Alvaro, Lots of thanks for your email. I agree that the draft cannot- and should not - mention all specific attacks.
But I find it strange that the draft is focused on underlay aspects of SRv6 and seems to ignore attacks on overlay services - be it data plane, control plane, or management plane. One possible aspect is impact on services that use MPLS underlay in hybrid deployment scenarios. My guess (FWIW) that attacks on SRv6 underlay would not affect MPLS underlay and vice versa. But attacks on SRv6overlay (as in my example) could affect services that use MPLS overlay (and vice versa). One possibility to resolve this could be to say that the draft is focused on SRv6 underlay security while overlay security would be considered in a separate document. My 2c, Sasha Get Outlook for Android<https://aka.ms/AAb9ysg> ________________________________ From: Alvaro Retana <[email protected]> Sent: Friday, September 4, 2026 4:34:49 PM To: [email protected] <[email protected]>; Alexander Vainshtein <[email protected]> Cc: [email protected] <[email protected]>; [email protected] <[email protected]>; James Guichard <[email protected]> Subject: [EXTERNAL] Re: [bess] Security aspects of SRv6-based overlay services [+ Jim: the draft is in IETF LC.] Sasha: Yes, the risk you describe is a BGP attack that could affect SRv6 services. §6.3 covers this topic (deletion/modification), but doesn’t mention your specific example — it can’t list them all! I’ll leave it to the authors. Thanks! Alvaro. On September 4, 2026 [https://image-processing-service.us-4.mimecastcybergraph.com/v2/banners?e=fxks67sGuausonyiKQVe7BROMlIpO503ZM_Av1nvhVMu1fRddXX9rBhQ_970hMBlRJLIEEdWoMJ3rjhgt1j0YAbtErJRWu-VodDEFx6QGSbn7UWeKMc47nn_mvy80tn6ylNc1nbvScM9Y0zxoiO5PsilhGR0R1c8PnlMx4jdKnd5XK56TsQjmjricU3PR01ZvaHxWYchpX8XllHyEbOBEyhgHP3Nt5LMfLaqXvmX5ZQrb7DwpLtagvAI-5tHazkeDfBCUKvXxqXbaxWEnEktLlL7f_8Qc96nXGoJ0LCCJGtK6jDqPzdQ-HNLzhiQw6oeqEwm4wRo3uGwygeJz3K-wdcddqNiJuvwv6q5-TH0bHj5JkUcuVeCEHoLYwiCxRH9lZIDAlQ_W-p72c8QaJ5SAX1tRUnnGUgYhDl5JJFfuG8dla-18y6A4tl8sbW0EK3IHNcRQl3BTk_jVRucuiE=]<https://report.mimecastcybergraph.com?magiclink=https%3A%2F%2Fapi.services.mimecast.com%2Foauth2%2Fauthorize%3Fresponse_type%3Dcode%26client_id%3Do20nRkVXf7VUVnANkXhoOwGytEwGN0YAlyeDJn7oBTGNl2kN%26state%3DeyJhbGciOiJSU0EtT0FFUC0yNTYiLCJlbmMiOiJBMjU2R0NNIn0.EeuMdEPYHvdSkVTedgj9SVFsejbCHwJiJtApzaNc92wH4YOxWeQu3d5TePdBfpwEmPEp9-Fr9A_6aIgY2mPWlBmVYYaQNj0S-17Agajvb1VmqRhGF2exfousxMnNyO79OH3s4rr21iQxno9i_BfVxneROCKbqOhFj8m6xLUa_pHcBCy0gr4rKbdJxObwGT3cnPRJR2SDogn9hspOd5ElUJzKvExKndta9TiQOnc9no4BYvHgCV4LHa7uv4uij6W8_d2hMpz6aAIlrWci9c2H9UopXpqU6l_t5ydhIV6G26MxKs-b_HQnieO6F9wnHe4P-Rpoh-ejaCRVVxRKGWRujA.teSgLuzDD3X_Lz_3.UKBiQI8FVxlDyFZeckhlHbFXeM6V7DviJSs9QtFgVKBJywaSudc2l_GGHzuCPXYt0YOssMBebZ6BVOiGgEqL-Qsiwg4V2pRd9oyMHntoV6_bA9FIbYc3i2VdzrEXuJ_WVEhlNWOJPc0W0pEkNqtVARYScpEQUq9L9HiL6-r18bgDjhkcN4PNdid31QItCYgsUcSTSeIod2C0swW9HT_52elxaWcELpwVQUzuNgb2e2aDixzUf6pFNI23ple98kiTDiUHYbqArjp8IhqFVkZuzGGwqYX1_oWW6Vt-ju3SDkjQuKfMJ7gats_5w54nDjppUdhNXhC25au3GoL10_kGRHpaJpYL15lF10c8jCVQZ2c0bLBmkzkV6UBgXw0_jL8fZF2rYLNwAWRUM0HlRwjOZx1I21FnivJWm7KdUymhyXDy0Xik4J41y90ar-rz1YyUXs_8-wQ8CQaVp5_azhFCJuwi1QnyXHD4YI8ivB4Q8Iejmqcxycl8dnrpoouy62LtqPP-8kHC7EHizRhyeGUEwUpYR5dpowhU-8oB_st2TD1ZTRKNly2ZaqBmpm3v9Xs8WnC86Pc4t4UthyOrEBFJi9noIiiDhfbx6oGYrRE_-i3BOVU13ZApC6XPmWWCAQURZ6fh0ZuzujGWW17IBhf04PNEz8hbeNeyhvlXA8G0M_Ib3uF-9TrYL6QEK2uyznV9gaYSm-DnO14cu_wqwsy32Kognh-mTUzgYjxrU5baU0eWyojHmRe8tX05sRc2BB_EA15ru6xm2UpJ7Lq9YSFXx8GJEBOtAkcL8iGjqA_TwSHj4AlPDfcYVxfS5mKA7iwgSF9xQ2v6UF9bSCGJtnVjawq9.8favJGElD1XWDhdW6-pDaA%26redirect_uri%3Dhttps%3A%2F%2Freport.mimecastcybergraph.com%2Fcallback> CGBANNERINDICATOR [+ Jim: the draft is in IETF LC.] Sasha: Yes, the risk you describe is a BGP attack that could affect SRv6 services. §6.3 covers this topic (deletion/modification), but doesn’t mention your specific example — it can’t list them all! I’ll leave it to the authors. Thanks! Alvaro. On September 4, 2026 at 3:14:01 AM, Alexander Vainshtein ([email protected]<mailto:[email protected]>) wrote: Hi all, I have briefly looked up the current version of the draft. I am not a security expert, but it seems that the draft deals with security aspects of SRv6 underlay. I wonder if SRv6 "service SIDs" and the way they are advertised in BGP do not introduce any special vulnerabilities. E.g., a compromised Route Reflector could modify (or simply discard) the BGP Prefix SID Attribute in routes of such families as VPN-IP or EVPN - with a devastating effect on the services., while such an attack would not have any impact on IP-VPN and EVPN services over MPLS underlay. What, if anything, do I miss? Regards, Sasha Get Outlook for Android<https://aka.ms/AAb9ysg> Disclaimer This e-mail together with any attachments may contain information of Ribbon Communications Inc. and its Affiliates that is confidential and/or proprietary for the sole use of the intended recipient. Any review, disclosure, reliance or distribution by others or forwarding without express permission is strictly prohibited. If you are not the intended recipient, please notify the sender immediately and then delete all copies, including any attachments. _______________________________________________ BESS mailing list -- [email protected]<mailto:[email protected]> To unsubscribe send an email to [email protected]<mailto:[email protected]>
_______________________________________________ spring mailing list -- [email protected] To unsubscribe send an email to [email protected]
