draft-ietf-intarea-nat-reveal-analysis – IETF84 Analysis of Solution Candidates to Reveal a Host Identifier (HOST_ID) in Shared Address Deployments draft-ietf-intarea-nat-reveal-analysis-02 IETF84 – August Authors: Mohamed Boucadair, Joe Touch, Pierre Levis, Reinaldo Penno Presenter: Dan Wing
draft-ietf-intarea-nat-reveal-analysis – IETF84 Steps to Success 1.There is a engineering problem 2.Discuss solutions 3.Engineer the best solution 2
draft-ietf-intarea-nat-reveal-analysis – IETF84 Steps to Success 1.There is a engineering problem 2.Discuss solutions 3.Engineer the best solution 3
draft-ietf-intarea-nat-reveal-analysis – IETF84 1. There Is an Engineering Problem RFC6269, “Issues with IP Address Sharing” – draft-ietf-intarea-shared-addressing-issues – Section 13.1, Abuse Logging and Penalty Boxes 4
draft-ietf-intarea-nat-reveal-analysis – IETF84 RFC6269, Section one user who fails a number of login attempts may block out other users who have not made any previous attempts but who will now fail on their first attempt.... 5
draft-ietf-intarea-nat-reveal-analysis – IETF84 IP Reputation 6 Image source: Jason Fesler, Yahoo!
draft-ietf-intarea-nat-reveal-analysis – IETF84 Captcha challenge 7
draft-ietf-intarea-nat-reveal-analysis – IETF84 Steps to Success 1.There is a engineering problem – Problem documented in RFC6269, Section Discuss solutions 3.Engineer the best solution 8
draft-ietf-intarea-nat-reveal-analysis – IETF84 2. Discuss Solutions (1/2) Collect proposed solutions Analyze differences Recommend best solution Previous examples of solution discussions – “Recommendation for a Routing Architecture”, RFC6115, recommendation: ILNP – “Requirements and Analysis of Media Security Management Protocols”, RFC5479, recommendation: DTLS-SRTP 9
draft-ietf-intarea-nat-reveal-analysis – IETF84 2. Discuss Solutions (2/2) draft-ietf-intarea-nat-reveal-analysis 8 solutions analyzed: 1.IPID field 2.IP option 3.Port sets 4.ICMP 5.TCP option 6.PROXY protocol 7.Host Identity Protocol (HIP) 8.Inject Application Headers (e.g., X-Forwarded-For) 10
draft-ietf-intarea-nat-reveal-analysis – IETF84 Steps to Success 1.There is a engineering problem – Problem documented in RFC6269, Section Discuss solutions – draft-ietf-intarea-nat-reveal-analysis 3.Engineer the best solution 11
draft-ietf-intarea-nat-reveal-analysis – IETF84 3. Engineer the best solution First need consensus on the best solution We aren’t yet ready 12
draft-ietf-intarea-nat-reveal-analysis – IETF84 Some Questions for the WG 1.Consensus on problem in RFC6269 §13.1? 2.“Just Deploy IPv6” – Does this avoid problem in RFC6269 §13.1? – Current trajectory is 50% IPv6 in 6 years 3.Are there more than 8 solutions? 4.Disagreement that ietf-intarea-nat-reveal- analysis should recommend a best solution 13
draft-ietf-intarea-nat-reveal-analysis – IETF84 Thank you draft-ietf-intarea-nat-reveal-analysis 14