[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [BEHAVE] Re: CPE equipments and stateful filters



On Jul 31, 2007, at 18:01, Christian Huitema wrote:
It makes a ton of sense to just leave the IKE port (UDP 500) open.
I agree.  I think <draft-ietf-v6ops-cpe-simple-security> says to do  
this.  If it doesn't, then the next revision (coming soon) will say it.
The argument against doing this, which I've heard at least one WG  
Chairman offer me, is that leaving any port or protocol open to all  
inbound traffic exposes the interior network to denial of bandwidth  
attacks (along with potentially draining the batteries of portables  
in power-save mode).
The more I've thought about that problem, the more I've come to  
believe that using stateful filtering middleboxes to counter the  
threat is like responding to the possibility of your house eventually  
being attacked by a swarm of mosquitos by always keeping your living  
room filled with carbon monoxide.  Yes, you've prevented the  
mosquitos, but you've also denied yourself access to your living room.
The traditional way you control mosquito populations is with taxpayer- 
funded pest control services going through the neighborhood, spraying  
insecticide into all the standing water collectors to keep them from  
breeding.  Something similar to that, I think, is the proper way to  
engineer an Internet pest control program.
If I ruled the world with an iron fist, operating a zombie-- even  
unknowingly-- would get your IP dial-tone terminated at your  
demarcation point, and you'd have to submit to an audit to get it  
turned back on again.  Carriers who didn't do this would see their  
peering jeopardized, then degraded, and finally dumped, with their  
contracts thrown into liquidated damages.  Failure to police your  
peering points would be grounds for operators in the DFZ to apply  
filters, limiters and/or delays on your prefixes in the global  
routing tables.  Operators who didn't like this could complain to  
their governments, which would then decide whether and how to go to  
the World Trade Organization.
When the zombie apocalypse hits, I want all the walking dead to be  
nuked from space.  It's the only way to be sure.  Alas, I don't rule  
the world.  We'll probably be stuck with a solution much more  
jackbooted and less effective.  Like stateful filtering middleboxes  
that have to be told to open pinholes for the IKE port.

--
james woodyatt <jhw@apple.com>
member of technical staff, communications engineering