Hi all,

I brought up ACL types and ACE numerical IDs in other separate email threads.  
This one is for a set of other misc. comments (one functional, the rest are 
more editorial).

A) Please make the metadata optional with an if-feature (or make each of 
input-interface & time-range their own if-features - that is probably better).  
Or drop those out of the model and leave them to augmentations.    If we do 
keep input-interface in the model as an if-feature then:
- should we import ietf-interfaces with just the prefix"if" ?  That is the 
prefix in the ietf-interfaces module and what is used in the routing model for 
example.
- shouldn't the input-interface be a leafref (e.g. if:interface-ref) ?

B) In section 3 there is a sentence about Metadata that mentions 'destination 
prefix length'.  I'm not sure that makes sense. A prefix length is part of a 
prefix matching criteria (i.e. a rule in an ACE) and not really a piece of 
metadata about a particular packet.

C) Is the access-list-entries container needed/useful ?  If there is some 
reason to keep that then should we call it acl-entries ? (like how we have 
acl-name, acl-type, acl-oper-data, etc)

D) Should we perhaps create identities for the protocols (based on whatever 
IANA assignments there are) ?  Right now all it says is uint8.  We should at 
least have a reference to some registry/document/rfc.

E) We should mention that port means TCP or UDP port.  Should we also consider 
some sort of 'when' statement such that port is only valid when protocol = tcp 
or udp ?    Related to this -> some implementations use a wildcard of some sort 
that means "TCP or UDP".  Maybe we should add that as an identity into 
"protocol" ?

Regards,
Jason

_______________________________________________
netmod mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/netmod

Reply via email to