[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: draft-ietf-opsec-infrastructure-security-01 - Infrastructure Hiding
On Thu, 26 Apr 2007, Tony Rall wrote:
"Hiding the infrastructure of the network provides one layer of
protection to the devices that make up the network core."
Please reconsider. Not only does this whole section provide no better
than weak protection, it violates numerous suggestions and mandates in
other RFCs.
...
I have stated this before,but I'll have to say I'll agree with a lot
of Tony's comments.
In September 2006 Donald Smith said as follows about this document
after the previous round of comments and discussion why this should
be BCP instead of Informational:
"If its not done as a BCP it will be harder to get some ISPs to
adopt. Some of the features in this draft will prevent your network
elements from becoming reflectors in a dos attack and therefore
general adoption is better for the internet at large."
Which is (IMHO) exactly the backwards logic. "Best Current" practice
should come first, and when it has been deployed wide enough and there
are no obvious bad effects, it shouldn't need the power of 'BCP' to
coerce others to deploy networks in a similar manner.
Further in the thread, people have stated that most of these
techniques have already been deployed in many large provider networks.
Could you please name a couple? I'd like to run traceroute etc.
through them to see if my requirements (as a customer of said transit
operators) for usability are being met or not.
I could imagine that it could be possible to hide some infrastructure
in a manner that doesn't __necessarily__ hurt the users very badly,
but as shown by this thread, the understanding of what infrastructure
hiding means (just iBGP loopback addresses vs everything including
interface addresses as an example) implies that there's likely still
some work to do.
--
Pekka Savola "You each name yourselves king, yet the
Netcore Oy kingdom bleeds."
Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings