Hi Brian,

On 23/10/12 2:54 PM, "Brian E Carpenter" <[email protected]>
wrote:

>On 21/10/2012 04:01, Ted Lemon wrote:
>> On Oct 20, 2012, at 10:55 PM, "Tirumaleswar Reddy (tireddy)"
>><[email protected]> wrote:
>>> Yes. In such Managed Networks, SLAAC is disabled and IPv6 addresses
>>>are only assigned using DHCPv6 server. Switches in such environments
>>>provide First Hop Security by gleaning DHCP/NDP messages and can make
>>>sure hosts are using the IPv6 addresses assigned by the DHCPv6 server
>>>only (Source Guard). With the technique in this draft only certain
>>>hosts will be permitted assignment of IA_TA and not for other hosts.
>> 
>> That makes sense‹thanks for clarifying!
>
>It makes sense, but the draft doesn't explain that it is only
>intended for use in managed networks where the suppression of
>privacy is considered acceptable. I think this needs to be stated
>in the Introduction, and the issue of (loss of) privacy needs to
>be discussed in the Security Considerations.

Sure, will state as suggested.


>
>How will users know that temporary addressing has been disabled?

Users wont. I suppose guests authenticating using Webauth could be served a
disclaimer page that points this out. It's the administrative domain that
makes this decision.


>
>Is there a risk of a rogue DHCPv6 relay switching off temporary
>addressing for hosts that really need it?

DHCP authentication should be used to counter such risks. A DHCP server
would then only process relay options included by a valid relay agent.


>
>Also, in the section
>
>> 3.2.1.  Avoiding Excessive IP-Based Authentication
>
>it says:
>
>>                      When Address-based authentication is used, re-
>>    authentication occurs for each address obtained by the host, which
>>    can create a lot of authentication transactions.  To reduce this
>>    chatter,
>
>This doesn't convince me that the proposed feature is solving a real
>problem. "A lot of" and "chatter" are vague terms. Can you add something
>to suggest what size of a network would have a real performance problem
>as a result?

When IP address based authentication eg Webauth is used, the
authentication device will end up authenticating each and every temporary
address used by the client - So 'a lot of' here implies that the number of
authentications is equal to the number of temporary addresses used by the
host - this would also lead to bad user experience. The same number of
transactions with the backend AAA server to validate user credentials will
also have to be made.
Will add these details.

-Prashanth


>
>Regards
>   Brian Carpenter
>
>
>_______________________________________________
>mif mailing list
>[email protected]
>https://www.ietf.org/mailman/listinfo/mif

_______________________________________________
mif mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/mif

Reply via email to