
From Internet-Drafts@ietf.org  Fri Feb 11 23:30:04 2011
Return-Path: <Internet-Drafts@ietf.org>
X-Original-To: savi@core3.amsl.com
Delivered-To: savi@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 970143A6898; Fri, 11 Feb 2011 23:30:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.532
X-Spam-Level: 
X-Spam-Status: No, score=-102.532 tagged_above=-999 required=5 tests=[AWL=0.067, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kJII8vbCxmHW; Fri, 11 Feb 2011 23:30:01 -0800 (PST)
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 9B7F93A6894; Fri, 11 Feb 2011 23:30:01 -0800 (PST)
MIME-Version: 1.0
Content-Type: Multipart/Mixed; Boundary="NextPart"
From: Internet-Drafts@ietf.org
To: i-d-announce@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 3.12
Message-ID: <20110212073001.31766.7653.idtracker@localhost>
Date: Fri, 11 Feb 2011 23:30:01 -0800
Cc: savi@ietf.org
Subject: [savi] I-D Action:draft-ietf-savi-framework-02.txt
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 12 Feb 2011 07:30:04 -0000

--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Source Address Validation Improvements Working Group of the IETF.


	Title           : Source Address Validation Improvement Framework
	Author(s)       : J. Wu, et al.
	Filename        : draft-ietf-savi-framework-02.txt
	Pages           : 12
	Date            : 2011-02-11

The Source Address Validation Improvement method was developed to
complement ingress filtering with finer-grained, standardized IP
source address validation.  This document describes and motivates the
design of the SAVI method.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-savi-framework-02.txt

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Message/External-body; name="draft-ietf-savi-framework-02.txt";
	site="ftp.ietf.org"; access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID: <2011-02-11231924.I-D@ietf.org>


--NextPart--

From jeanmichel.combes@gmail.com  Wed Feb 16 00:53:40 2011
Return-Path: <jeanmichel.combes@gmail.com>
X-Original-To: savi@core3.amsl.com
Delivered-To: savi@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 888123A6DEB for <savi@core3.amsl.com>; Wed, 16 Feb 2011 00:53:40 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BpXOGQEmS-ab for <savi@core3.amsl.com>; Wed, 16 Feb 2011 00:53:39 -0800 (PST)
Received: from mail-wy0-f172.google.com (mail-wy0-f172.google.com [74.125.82.172]) by core3.amsl.com (Postfix) with ESMTP id 9707C3A6ABA for <savi@ietf.org>; Wed, 16 Feb 2011 00:53:39 -0800 (PST)
Received: by wyf23 with SMTP id 23so1166943wyf.31 for <savi@ietf.org>; Wed, 16 Feb 2011 00:54:06 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:date:message-id:subject:from:to:cc :content-type; bh=kMuGCkzGrIjyvMKLttUXl0/1N+zUKyy1YyNywnzEXk4=; b=BkPzGXlLkLxs3c7KXqAjX8/xMtDSmvJl/Ow1Z7kzFZBNeaOJWZ8e3RqPrQ0vtJ1ilh ZPpyo95wnc6P9x3XjNg/6BIEEh+Oj+KwpfcUhm4BcnUxLuliTzOaFIRGkW/jkPq6iUxo WLbmgoMnmOMSL3+U7aHEy2sLqTvyswRlwQmL0=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:cc:content-type; b=v26kJ2TACfmjsaGoNHG4Z4iWp+s/BZprDZFrJylhruYNlrQ48WSmcMVviP3iVm4s8q ly0DIR6NnjcZx6JstGtgyvm2Hx/b05BPtpwBL1ovGUUUHzF7T5xzeZ/s73mUIbly58iR HLq56vzTlrvaQdyH5DA34t9y/EvWHbkdMzVnU=
MIME-Version: 1.0
Received: by 10.216.89.204 with SMTP id c54mr247401wef.109.1297846446474; Wed, 16 Feb 2011 00:54:06 -0800 (PST)
Received: by 10.216.239.69 with HTTP; Wed, 16 Feb 2011 00:54:06 -0800 (PST)
Date: Wed, 16 Feb 2011 09:54:06 +0100
Message-ID: <AANLkTi=OXeHzUb_DAxh2+jTuJPysLt5Qei+mAJb_x6UV@mail.gmail.com>
From: Jean-Michel Combes <jeanmichel.combes@gmail.com>
To: SAVI Mailing List <savi@ietf.org>
Content-Type: text/plain; charset=ISO-8859-1
Cc: Christian Vogt <christian.vogt@ericsson.com>
Subject: [savi] WGLC: draft-ietf-savi-framework-02
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 16 Feb 2011 08:53:40 -0000

Folks,

This is a 2 weeks working group last call for the "Source Address
Validation Improvement Framework" document.
Please, don't hesitate to review the draft and to say whether you are
in favor advancing the draft or not.

Thanks.

Christian & Jean-Michel.

From jeanmichel.combes@gmail.com  Fri Feb 25 09:15:15 2011
Return-Path: <jeanmichel.combes@gmail.com>
X-Original-To: savi@core3.amsl.com
Delivered-To: savi@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 7795F3A6950 for <savi@core3.amsl.com>; Fri, 25 Feb 2011 09:15:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.599
X-Spam-Level: 
X-Spam-Status: No, score=-103.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YMC1XUzpznKW for <savi@core3.amsl.com>; Fri, 25 Feb 2011 09:15:14 -0800 (PST)
Received: from mail-ww0-f44.google.com (mail-ww0-f44.google.com [74.125.82.44]) by core3.amsl.com (Postfix) with ESMTP id 7A8303A68B1 for <savi@ietf.org>; Fri, 25 Feb 2011 09:15:14 -0800 (PST)
Received: by wwb22 with SMTP id 22so485894wwb.13 for <savi@ietf.org>; Fri, 25 Feb 2011 09:16:06 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=9RZDVa0GPPQdI8iMb2EkzUiok2JjGWZG1MKhr8SkflE=; b=fwl464YDC0pvy9U0lw03Tw6O9lgyXV4yWneVVuKK/1LSEvz+Ks/01IbnO0p9StzMJI k0HhtU78q5b0SGX0ZbeQ72Mi6UmMW/WhSJ/MhjVAqbCbwjX8Ntpfgqp/lROLAimC9/Ik ySBa9KS+53twiJr/F9FMMD65xBurxaY25ElHA=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=bLLSnZ+T6FJcrJCXoiE6ibfPDla3rMr9pmUC31s0XEvmH9wPvsquY0DxAe38eI6CWR bkN0pe2WehPyflVzB4iQnbIB7JhZEie9fEbfJRjtLZROw44L+/FIXF4zrAofFU94OgcL lDxxCFI2oJwhvsRPaYe0wubQVxLU32Pk2YzxU=
MIME-Version: 1.0
Received: by 10.216.173.147 with SMTP id v19mr2431274wel.102.1298654166139; Fri, 25 Feb 2011 09:16:06 -0800 (PST)
Received: by 10.216.64.130 with HTTP; Fri, 25 Feb 2011 09:16:06 -0800 (PST)
In-Reply-To: <AANLkTi=OXeHzUb_DAxh2+jTuJPysLt5Qei+mAJb_x6UV@mail.gmail.com>
References: <AANLkTi=OXeHzUb_DAxh2+jTuJPysLt5Qei+mAJb_x6UV@mail.gmail.com>
Date: Fri, 25 Feb 2011 18:16:06 +0100
Message-ID: <AANLkTim=zsNG6_DR_m_u0sz5ySC75bGKwbyytXwzZsaE@mail.gmail.com>
From: Jean-Michel Combes <jeanmichel.combes@gmail.com>
To: SAVI Mailing List <savi@ietf.org>
Content-Type: text/plain; charset=ISO-8859-1
Cc: Christian Vogt <christian.vogt@ericsson.com>
Subject: Re: [savi] WGLC: draft-ietf-savi-framework-02
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 25 Feb 2011 17:15:15 -0000

Folks,

only 4 days before the end of this WGLC and no feedback for the moment ...

This document is important for the WG:
- all solutions will have to be compliant with it
- without feedback, it will be impossible to move forward it (i.e. AD
review, IESG review)
- the consequence is that it will be impossible to move forward the
solutions specs

So, please, review it (it's a short document, only 12 pages) and send
your opinion on the ML.

Thanks.

Christian & Jean-Michel.



2011/2/16 Jean-Michel Combes <jeanmichel.combes@gmail.com>:
> Folks,
>
> This is a 2 weeks working group last call for the "Source Address
> Validation Improvement Framework" document.
> Please, don't hesitate to review the draft and to say whether you are
> in favor advancing the draft or not.
>
> Thanks.
>
> Christian & Jean-Michel.
>

From xiayangsong@huawei.com  Fri Feb 25 15:52:12 2011
Return-Path: <xiayangsong@huawei.com>
X-Original-To: savi@core3.amsl.com
Delivered-To: savi@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 26D723A6A7A for <savi@core3.amsl.com>; Fri, 25 Feb 2011 15:52:12 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.495
X-Spam-Level: 
X-Spam-Status: No, score=-0.495 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FH_RELAY_NODNS=1.451, HELO_MISMATCH_COM=0.553,  RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zA8TOd0kmVTO for <savi@core3.amsl.com>; Fri, 25 Feb 2011 15:52:10 -0800 (PST)
Received: from szxga01-in.huawei.com (unknown [119.145.14.64]) by core3.amsl.com (Postfix) with ESMTP id 999123A6A78 for <savi@ietf.org>; Fri, 25 Feb 2011 15:52:09 -0800 (PST)
Received: from huawei.com (szxga05-in [172.24.2.49]) by szxga05-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTP id <0LH700H4T6C47T@szxga05-in.huawei.com> for savi@ietf.org; Sat, 26 Feb 2011 07:52:52 +0800 (CST)
Received: from huawei.com ([172.24.2.119]) by szxga05-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTP id <0LH700N4J6C328@szxga05-in.huawei.com> for savi@ietf.org; Sat, 26 Feb 2011 07:52:52 +0800 (CST)
Received: from X24512z ([10.193.34.89]) by szxml06-in.huawei.com (iPlanet Messaging Server 5.2 HotFix 2.14 (built Aug 8 2006)) with ESMTPA id <0LH7007HK6BUHX@szxml06-in.huawei.com> for savi@ietf.org; Sat, 26 Feb 2011 07:52:51 +0800 (CST)
Date: Fri, 25 Feb 2011 15:52:42 -0800
From: Frank Xia <xiayangsong@huawei.com>
In-reply-to: <AANLkTim=zsNG6_DR_m_u0sz5ySC75bGKwbyytXwzZsaE@mail.gmail.com>
To: 'Jean-Michel Combes' <jeanmichel.combes@gmail.com>, 'SAVI Mailing List' <savi@ietf.org>
Message-id: <001401cbd547$18b7e3d0$5922c10a@china.huawei.com>
MIME-version: 1.0
X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.3350
X-Mailer: Microsoft Office Outlook 11
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Thread-index: AcvVD7W16JfC44ehSHOPmKsZU/hR+wANglYg
References: <AANLkTi=OXeHzUb_DAxh2+jTuJPysLt5Qei+mAJb_x6UV@mail.gmail.com> <AANLkTim=zsNG6_DR_m_u0sz5ySC75bGKwbyytXwzZsaE@mail.gmail.com>
Cc: 'Christian Vogt' <christian.vogt@ericsson.com>
Subject: Re: [savi] WGLC: draft-ietf-savi-framework-02
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 25 Feb 2011 23:52:12 -0000

Hi Guys

I support this draft to advance.

At the same time, I am not sure if these scenarios are covered :
1)A legacy switch to which hosts are attaching uses two trunked ports
  to connect to SAVI switch.
2)STP runs among switches, and a link failure happens.

BR
Frank

-----Original Message-----
From: savi-bounces@ietf.org [mailto:savi-bounces@ietf.org] On Behalf Of
Jean-Michel Combes
Sent: Friday, February 25, 2011 9:16 AM
To: SAVI Mailing List
Cc: Christian Vogt
Subject: Re: [savi] WGLC: draft-ietf-savi-framework-02

Folks,

only 4 days before the end of this WGLC and no feedback for the moment ...

This document is important for the WG:
- all solutions will have to be compliant with it
- without feedback, it will be impossible to move forward it (i.e. AD
review, IESG review)
- the consequence is that it will be impossible to move forward the
solutions specs

So, please, review it (it's a short document, only 12 pages) and send
your opinion on the ML.

Thanks.

Christian & Jean-Michel.



2011/2/16 Jean-Michel Combes <jeanmichel.combes@gmail.com>:
> Folks,
>
> This is a 2 weeks working group last call for the "Source Address
> Validation Improvement Framework" document.
> Please, don't hesitate to review the draft and to say whether you are
> in favor advancing the draft or not.
>
> Thanks.
>
> Christian & Jean-Michel.
>
_______________________________________________
savi mailing list
savi@ietf.org
https://www.ietf.org/mailman/listinfo/savi



From jeanmichel.combes@gmail.com  Mon Feb 28 01:24:34 2011
Return-Path: <jeanmichel.combes@gmail.com>
X-Original-To: savi@core3.amsl.com
Delivered-To: savi@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 4BC833A6AE6 for <savi@core3.amsl.com>; Mon, 28 Feb 2011 01:24:34 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -99.782
X-Spam-Level: 
X-Spam-Status: No, score=-99.782 tagged_above=-999 required=5 tests=[AWL=-3.817, BAYES_00=-2.599, CHARSET_FARAWAY_HEADER=3.2, CN_BODY_35=0.339, MIME_8BIT_HEADER=0.3, MIME_CHARSET_FARAWAY=2.45, RCVD_IN_DNSWL_LOW=-1, SARE_SUB_ENC_GB2312=1.345, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wTVfwBUZts8G for <savi@core3.amsl.com>; Mon, 28 Feb 2011 01:24:33 -0800 (PST)
Received: from mail-ww0-f44.google.com (mail-ww0-f44.google.com [74.125.82.44]) by core3.amsl.com (Postfix) with ESMTP id 4B8153A6908 for <savi@ietf.org>; Mon, 28 Feb 2011 01:24:33 -0800 (PST)
Received: by wwb22 with SMTP id 22so2168858wwb.13 for <savi@ietf.org>; Mon, 28 Feb 2011 01:25:32 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:in-reply-to:references:date :message-id:subject:from:to:content-type:content-transfer-encoding; bh=DVbya4vtB0vE9Yyn6GUvUb/2S23KfZjoSVoLnrjbKfA=; b=j/JC/c4gKSdxfOeWSf7YYljNmKuCPWhV5lfrVYSjctwTO526GxxE1q9wRZ+HavNlxv EHKC7mcDiFnFVRsPJW9Y+eZ0uB3rW6VaOjA3M2+rl45cTX7wGSqHtIN1hy4QM7J1x9BV EfAteoZI0YnO2+a0H7Q6nNzFgsAmrp5oCz9DY=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type:content-transfer-encoding; b=rHMAD7GAJpFEHw/IxLc5OXpiYNy+O2+Y+F1Iji2kOvuKSNrnmbWeqJjWUI+Ryd73na 7Eo4EZLTy3iecy9mY922QfYzrWxx0Or+jZgxZ0lXE1TC04R2K09ZHPma0DBT5y0Y5YSn NaQ/PL0R3/sHNOxTuO0Op2H/DaDU9xmBFSjls=
MIME-Version: 1.0
Received: by 10.216.165.204 with SMTP id e54mr4939723wel.48.1298885131392; Mon, 28 Feb 2011 01:25:31 -0800 (PST)
Received: by 10.216.64.130 with HTTP; Mon, 28 Feb 2011 01:25:31 -0800 (PST)
In-Reply-To: <20110226080849.4D24736FCD2@mail3-113.sinamail.sina.com.cn>
References: <20110226080849.4D24736FCD2@mail3-113.sinamail.sina.com.cn>
Date: Mon, 28 Feb 2011 10:25:31 +0100
Message-ID: <AANLkTikf5Hb6ANxTj3AU648XJzb3TY0AxJwSBVT_+roD@mail.gmail.com>
From: Jean-Michel Combes <jeanmichel.combes@gmail.com>
To: SAVI Mailing List <savi@ietf.org>
Content-Type: text/plain; charset=GB2312
Content-Transfer-Encoding: quoted-printable
Subject: [savi] =?gb2312?b?RndkOiC72Li0o7pGdzogIFdHTEM6IGRyYWZ0LWlldGYt?= =?gb2312?b?c2F2aS1mcmFtZXdvcmstMDI=?=
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 28 Feb 2011 09:24:34 -0000

FYI.

JMC.

---------- Forwarded message ----------
From:  <lintao850711@sina.com>
Date: 2011/2/26
Subject: =BB=D8=B8=B4=A3=BAFw: [savi] WGLC: draft-ietf-savi-framework-02
To: jeanmichel.combes@gmail.com
Cc : Jun Bi <junbi@tsinghua.edu.cn>


This draft is ok.

-----=D4=AD=CA=BC=D3=CA=BC=FE-----
From: Jean-Michel Combes
Sent: Saturday, February 26, 2011 1:16 AM
To: SAVI Mailing List
Cc: Christian Vogt
Subject: Re: [savi] WGLC: draft-ietf-savi-framework-02

Folks,

only 4 days before the end of this WGLC and no feedback for the moment ...

This document is important for the WG:
- all solutions will have to be compliant with it
- without feedback, it will be impossible to move forward it (i.e. AD
review, IESG review)
- the consequence is that it will be impossible to move forward the
solutions specs

So, please, review it (it's a short document, only 12 pages) and send
your opinion on the ML.

Thanks.

Christian & Jean-Michel.



2011/2/16 Jean-Michel Combes <jeanmichel.combes@gmail.com>:
> Folks,
>
> This is a 2 weeks working group last call for the "Source Address
> Validation Improvement Framework" document.
> Please, don't hesitate to review the draft and to say whether you are
> in favor advancing the draft or not.
>
> Thanks.
>
> Christian & Jean-Michel.
>
_______________________________________________
savi mailing list
savi@ietf.org
https://www.ietf.org/mailman/listinfo/savi

From swmike@swm.pp.se  Mon Feb 28 06:10:04 2011
Return-Path: <swmike@swm.pp.se>
X-Original-To: savi@core3.amsl.com
Delivered-To: savi@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 9AD9A3A6BF4 for <savi@core3.amsl.com>; Mon, 28 Feb 2011 06:10:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[AWL=0.000,  BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9lWMfvmrqUME for <savi@core3.amsl.com>; Mon, 28 Feb 2011 06:10:03 -0800 (PST)
Received: from uplift.swm.pp.se (ipv6.swm.pp.se [IPv6:2a00:801::f]) by core3.amsl.com (Postfix) with ESMTP id 9B2283A6BF6 for <savi@ietf.org>; Mon, 28 Feb 2011 06:10:03 -0800 (PST)
Received: by uplift.swm.pp.se (Postfix, from userid 501) id 7066E9E; Mon, 28 Feb 2011 15:11:00 +0100 (CET)
Received: from localhost (localhost [127.0.0.1]) by uplift.swm.pp.se (Postfix) with ESMTP id 6FDB09C; Mon, 28 Feb 2011 15:11:00 +0100 (CET)
Date: Mon, 28 Feb 2011 15:11:00 +0100 (CET)
From: Mikael Abrahamsson <swmike@swm.pp.se>
To: Jean-Michel Combes <jeanmichel.combes@gmail.com>
In-Reply-To: <AANLkTi=OXeHzUb_DAxh2+jTuJPysLt5Qei+mAJb_x6UV@mail.gmail.com>
Message-ID: <alpine.DEB.1.10.1102281507400.11974@uplift.swm.pp.se>
References: <AANLkTi=OXeHzUb_DAxh2+jTuJPysLt5Qei+mAJb_x6UV@mail.gmail.com>
User-Agent: Alpine 1.10 (DEB 962 2008-03-14)
Organization: People's Front Against WWW
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed
Cc: SAVI Mailing List <savi@ietf.org>, Christian Vogt <christian.vogt@ericsson.com>
Subject: Re: [savi] WGLC: draft-ietf-savi-framework-02
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 28 Feb 2011 14:10:04 -0000

On Wed, 16 Feb 2011, Jean-Michel Combes wrote:

I have read the draft and found it sensible and I would like to voice my 
support for it.

I would be more comfortable if it stated more explicitly that the IP/mac 
binding is important, but I felt that it was at least implicit that this 
was the ultimate goal.

For instance, I think it's important that on a port where DHCP(v6) is 
specified to be mandatory, no traffic should be allowed from an IP/mac 
that doesn't correspond to something that has been handed out by stateful 
DHCP. I hope this is implicit, but if it's expressly stated in the 
document, I missed it.

> Folks,
>
> This is a 2 weeks working group last call for the "Source Address
> Validation Improvement Framework" document.
> Please, don't hesitate to review the draft and to say whether you are
> in favor advancing the draft or not.
>
> Thanks.
>
> Christian & Jean-Michel.
> _______________________________________________
> savi mailing list
> savi@ietf.org
> https://www.ietf.org/mailman/listinfo/savi
>

-- 
Mikael Abrahamsson    email: swmike@swm.pp.se

From jeanmichel.combes@gmail.com  Mon Feb 28 06:12:31 2011
Return-Path: <jeanmichel.combes@gmail.com>
X-Original-To: savi@core3.amsl.com
Delivered-To: savi@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 193933A6A06 for <savi@core3.amsl.com>; Mon, 28 Feb 2011 06:12:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.327
X-Spam-Level: 
X-Spam-Status: No, score=-102.327 tagged_above=-999 required=5 tests=[AWL=1.272, BAYES_00=-2.599, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fQ49RBradWDj for <savi@core3.amsl.com>; Mon, 28 Feb 2011 06:12:29 -0800 (PST)
Received: from mail-ww0-f44.google.com (mail-ww0-f44.google.com [74.125.82.44]) by core3.amsl.com (Postfix) with ESMTP id 479F03A6BF4 for <savi@ietf.org>; Mon, 28 Feb 2011 06:12:29 -0800 (PST)
Received: by wwb22 with SMTP id 22so2369575wwb.13 for <savi@ietf.org>; Mon, 28 Feb 2011 06:13:29 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=SWXstiXyMXKdYXnv/wINaaAb1BsSRHVp7yRETcRPyi0=; b=tZpsaMOFxRUvMUUBn4W1a+bHXVUeny/s6c7AmsnVdVao7hNYIjBxqGusnajKuw9mNl QDhsHAX1xznZ1mua9nPoZrjILGWrUCU7XL4zlC2QgiJ9soD56mv+kks0sE9T5gXXmfGr cvsau5zUX3QKFJ4vcVLqdGOKye4bBTeZyodyk=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=Ve/fRmVbJsR9qP8MlmK9WYPIhc2N1oRDI9+bOpBsO4fZ5AFaMkCb/pvB5lVEd4lopv ne0lhWXP5l6e7WmHgQxhsEN8Kga40D4zYZO18TH6iJ3iJbf1CSCSdzeewdSbhsuoTwJ0 ovKBnbQI87Kc4i7UCaXGYtJeuRNEwXylD1b3E=
MIME-Version: 1.0
Received: by 10.216.20.141 with SMTP id p13mr2434872wep.102.1298902408604; Mon, 28 Feb 2011 06:13:28 -0800 (PST)
Received: by 10.216.64.130 with HTTP; Mon, 28 Feb 2011 06:13:28 -0800 (PST)
In-Reply-To: <AANLkTim=zsNG6_DR_m_u0sz5ySC75bGKwbyytXwzZsaE@mail.gmail.com>
References: <AANLkTi=OXeHzUb_DAxh2+jTuJPysLt5Qei+mAJb_x6UV@mail.gmail.com> <AANLkTim=zsNG6_DR_m_u0sz5ySC75bGKwbyytXwzZsaE@mail.gmail.com>
Date: Mon, 28 Feb 2011 15:13:28 +0100
Message-ID: <AANLkTikowzH7mEfRJbaDLyfYp=_VTj2fPTJH_pKyTwvV@mail.gmail.com>
From: Jean-Michel Combes <jeanmichel.combes@gmail.com>
To: SAVI Mailing List <savi@ietf.org>
Content-Type: text/plain; charset=ISO-8859-1
Cc: Christian Vogt <christian.vogt@ericsson.com>
Subject: Re: [savi] WGLC: draft-ietf-savi-framework-02
X-BeenThere: savi@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: Mailing list for the SAVI working group at IETF <savi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/savi>
List-Post: <mailto:savi@ietf.org>
List-Help: <mailto:savi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/savi>, <mailto:savi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 28 Feb 2011 14:12:31 -0000

<WG chair hat off>

Please find my review of this draft below (my comments are mostly
minor/editorial ones):


            Source Address Validation Improvement Framework
                      draft-ietf-savi-framework-02

Abstract

   The Source Address Validation Improvement method was developed to
   complement ingress filtering with finer-grained, standardized IP
   source address validation.  This document describes and motivates the
   design of the SAVI method.

[snip]

1.  Introduction

   Since IP source addresses are used by hosts and network entities to
   determine the origin of a packet and as a destination for return
   data, spoofing of IP source addresses can enable impersonation,
   concealment, and malicious traffic redirection.  Unfortunately, the
   Internet architecture does not prevent IP source address spoofing.

<JMC>
Maybe, add a reference to the treats doc
[draft-ietf-savi-threat-scope] at the end of the sentence.
<JMC>

   Since the IP source address of a packet generally takes no role in
   forwarding the packet, it can be selected arbitrarily by the sending
   host without jeopardizing packet delivery.  Extra methods are
   necessary for IP source address validation, to augment packet
   forwarding with an explicit check of whether a given packet's IP
   source address is legitimate.

   IP source address validation can happen at different granularity:
   Ingress filtering [BCP38], a widely deployed standard for IP source
   address validation, functions at the coarse granularity of networks.
   It verifies that the prefix of an IP source address routes to the
   network from which the packet was received.  An advantage of ingress
   filtering is simplicity:  The decision of whether to accept or to

<JMC>
s/"is simplicity:  The decision of"/"is simplicity:  the decision of"
<JMC>

   reject an IP source address can be made solely based on the
   information available from routing protocols.  However, the

<JMC>
"information available from routing protocols": maybe add a reference to RFC3704
<JMC>

   simplicity comes at the cost of not being able to validate IP source
   addresses at a finer granularity, due to the aggregated nature of the
   information available from routing protocols.  Finer-grained IP
   source address validation would be helpful to enable IP-source-
   address-based authentication, authorization, and host localization,
   as well as to efficiently identify misbehaving hosts.  Partial
   solutions [BA2007] exist for finer-grained IP source address
   validation, but are proprietary and hence often unsuitable for
   corporate procurement.

[snip]

3.1.  IP Address Assignment Methods

   Since the SAVI method traces IP address assignment packets, it
   necessarily needs to incorporate logic that is specific to particular
   IP address assignment methods.  However, developing SAVI method
   variants for each IP address assignment method is alone not
   sufficient, since multiple IP address assignment methods may co-exist
   on a given link.  The SAVI method hence comes in multiple variants:
   for links with Stateless Address Autoconfiguration, for links with
   DHCP, for links with Secure Neighbor Discovery, and for links that
   use any combination of IP address assignment methods.

<JMC>
Maybe add a reference for each IP address assignment method.
Maybe, even if this is out of scope from the WG charter, add IKEv2
[RFC5996][RFC5739] as IP address assignment method. I have especially
in mind Mobile Node's Home Address assignment based on IKEv2
[RFC5026].
<JMC>

   The reason to develop SAVI method variants for each single IP address
   configuration method, in addition to the variant that handles all IP
   address assignment methods, is to minimize the complexity of the
   common case:  Many link deployments today either are constrained to a

<JMC>
s/"common case:  Many link deployments"/"common case:  many link deployments"
<JMC>

   single IP address assignment methods or, equivalently from the
   perspective of the SAVI method, separate IP address assignment
   methods into different IP address prefixes.  The SAVI method for such
   links can be simpler than the SAVI method for links with multiple IP
   address assignment methods per IP address prefix.



[snip]


4.  Scalability Optimizations

   The preference to locate a SAVI instance close to hosts implies that
   multiple SAVI instances must be able to co-exist in order to support
   large links.  Although the model of the SAVI method is independent of
   the number of SAVI instances per link, co-existence of multiple SAVI
   instances without further measures can lead to higher-than-necessary
   memory requirements:  Since a SAVI instance creates bindings for the

<JMC>
s/"memory requirements:  Since a SAVI instance creates"/"memory
requirements:  since a SAVI instance creates"
<JMC>

   IP source addresses of all hosts on a link, bindings are replicated
   if multiple SAVI instances co-exist on the link.  High memory
   requirements, in turn, increase the cost of a SAVI instance.  This is
   problematic in particular for SAVI instances that are located on a
   switch, since it may significantly increase the cost of such a
   switch.

[snip]

   In the example of figure Figure 1, the protection perimeter
   encompasses one of the legacy switches, located in the middle of the
   depicted link topology.  This enables a single, unpartitioned
   protection perimeter.  A single protection perimeter minimizes memory
   requirements for the SAVI instances because every binding is kept
   only once, namely, by the SAVI instance that attaches to the host
   being validated.  Excluding the legacy switch from the protection
   perimeter would result in two smaller protection perimeters to the
   left and to the right of the depicted link topology.  The memory
   requirements for the SAVI instances would then be higher:  Since IP

<JMC>
s/"then be higher:  Since IP"/"then be higher:  since IP"
<JMC>

   source address validation would be activated on the two ports
   connecting to the legacy switch, the SAVI instances adjacent to the
   legacy switch would replicate all bindings from the respectively
   other protection perimeter.  The reason why it is possible to include
   the legacy switch in the protection perimeter is because the depicted
   link topology guarantees that packets cannot enter the protection
   perimeter via this legacy switch.  Without this guarantee, the legacy
   switch would have to be excluded from the protection perimeter in
   order to ensure that packets entering the protection perimeter
   undergo IP source address validation.


5.  Reliability Optimizations

[snip]

   To limit the disruption that missing bindings for legitimate IP
   addresses can have, the SAVI method includes a mechanism for reactive
   binding creation based on regular packets.  This mechanism
   supplements the proactive binding creation based on IP address
   configuration packets.  Reactive binding creation occurs when a SAVI
   instances recognizes excessive drops of regular packets originating
   from the same IP address.  The SAVI instance then verifies whether
   said IP address is unique on the link.  How the verification is
   carried out depends on the IP address configuration method that the
   SAVI instance supports:  The SAVI method variant for Stateless

<JMC>
s/"SAVI instance supports:  The SAVI method variant"/"SAVI instance
supports.  The SAVI method variant"
<JMC>

   Address Autoconfiguration and for Secure Neighbor Discovery verifies
   an IP address through the Duplicate Address Detection procedure.  The
   SAVI method variant for DHCP verifies an IP address through a DHCP
   Lease Query message exchange with the DHCP server.  If verification
   indicates that the IP address is unique on the link, the SAVI
   instance creates a binding for the IP address.  Otherwise, no binding
   is created, and packets sent from the IP address continue to be
   dropped.


6.  Mix Scenario

   While multiple assignment methods can be used on the same link, the
   SAVI device may have to deal with a mix of binding discovery methods.
   if the address prefix used for each assignment method is different,

<JMC>
s/"if the address prefix used for each assignment method"/"If the
address prefix used for each assignment method"
<JMC>

   mix scenario can handle the same as scenario with only one assignment
   method.  If different address assignment methods are used to assign
   addresses from the same prefix, additional considerations are needed
   because one binding mechanism may create a binding violating an
   existing binding from another binding mechanism, e.g., binding from
   SAVI-FCFS may violate binding from SAVI-DHCP.  Thus, the collision

<JMC>
Maybe, add references for SAVI-FCFS and SAVI-DHCP.
<JMC>

   between different SAVI mechanisms in mix scenario must be handled in
   case more than one address assignment method is used to assign
   addresses from the same prefix.

[snip]

<JMC>
A Security Considerations section is missing.
An IANA Considerations section is missing too.
<JMC>


[snip]


8.  References

<JMC>
The References section must be split into an Informative References
section and a Normative References section.
<JMC>

   [BA2007]  Baker, F., "Cisco IP Version 4 Source Guard", IETF Internet
             draft (work in progress), November 2007.

   [BCP38]   Paul, P. and D. Senie, "Network Ingress Filtering:
             Defeating Denial of Service Attacks which employ IP Source
             Address Spoofing", RFC 2827, BCP 38, May 2000.

[snip]


Best regards.

JMC.


2011/2/25 Jean-Michel Combes <jeanmichel.combes@gmail.com>:
> Folks,
>
> only 4 days before the end of this WGLC and no feedback for the moment ...
>
> This document is important for the WG:
> - all solutions will have to be compliant with it
> - without feedback, it will be impossible to move forward it (i.e. AD
> review, IESG review)
> - the consequence is that it will be impossible to move forward the
> solutions specs
>
> So, please, review it (it's a short document, only 12 pages) and send
> your opinion on the ML.
>
> Thanks.
>
> Christian & Jean-Michel.
>
>
>
> 2011/2/16 Jean-Michel Combes <jeanmichel.combes@gmail.com>:
>> Folks,
>>
>> This is a 2 weeks working group last call for the "Source Address
>> Validation Improvement Framework" document.
>> Please, don't hesitate to review the draft and to say whether you are
>> in favor advancing the draft or not.
>>
>> Thanks.
>>
>> Christian & Jean-Michel.
>>
>
