Erik Nordmark wrote:
[...] However, I don't think we need to repeat that the tunnel source address can not
be an address not assigned to the node all over the document.
I agree.
Problem 7: Section 3.6 Decapsulation
Black hole effect, in case one misconfigures the tunnel entrypoint, the tunnel exitpoint, or routing system instability causes source address oscillation.
Node which was misconfigured has no way of finding out it did that. Misconfiguration can happen at any end of the tunnel.
Suggestion: Change third paragraph to:
Packets for which the IPv4 source address does not match MUST be discarded and an ICMP message MUST be generated, with the error code ICMPv4 Protocol 41 Unreachable.
I haven't read the followup emails on the list yet, but if this is essentially a form of source address filtering, the fact is that for ingress filtering there is no error message. So a MUST is definitely too strong - there are good reasons for not sending any error. A MAY might be appropriate [I have to read the rest of the messages on the list.]
Sending protocol 41 unreachable seems like a likely source of confusion though so we shouldn't overload that.
Erik
Regards, Alex
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature