[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [BEHAVE] Re: CPE equipments and stateful filters



On Jul 31, 2007, at 18:01, Christian Huitema wrote:

It makes a ton of sense to just leave the IKE port (UDP 500) open.

I agree. I think <draft-ietf-v6ops-cpe-simple-security> says to do this. If it doesn't, then the next revision (coming soon) will say it.

The argument against doing this, which I've heard at least one WG Chairman offer me, is that leaving any port or protocol open to all inbound traffic exposes the interior network to denial of bandwidth attacks (along with potentially draining the batteries of portables in power-save mode).

The more I've thought about that problem, the more I've come to believe that using stateful filtering middleboxes to counter the threat is like responding to the possibility of your house eventually being attacked by a swarm of mosquitos by always keeping your living room filled with carbon monoxide. Yes, you've prevented the mosquitos, but you've also denied yourself access to your living room.

The traditional way you control mosquito populations is with taxpayer- funded pest control services going through the neighborhood, spraying insecticide into all the standing water collectors to keep them from breeding. Something similar to that, I think, is the proper way to engineer an Internet pest control program.

If I ruled the world with an iron fist, operating a zombie-- even unknowingly-- would get your IP dial-tone terminated at your demarcation point, and you'd have to submit to an audit to get it turned back on again. Carriers who didn't do this would see their peering jeopardized, then degraded, and finally dumped, with their contracts thrown into liquidated damages. Failure to police your peering points would be grounds for operators in the DFZ to apply filters, limiters and/or delays on your prefixes in the global routing tables. Operators who didn't like this could complain to their governments, which would then decide whether and how to go to the World Trade Organization.

When the zombie apocalypse hits, I want all the walking dead to be nuked from space. It's the only way to be sure. Alas, I don't rule the world. We'll probably be stuck with a solution much more jackbooted and less effective. Like stateful filtering middleboxes that have to be told to open pinholes for the IKE port.


--
james woodyatt <jhw@apple.com>
member of technical staff, communications engineering