[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [BEHAVE] Re: CPE equipments and stateful filters



On Jul 31, 2007, at 10:46, Dan Wing wrote:
[ I wrote: ]
Neither of these two forms of traffic could reasonably be described as "unsolicited" in this case.

We have different definitions of 'solicited traffic' and 'unsolicited traffic'.

That seems to be the case.

What are your definitions?

I have a more human-centered view of what it means for traffic to be solicited: if a human network administrator is expecting the traffic, then any protocol or method initiated by an administrator for the purpose of enabling an exception to the "denial by default" policy is an explicit solicitation.

For example, an HTTP or SMTP server could solicit inbound connections by sending an NSLP CREATE/EXT message to the appropriate NSIS responder. A more common scenario might be the case where an Apple File Sharing (AFP) protocol server advertises a DNS-SD record with wide-area Bonjour™ and opens an IPv4/NAT translation for it with NAT- PMP.


--
james woodyatt <jhw@apple.com>
member of technical staff, communications engineering