Document: draft-ietf-spring-srv6-security
Title: Segment Routing IPv6 Security Considerations
Reviewer: Colin Perkins
Review result: Ready

This document has been reviewed as part of the transport area review team's
ongoing effort to review key IETF documents. These comments were written
primarily for the transport area directors, but are copied to the document's
authors and WG to allow them to address any issues raised and also to the IETF
discussion list for information.

When done at the time of IETF Last Call, the authors should consider this
review as part of the last-call comments they receive. Please always CC
[email protected] if you reply to or forward this review.

The draft presents a security assessment of SRv6, specifically considering the
mechanisms described in RFC8402, RFC8754, RFC8986, RFC9020, RFC9256, RFC9491,
RFC9524, and RFC9800.

The draft is well written and clearly describes threats and mitigations. It has
a well-defined scope, and stays within its boundaries. The threat models and
effects of possible attacks are clearly described.

Section 6 discusses data plane, control plane, and management plane attacks
(summarised in Table 2). This is well-structured and well-written, and clearly
describes the relevant issues. The attacks described can certainly impact on
transport protocol behaviour, but the types of attack are known and their
impacts are understood. Thus, there do not appear to be any new
transport-related failure modes or risks.

Section 7 discusses mitigations, with Section 7.2 considering encapsulation of
packets as a mitigation against some attacks. Encapsulation has implications
for the transport. since it can affect the path MTU and impact ECN behaviour,
but the referenced RFC 8754 discusses these issues, and there don’t appear to
be new transport-related concerns.

Overall, this looks to be a useful document. It does not appear to raise any
transport-related concerns.

Colin


_______________________________________________
spring mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to