-reply {
                   from {
                       source-prefix-list {
                           EBGP-NEIGHBORS;
                       }
                       protocol tcp;
                       tcp-established;
                       source-port bgp;
                   }
                   then accept;
               }



Notes
-----
There is a security question in that firewall relating to bgp reply.
Any neighbor that fakes a tcp source port to 179 can access any router port, for example, ssh.
Need to add the line tcp-established. Would also be better to add source-port bgp since bgp protocol uses the 179 port to destination. Add the fix to all bgps, including ipv6.

--------------------------------------
RFC6192 (draft-ietf-opsec-protect-control-plane-06)
--------------------------------------
Title               : Protecting the Router Control Plane
Publication Date    : March 2011
Author(s)           : D. Dugal, C. Pignataro, R. Dunn
Category            : INFORMATIONAL
Source              : Operational Security Capabilities for IP Network Infrastructure
Area                : Operations and Management
Stream              : IETF
Verifying Party     : IESG


From nobody Wed Mar 29 13:37:15 2017
Return-Path: <Donald.Smith@CenturyLink.com>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6A27F1298CC; Wed, 29 Mar 2017 13:37:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id EhpkyF12aua3; Wed, 29 Mar 2017 13:37:11 -0700 (PDT)
Received: from lxomp52w.centurylink.com (lxomp52w.centurylink.com [155.70.50.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C977212957C; Wed, 29 Mar 2017 13:37:10 -0700 (PDT)
Received: from lxdenvmpc030.qintra.com (emailout.qintra.com [10.1.51.30]) by lxomp52w.centurylink.com (8.14.8/8.14.8) with ESMTP id v2TKb74J055715 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 29 Mar 2017 15:37:08 -0500
Received: from lxdenvmpc030.qintra.com (unknown [127.0.0.1]) by IMSA (Postfix) with ESMTP id B7EAB1E0065; Wed, 29 Mar 2017 14:37:02 -0600 (MDT)
Received: from lxdnp32k.corp.intranet (unknown [151.119.92.134]) by lxdenvmpc030.qintra.com (Postfix) with ESMTP id 957FC1E0049; Wed, 29 Mar 2017 14:37:02 -0600 (MDT)
Received: from lxdnp32k.corp.intranet (localhost [127.0.0.1]) by lxdnp32k.corp.intranet (8.14.8/8.14.8) with ESMTP id v2TKb2bk047101; Wed, 29 Mar 2017 14:37:02 -0600
Received: from vddcwhubex502.ctl.intranet (vddcwhubex502.ctl.intranet [151.119.128.29]) by lxdnp32k.corp.intranet (8.14.8/8.14.8) with ESMTP id v2TKb2XV047097 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Wed, 29 Mar 2017 14:37:02 -0600
Received: from PDDCWMBXEX503.ctl.intranet ([fe80::9033:ef22:df02:32a9]) by vddcwhubex502.ctl.intranet ([151.119.128.29]) with mapi id 14.03.0339.000; Wed, 29 Mar 2017 14:37:01 -0600
From: "Smith, Donald" <Donald.Smith@CenturyLink.com>
To: RFC Errata System <rfc-editor@rfc-editor.org>, "hugocanalli@gmail.com" <hugocanalli@gmail.com>, "dave@juniper.net" <dave@juniper.net>, "cpignata@cisco.com" <cpignata@cisco.com>, "rodunn@cisco.com" <rodunn@cisco.com>
CC: "opsec@ietf.org" <opsec@ietf.org>, "iesg@ietf.org" <iesg@ietf.org>
Thread-Topic: [OPSEC] [Errata Verified] RFC6192 (4851)
Thread-Index: AQHSqLlu3ULAhDNPBkO7ZD5wwL9Os6GsRiKp
Date: Wed, 29 Mar 2017 20:37:01 +0000
Message-ID: <68EFACB32CF4464298EA2779B058889D53BB78AD@PDDCWMBXEX503.ctl.intranet>
References: <20170329182147.BF8F8B80D6F@rfc-editor.org>
In-Reply-To: <20170329182147.BF8F8B80D6F@rfc-editor.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [151.119.128.7]
Content-Type: multipart/alternative; boundary="_000_68EFACB32CF4464298EA2779B058889D53BB78ADPDDCWMBXEX503ct_"
MIME-Version: 1.0
X-TM-AS-MML: disable
X-CFilter-Loop: Reflected
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/daHFFjGMRrbUBDWEma-q3HuCl5M>
Subject: Re: [OPSEC] [Errata Verified] RFC6192 (4851)
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Mar 2017 20:37:13 -0000

--_000_68EFACB32CF4464298EA2779B058889D53BB78ADPDDCWMBXEX503ct_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

I think the established will block fins, and resets unless they happen to h=
ave the ACK bit set too.

It will block syn only packets too but since this is for ebgp-reply that sh=
ould be ok.







if (initial_ttl!=3D255) then (rfc5082_compliant=3D=3D0)
Donald.Smith@centurylink.com<mailto:Donald.Smith@centurylink.com>
________________________________
From: OPSEC [opsec-bounces@ietf.org] on behalf of RFC Errata System [rfc-ed=
itor@rfc-editor.org]
Sent: Wednesday, March 29, 2017 12:21 PM
To: hugocanalli@gmail.com; dave@juniper.net; cpignata@cisco.com; rodunn@cis=
co.com
Cc: opsec@ietf.org; iesg@ietf.org; rfc-editor@rfc-editor.org
Subject: [OPSEC] [Errata Verified] RFC6192 (4851)

The following errata report has been verified for RFC6192,
"Protecting the Router Control Plane".

--------------------------------------
You may review the report below and at:
http://www.rfc-editor.org/errata_search.php?rfc=3D6192&eid=3D4851

--------------------------------------
Status: Verified
Type: Technical

Reported by: Hugo Leonardo Canalli <hugocanalli@gmail.com>
Date Reported: 2016-11-01
Verified by: joel jaeggli (IESG)

Section: A.2

Original Text
-------------
   term ebgp-reply {
                   from {
                       source-prefix-list {
                           EBGP-NEIGHBORS;
                       }
                       protocol tcp;
                       port bgp;
                   }
                   then accept;
               }

Corrected Text
--------------
   term ebgp-reply {
                   from {
                       source-prefix-list {
                           EBGP-NEIGHBORS;
                       }
                       protocol tcp;
                       tcp-established;
                       source-port bgp;
                   }
                   then accept;
               }



Notes
-----
There is a security question in that firewall relating to bgp reply.
Any neighbor that fakes a tcp source port to 179 can access any router port=
, for example, ssh.
Need to add the line tcp-established. Would also be better to add source-po=
rt bgp since bgp protocol uses the 179 port to destination. Add the fix to =
all bgps, including ipv6.

--------------------------------------
RFC6192 (draft-ietf-opsec-protect-control-plane-06)
--------------------------------------
Title               : Protecting the Router Control Plane
Publication Date    : March 2011
Author(s)           : D. Dugal, C. Pignataro, R. Dunn
Category            : INFORMATIONAL
Source              : Operational Security Capabilities for IP Network Infr=
astructure
Area                : Operations and Management
Stream              : IETF
Verifying Party     : IESG

_______________________________________________
OPSEC mailing list
OPSEC@ietf.org
https://www.ietf.org/mailman/listinfo/opsec


This communication is the property of CenturyLink and may contain confident=
ial or privileged information. Unauthorized use of this communication is st=
rictly prohibited and may be unlawful. If you have received this communicat=
ion in error, please immediately notify the sender by reply e-mail and dest=
roy all copies of the communication and any attachments.

--_000_68EFACB32CF4464298EA2779B058889D53BB78ADPDDCWMBXEX503ct_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html dir=3D"ltr">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style>.EmailQuote {
	PADDING-LEFT: 4pt; MARGIN-LEFT: 1pt; BORDER-LEFT: #800000 2px solid
}
</style><style id=3D"owaParaStyle">P {
	MARGIN-BOTTOM: 0px; MARGIN-TOP: 0px
}
</style>
</head>
<body fPStyle=3D"1" ocsi=3D"0">
<div style=3D"direction: ltr;font-family: Tahoma;color: #000000;font-size: =
10pt;">
<p>I think the established will block fins,&nbsp;and resets unless they hap=
pen to have the ACK bit set too.</p>
<p>It will block syn only packets too but since this is for ebgp-reply that=
 should be ok.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div>
<p>&nbsp;</p>
<div style=3D"FONT-SIZE: 13px; FONT-FAMILY: Tahoma">
<div><font size=3D"2">
<div>if (initial_ttl!=3D255) then (rfc5082_compliant=3D=3D0)</div>
</font></div>
<div><font size=3D"2"><a href=3D"mailto:Donald.Smith@centurylink.com">Donal=
d.Smith@centurylink.com</a></font></div>
</div>
</div>
<div style=3D"FONT-SIZE: 16px; FONT-FAMILY: Times New Roman; COLOR: #000000=
">
<div>
<hr tabindex=3D"-1">
<div id=3D"divRpF131650" style=3D"DIRECTION: ltr"><font color=3D"#000000" s=
ize=3D"2" face=3D"Tahoma"><b>From:</b> OPSEC [opsec-bounces@ietf.org] on be=
half of RFC Errata System [rfc-editor@rfc-editor.org]<br>
<b>Sent:</b> Wednesday, March 29, 2017 12:21 PM<br>
<b>To:</b> hugocanalli@gmail.com; dave@juniper.net; cpignata@cisco.com; rod=
unn@cisco.com<br>
<b>Cc:</b> opsec@ietf.org; iesg@ietf.org; rfc-editor@rfc-editor.org<br>
<b>Subject:</b> [OPSEC] [Errata Verified] RFC6192 (4851)<br>
</font><br>
</div>
<div></div>
</div>
<font size=3D"2"><span style=3D"FONT-SIZE: 10pt">
<div class=3D"PlainText">The following errata report has been verified for =
RFC6192,<br>
&quot;Protecting the Router Control Plane&quot;. <br>
<br>
--------------------------------------<br>
You may review the report below and at:<br>
<a href=3D"http://www.rfc-editor.org/errata_search.php?rfc=3D6192&amp;eid=
=3D4851" target=3D"_blank">http://www.rfc-editor.org/errata_search.php?rfc=
=3D6192&amp;eid=3D4851</a><br>
<br>
--------------------------------------<br>
Status: Verified<br>
Type: Technical<br>
<br>
Reported by: Hugo Leonardo Canalli &lt;hugocanalli@gmail.com&gt;<br>
Date Reported: 2016-11-01<br>
Verified by: joel jaeggli (IESG)<br>
<br>
Section: A.2<br>
<br>
Original Text<br>
-------------<br>
&nbsp;&nbsp; term ebgp-reply {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; from {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; source-prefix-lis=
t {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp; EBGP-NEIGHBORS;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; protocol tcp;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; port bgp;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; then accept;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; }<br>
<br>
Corrected Text<br>
--------------<br>
&nbsp;&nbsp; term ebgp-reply {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; from {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; source-prefix-lis=
t {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp; EBGP-NEIGHBORS;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; protocol tcp;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; tcp-established;<=
br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; source-port bgp;<=
br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; then accept;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; }<br>
<br>
<br>
<br>
Notes<br>
-----<br>
There is a security question in that firewall relating to bgp reply.<br>
Any neighbor that fakes a tcp source port to 179 can access any router port=
, for example, ssh.<br>
Need to add the line tcp-established. Would also be better to add source-po=
rt bgp since bgp protocol uses the 179 port to destination. Add the fix to =
all bgps, including ipv6.<br>
<br>
--------------------------------------<br>
RFC6192 (draft-ietf-opsec-protect-control-plane-06)<br>
--------------------------------------<br>
Title&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp; : Protecting the Router Control Plane<br>
Publication Date&nbsp;&nbsp;&nbsp; : March 2011<br>
Author(s)&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; : D. =
Dugal, C. Pignataro, R. Dunn<br>
Category&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
: INFORMATIONAL<br>
Source&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; : Operational Security Capabilities for IP Network Infrastructure=
<br>
Area&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp; : Operations and Management<br>
Stream&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp; : IETF<br>
Verifying Party&nbsp;&nbsp;&nbsp;&nbsp; : IESG<br>
<br>
_______________________________________________<br>
OPSEC mailing list<br>
OPSEC@ietf.org<br>
<a href=3D"https://www.ietf.org/mailman/listinfo/opsec" target=3D"_blank">h=
ttps://www.ietf.org/mailman/listinfo/opsec</a><br>
<br>
<br>
</div>
</span></font></div>
</div>
<center>This communication is the property of CenturyLink and may contain c=
onfidential or privileged information. Unauthorized use of this communicati=
on is strictly prohibited and may be unlawful. If you have received this co=
mmunication in error, please immediately
 notify the sender by reply e-mail and destroy all copies of the communicat=
ion and any attachments.</center>
</body>
</html>

--_000_68EFACB32CF4464298EA2779B058889D53BB78ADPDDCWMBXEX503ct_--


From nobody Fri Mar 31 09:59:09 2017
Return-Path: <dave@juniper.net>
X-Original-To: opsec@ietfa.amsl.com
Delivered-To: opsec@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 05999129574; Fri, 31 Mar 2017 09:59:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.921
X-Spam-Level: 
X-Spam-Status: No, score=-1.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=junipernetworks.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pb6efGnE82qE; Fri, 31 Mar 2017 09:58:59 -0700 (PDT)
Received: from NAM03-BY2-obe.outbound.protection.outlook.com (mail-by2nam03on0091.outbound.protection.outlook.com [104.47.42.91]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 424D6129512; Fri, 31 Mar 2017 09:58:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=junipernetworks.onmicrosoft.com; s=selector1-juniper-net; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=/O1gx66LB0yI/w1tSRi0p53Ksnijr56OS9iLiIH+kLI=; b=hK2ZJZZvD2sh40dQJHOSDryGCD3Fu3GwfZGQSvUYJr7K2Ib0+yyekJpjD0Fr4apKcKp9MBwESUAbOQG0QpiXDboLft9W2ZRsJOyg65ShDRsnmYRfvokh19sE0FryaG/BcYP+UnDSyHCav77K10dA20cWuGqm+ApO+ZsSl6YYm+s=
Authentication-Results: juniper.net; dkim=none (message not signed) header.d=none;juniper.net; dmarc=none action=none header.from=juniper.net;
Received: from [172.29.38.168] (66.129.241.12) by BLUPR0501MB1073.namprd05.prod.outlook.com (10.160.34.142) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1019.8; Fri, 31 Mar 2017 16:58:57 +0000
References: <20170329182147.BF8F8B80D6F@rfc-editor.org> <68EFACB32CF4464298EA2779B058889D53BB78AD@PDDCWMBXEX503.ctl.intranet>
CC: "Smith, Donald" <Donald.Smith@CenturyLink.com>, "cpignata@cisco.com" <cpignata@cisco.com>, "rodunn@cisco.com" <rodunn@cisco.com>, "opsec@ietf.org" <opsec@ietf.org>, "iesg@ietf.org" <iesg@ietf.org>
To: RFC Errata System <rfc-editor@rfc-editor.org>, "hugocanalli@gmail.com" <hugocanalli@gmail.com>
From: Dave Dugal <dave@juniper.net>
Openpgp: url=http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x879F65CDAB6E02A5
Organization: Juniper Networks, Inc.
Message-ID: <e5c1e1c6-c714-52e6-0939-976f4e95c50c@juniper.net>
Date: Fri, 31 Mar 2017 12:58:53 -0400
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.8.0
MIME-Version: 1.0
In-Reply-To: <68EFACB32CF4464298EA2779B058889D53BB78AD@PDDCWMBXEX503.ctl.intranet>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
X-Originating-IP: [66.129.241.12]
X-ClientProxiedBy: BN6PR03CA0023.namprd03.prod.outlook.com (10.168.230.161) To BLUPR0501MB1073.namprd05.prod.outlook.com (10.160.34.142)
X-MS-Office365-Filtering-Correlation-Id: b3dcd289-cb55-42d4-1ae5-08d47857390d
X-MS-Office365-Filtering-HT: Tenant
X-Microsoft-Antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(48565401081)(201703131423075)(201703031133081); SRVR:BLUPR0501MB1073; 
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB1073; 3:3DSSK5BKV0QsQvQ5006branWdRxvQLlrKu+SrGxIfD9xF2WZ0tFboOy/XIgL0ZXFjWnFZ/vLG97nbgnUNBvUyr98z2jVLcm6aWLdycYhRxhb+CnFJMza+skfDxUxzM+3vtd/ho2Jr2yeaRwOCHzgF94UsXMyasrl2wrqHo4p85hCsTmKOYO4C5CWHAO1Z7XhhHE06I819A/YBTbMdusJ/TTJzr2Z0C8aI2PNRcCmKEb5fxh/yFqeJ5LGKDQeC3yzD9EA3xmzPB6K/yp8FRuBqN+OwKSq8Lu3DukQgUmNPYtvO58QNIOohJXqypqOGMkxM5ZR/jFn8ziIG1Y5Q+MWrY3NWor8EwHT0F58Sd40K/s=; 25:hHcuG036wHsbc9pB1rnWvVke6b3U/5ZvwC+jQXtN4hD1Yu2d/4qVEGHIZ3sXLJcf1Od1qDmRHeU8MeUD+Mdnv7LFdeF07+kYDft9FIQdTplCpaYOOg5LM3m7aY8QrOaMxqSc/9ZUdZV8/mrD/gowld0AYRQgi0AgdJlT57mjoVXkq1iqYm9MR/zrq3238TbHmY0wpy2RT9bCJNMGlqbXA4aU0DL/mjt9lk3dJ2Kv/pdsnnXyF2eT8CNlYGnzI/6s2GiAFL4A4Wt+O/ew22VpP+elWrVOODcB9oZGGSDdaavrQSfXTHIIqUUyA/hO8QxcjqJh/8IL2cPbpl5tWCQ5J0L5uLKTWBWQNKRiJZKhtpd7EsXasctfG0hB5xfk/mR9rZ+M8+ztH4BEHcas3VpgdvQF9ceqeZigOKLG7Lqg8j3paB69/9prjnSZv3YXTMkWMRdyVxb1kdm/DVbtAwG+aQ==
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB1073; 31:XJQH/8c6/xcCzsccXMymU93UUe7NS1h6Dt77vE6n9L321NCkROMOcHSz8DIwlLiXqa1kwJaJ/7W2XXI94vi2NE53BAsSVDc/pV6YFdrMd43sR4N3Xl7uc38XVX1xall62mCkiZOLN9SltyHZqUp8dBRCHU4C4H6beHfqhJINPMO2+Q2GeAUFWmXgqivH4f8plys92Nt1Ooq6n0XejuAJpOCOAuuWPXFO9Cq4OydJVG4=; 20:yGLyKG9gNeVwAaF/2EY7XhgmOi5/nCY7U3fi6KiVoLOrzG+6WICEodBT0m8nxlPgIlWE45MLeJ2YyX9kB/qaVUmqmILg5+NZZODybiadMh93GILP79ksh54TYwOj8ziPWEWMc4aj3glsEROuvz1a3kZ8xuB+IZL6Sg63CG64mrd3QhWPTQrL+0KltnsparrhPBYs+B4hhnfTr+7GSMhWF0KMQi2VNKqsE4j/d8KUl2MEdGh2ZKMyRxQ/ZDtWtJgDq/l7X/hauQzyHyUIx5XTcjWKTwvFTrW4jXtNnd7tVVhSUwANTw16zg/zV2sAxCpx+FapXEy0hkShhjRnY5+vCL0uajQ3s18OLgkN4jQMrH9+5kRWHfZf39Eqy4Mj0eFlmKOtaj9+WW0S0hY3B2N2Ep0MMZXXWa/zRTTydzPa9RnNVeXjIiXLMPDISppsYXCjPrcaaC4XRXED+0/k5ib8K5+Rpjd3i+Q5a6Mh1sMUJjOYwwg4RfzVuJGlRc0zBIIMPiSfTCRfyohmfYiNRxwL0Ma/na19SZ/+0F/2v4UrE/j7KjzPdOIgVLjEwgKShmZvrWkpMSJ1S1CmZOG7CoAuWS64LhRxHu6AeAEpXXuYy38=
X-Microsoft-Antispam-PRVS: <BLUPR0501MB10733AD62EAAC9BA3CB0D393C2370@BLUPR0501MB1073.namprd05.prod.outlook.com>
X-Exchange-Antispam-Report-Test: UriScan:(192374486261705)(138986009662008)(95692535739014); 
X-Exchange-Antispam-Report-CFA-Test: BCL:0; PCL:0; RULEID:(6040450)(601004)(2401047)(8121501046)(5005006)(93006095)(93001095)(3002001)(10201501046)(6055026)(6041248)(201703131423075)(201703011903075)(201702281528075)(201703061421075)(20161123560025)(20161123555025)(20161123564025)(20161123562025)(6072148); SRVR:BLUPR0501MB1073; BCL:0; PCL:0; RULEID:; SRVR:BLUPR0501MB1073; 
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB1073; 4:sidZ47RTXIeUsEaDn5vDh5HTjph0iqgy6fDnPtQ/mVCrJn9DgPkAS/dk3pUfUWocoNWZnbDMLj5cakG/MK6OJvfaMhq3k6WdE9rMAfvMe2BNkZkoKaRWwFogv3AoGXTyqRnUZo+zQJVXFaTOpYIOB8extHsSA5hJrk4AinQqQ3bpTey8GwiCJcRSQFBGCqjlJf2iJRDFR5657bnsCQ8bxaKoFL4FLyOlwzHGXiOlTe/7QNpvjw8vSQVdzU18XyYvgUh950DFyLIdbGlL3qOoQ3eQKYhcPnz4vXbGwmIbsFF8jdxEQurSWXJcWQOw8DdBuG6rm7r42dH2BtHuGKu/JR9+Rgo4Hi4otAxF3QcodWb7EmkrPEFPT4/CkCYtxwl0pKDmztJh1zmr2a62Gk/B0iFfAgtXEcIpcf6pTK9l+nf4N7O+CB/7Yl029YmRX11snQZsXlfuGUWkXOLBOEGYm7VwJWaLeKtaCi46wKbkllHRMxFI3M1kRe8xRz1vk8Ju3qR7VrnBA6y5TowM59chzK5c+OLUF6y2tE51dHdU4ivT7xISy9v9M0fxDtcmZvLQcvQzMkLJ17YVDjLJhUfyCo9juDt26gHi7IPz7TeFUBBvs9Y2T2HINNK8c/nkWyxBH0gOzrHtwVbte86FDrdzPX0bZKYju1fTdvsEHBb3EkcvU1NQwKDkIPuFYf4h1yGphxua9KXZm+1poZuf/DPfFBmo6T/5447SR+ufyZJN1bnPn40Vz4Yfa6PsVOHxRyu5EWVXKJbqb5KwuFTeUNx8yBY3THBtmHyuKIvBXLfdrpcMN/AWvj/Fb9Ek00KmY1JzZIacoZDS/lP5P9q3Zy8bhzR+zoBFdqvzAHb0gvRVD4giRGfoH9VdOtP/jhl4g6pI
X-Forefront-PRVS: 02638D901B
X-Forefront-Antispam-Report: SFV:NSPM; SFS:(10019020)(4630300001)(6009001)(6049001)(39840400002)(39860400002)(39450400003)(39850400002)(39400400002)(39410400002)(377424004)(377454003)(24454002)(189998001)(7110500001)(31686004)(81166006)(4001350100001)(50466002)(2906002)(65826007)(42186005)(53936002)(966004)(66066001)(65806001)(65956001)(36756003)(2420400007)(15188155005)(6666003)(2950100002)(2501003)(5890100001)(8676002)(64126003)(229853002)(83506001)(53546009)(230700001)(3260700006)(25786009)(305945005)(5660300001)(77096006)(6486002)(31696002)(86362001)(4326008)(6306002)(3846002)(6116002)(38730400002)(6246003)(54906002)(54356999)(50986999)(33646002)(47776003)(16799955002)(76176999)(23676002); DIR:OUT; SFP:1102; SCL:1; SRVR:BLUPR0501MB1073; H:[172.29.38.168]; FPR:; SPF:None; MLV:sfv; LANG:en; 
X-Microsoft-Exchange-Diagnostics: =?utf-8?B?MTtCTFVQUjA1MDFNQjEwNzM7MjM6b0U5UVVUZXpENjlUSEtOWnBoUjR4M0RP?= =?utf-8?B?eWU4UkdiMFRLd3dhZFBGQkhwVWtTeVEvcUJlYzk5ME9BTDRHY2l6bGtBVkp1?= =?utf-8?B?cjNsMC9iVkl3dVlKM0FNRzliRDFmWmVUaDNCeFU5Q0JXa0VsYmxFZnF5YmxG?= =?utf-8?B?TnVmWGx5Njd3WUlzSkQ3dmJGNkpsL1ppZlk2cjRxaC9EeXNGOStERXp4eXcv?= =?utf-8?B?K1pycHZ4VGY0eHl5OHcrNklVQ2FyYVRydm0xaGtqS1FSYURmMjlOUDVjYXI3?= =?utf-8?B?elRlL1NqS1QzVnNzTitIcEpKRVJZRis1d0tUOVk2SXp3b0wxSlcyWUFpU3dW?= =?utf-8?B?dVhES2tPWVl2cW4wSWcwRXlDWkV4c3N6ZWJ2OWU0a2NyU29OK28wdExYK01r?= =?utf-8?B?NHJrdlc3Y0YxZTZPNi9vOEpCTkJ4WnN1SDBIV1c3RTd3NFBobE51cUlHaEIx?= =?utf-8?B?cEhTbkcvNlBiRkxQbmxTaE8xZzVRMU51V3c1NzNjVXBCM0RiOExCUHhYeWw2?= =?utf-8?B?ZXlmS1Z2Z1VibWp5MlhBRFdJMWp4RTBaVHZKcWhBcFpaeVdnNTBtenQxcHBa?= =?utf-8?B?TXBqc2xaTmR6TlVabUpQTStzRndWTE9KaWZOaVV0U1psK0lENStJM1Bad1Rp?= =?utf-8?B?S1RKVVBBUXpXdHI5Y2llYjlSdTJ1Vm1yZ2l0WXEvdlpDV05RN1FOc0NtWjQ1?= =?utf-8?B?bFI2R1RidUVlL3k3VDBrV2JWSHJVOFp4U0FLWjFUZUo1L3Fzb3VXLzB4SkVJ?= =?utf-8?B?a1hiK3RQTTAxRTBKT1VveDFHdVFYQ3pUazNyM3JPbWZYNFo5dnhtUWhZdFdu?= =?utf-8?B?TEpCNWpDc3B4VTNvUVp5d0FDa1R6NXhoeThzeUZqT1BnMzA5amlZUXF4bE41?= =?utf-8?B?MDhaMFE4QUhKUWhDdVVqL3k2Nlp0VW5PcXBZT1kxQTB2YldWd2g3U25XWlBp?= =?utf-8?B?M0RuRGNlNm1oNzBRSGxFWEpma2E1bE9sZGtKSlZuVC9oWlFOVm5hYzQrc0s0?= =?utf-8?B?MENGVWg4RFhLeklBUVlEMXpQTmY3ekMwQmFkcHdTYWwwbXowaE1xdG5aODEz?= =?utf-8?B?Mnl6b0lodEhEc2lCV1BJd1ovMjN2NEo4aDZUQlFxQW56TGRUakpuOXJUSmUr?= =?utf-8?B?aVYzT1ZmN0tJT0U0K0hMa0Z5bzdJSXZFd01ZK3Z6SzduNUhnYnpYUnNCOVRM?= =?utf-8?B?aVlyQ0V0dlVxMHlsZGhhUEJXdndqeDBUMzd0OFRtdlNKMFlRbElxU0ZlM3Vl?= =?utf-8?B?S2dQOE82OHZTb2V6OGhBRkxPRXZITHNEUWl6dDJtdUNsSkREc00yZ0U3VXZs?= =?utf-8?B?VjZyc3MrbWkyYTVSRjJITmlUZlMveThIcng1dVp0YXpaYzBGSUx1ajVCd3NF?= =?utf-8?B?dVZMWGRzU1IycHBTNHR5MWNLWTFMT2EvWlFJTXh2bHgwenZ4VmZyYk5oWXlW?= =?utf-8?B?WHV1TTRJTzVMVnpsUnNBTzdiaXNrMnhGUVRjWms0R0dueldlb0NLUlV5Rjcv?= =?utf-8?B?d2R2S2gycVlCS2pBMTU0L1RjMlFmWUJRTk5NcWZrWDBnMVBjd0Z5NVVsUis1?= =?utf-8?B?aHAvRW1nK2RkQzhDMzI0cnBmWXRYQnBtajhaUXJHSk05UlI2V1cydk5kbmk1?= =?utf-8?B?Z2NvSjRTVG01aUJCTzE2U2QzTm03THVzZWc3YTdBeUZyaSs4Sk95MlhnRERL?= =?utf-8?B?aWk3K2dNNzdmYm1ELzhMSHFtcjBjRGVVanpVOFVtRGRKeEZZVm1lRSszYmli?= =?utf-8?B?engxd0FGeUUwWE9ob1ZVd2RkcFYwWldVU01oQWdjOHdpSEpCWk1FUUYvRUVu?= =?utf-8?B?U3ZuZlF5TTJoNTVJTjNRTHpsOXJ5WWEwL09IZ1paUFJneFhiZHE0TkRLSmh0?= =?utf-8?B?c3FHYU9zNEFMWDhsa3NPY0VmaW5DQlpIeU9qakpJdHBJYlZWYVZtMXRmeUNH?= =?utf-8?B?eHdLbmNUV0lzQVoyWWdUVWZqc21sSklGTy9KSVFObDFYYjRaTG9sTzhENzFo?= =?utf-8?B?emsvNVBleW9YbUNuYlVPSWVXRVpEZWx5ejNsVGFLdXFEaUdDNlQvaFBxa29v?= =?utf-8?Q?VMFHHo=3D?=
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB1073; 6:ARSyk8larbngngqpAif46JvEPZ/TcxS0aapHB5af2AZuMwnptkm7ilTYOWQNjq8ixAZBQ1d90ONrtlwzqurnX09rjLdJdVIzebRNVtYXtAtnETW9dyLnTAYY5wT5DeOXvaqH9HcuTS7F9Eux71B9YpCofjpuwluKZORhQvWv2ubpK3V120T7XnZpT3fYqwhmGGDSL/8DObDBdahen5FomIF3zgSIqlse4AandJ92q2HG6GPQOt06GA1OA2fVXI7n71VbMVN9Dw9uOOMMSNcPunKFP9XsBCh/td/CofY55KX+Iu94Ncbc3laCnqOGH8UDe6lyXOAuOwyI1xHzKQCBVnNgaQYbpxM3EIoNyqpTePPv8X2mt/X4u4uQVwt3whM3zPXicSS+O53k80yDt8WYmO9HC9bc2u3bHpqSz9JDN7g=; 5:fazjCJOyIHwpbS6Wb9acIYu8+wOaaGdxXH4k4m/E/7GSrE2AWF7awbDqCL0H6x0WsRTPKkQqdlQrPq8A9oCFX39b7M11OCPxN3G2VrXk5EiPM8BbYOESD8l0TTunIP0fs7qf4l9S5o6yhQxk02Mmug==; 24:Fe4p/bqqhwqiP77H5fKVgLvY0RwTG+txbSQIKZvuxauD36IkPE+sbSUaG7WF57sC7VBp5WSrEK+8wzXrqFiSAtdwL30C1TBCpjMIQAMhlew=
SpamDiagnosticOutput: 1:99
SpamDiagnosticMetadata: NSPM
X-Microsoft-Exchange-Diagnostics: 1; BLUPR0501MB1073; 7:bK5b9MEMy/yvQ26TPVpdLhYrSNH8CUkGn1yz8fLCvj9TSTrWuE+GuTWZ75HRkBDLXc+zXajY7rp9EiLEaYb1xgH4ew6yQXjM+n5rQ0PlvCvoRkBBr6UyL0iKIjpgULq7uAV8kLEZGncVHXgH8zDS763YC9KOSTgHdVkBlK3CW59gcmMe//gBLsBFlH1YQf/rq9sZxUjiN2RWzxeRug5xJDCxFvlDLJJpC4m5ml5uxj2Demx9m/R4cudZdyA0S1njdl+lPKabbYlaJEG47lgSzHyix46DKTqQOo2NlTp0fRVXXN3r6qHbwoDwlzIINgWcmnCYNSzGPN/aBw7lgx59LA==
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 31 Mar 2017 16:58:57.5105 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BLUPR0501MB1073
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsec/vmMx7Gz7z0YenPK-pPIe8VF9y04>
Subject: Re: [OPSEC] [Errata Verified] RFC6192 (4851)
X-BeenThere: opsec@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: opsec wg mailing list <opsec.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsec>, <mailto:opsec-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsec/>
List-Post: <mailto:opsec@ietf.org>
List-Help: <mailto:opsec-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsec>, <mailto:opsec-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 31 Mar 2017 16:59:02 -0000

I agree with Don's concern.  The original intent was to keep all TCP
segments away from port 179 unless the source address is that of a known
BGP peer (3.1. Legitimate Traffic).  The examples listed in the
appendices were meant to provide generalized "do no harm" starting
points.  Additional customization and finer granularity is completely
acceptable as an exercise left to the implementer, as long as the Design
Trade-Offs (3.3) are well understood.

I'm also unsure how s/port/source-port/ in this 'accept' clause on an
input filter helps to defend against a source port 179 SSH intrusion.
The intent of using 'port' was to accept EBGP replies whether the local
router initiated the session (src:179, dst:ephemeral) or the peer
initiated the session (src:ephemeral, dst:179).

---
Dave Dugal
Juniper Networks
PGP Key: 0x879F65CDAB6E02A5
	

On 3/29/2017 4:37 PM, Smith, Donald wrote:
> I think the established will block fins, and resets unless they happen
> to have the ACK bit set too.
> 
> It will block syn only packets too but since this is for ebgp-reply that
> should be ok.
>  
> 
> if (initial_ttl!=255) then (rfc5082_compliant==0)
> Donald.Smith@centurylink.com <mailto:Donald.Smith@centurylink.com>
>
> ------------------------------------------------------------------------
>
> *From:* OPSEC [opsec-bounces@ietf.org] on behalf of RFC Errata System
> [rfc-editor@rfc-editor.org]
> *Sent:* Wednesday, March 29, 2017 12:21 PM
> *To:* hugocanalli@gmail.com; dave@juniper.net; cpignata@cisco.com;
> rodunn@cisco.com
> *Cc:* opsec@ietf.org; iesg@ietf.org; rfc-editor@rfc-editor.org
> *Subject:* [OPSEC] [Errata Verified] RFC6192 (4851)
> 
> The following errata report has been verified for RFC6192,
> "Protecting the Router Control Plane".
> 
> --------------------------------------
> You may review the report below and at:
> http://www.rfc-editor.org/errata_search.php?rfc=6192&eid=4851
> 
> --------------------------------------
> Status: Verified
> Type: Technical
> 
> Reported by: Hugo Leonardo Canalli <hugocanalli@gmail.com>
> Date Reported: 2016-11-01
> Verified by: joel jaeggli (IESG)
> 
> Section: A.2
> 
> Original Text
> -------------
>    term ebgp-reply {
>                    from {
>                        source-prefix-list {
>                            EBGP-NEIGHBORS;
>                        }
>                        protocol tcp;
>                        port bgp;
>                    }
>                    then accept;
>                }
> 
> Corrected Text
> --------------
>    term ebgp-reply {
>                    from {
>                        source-prefix-list {
>                            EBGP-NEIGHBORS;
>                        }
>                        protocol tcp;
>                        tcp-established;
>                        source-port bgp;
>                    }
>                    then accept;
>                }
> 
> 
> 
> Notes
> -----
> There is a security question in that firewall relating to bgp reply.
> Any neighbor that fakes a tcp source port to 179 can access any router
> port, for example, ssh.
> Need to add the line tcp-established. Would also be better to add
> source-port bgp since bgp protocol uses the 179 port to destination. Add
> the fix to all bgps, including ipv6.
> 
> --------------------------------------
> RFC6192 (draft-ietf-opsec-protect-control-plane-06)
> --------------------------------------
> Title               : Protecting the Router Control Plane
> Publication Date    : March 2011
> Author(s)           : D. Dugal, C. Pignataro, R. Dunn
> Category            : INFORMATIONAL
> Source              : Operational Security Capabilities for IP Network
> Infrastructure
> Area                : Operations and Management
> Stream              : IETF
> Verifying Party     : IESG
> 
> _______________________________________________
> OPSEC mailing list
> OPSEC@ietf.org
> https://www.ietf.org/mailman/listinfo/opsec
> 
> 
> This communication is the property of CenturyLink and may contain
> confidential or privileged information. Unauthorized use of this
> communication is strictly prohibited and may be unlawful. If you have
> received this communication in error, please immediately notify the
> sender by reply e-mail and destroy all copies of the communication and
> any attachments.
> 

