[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Some suggestions for draft-ietf-v6ops-cpe-simple-security-03



Fred Baker writes:
Forwarding comments... Begin forwarded message:
From: Mark Smith <ipng@69706e6720323030352d30312d31340a.nosense.org>
Date: August 24, 2008 4:15:53 AM PDT
To: jhw@apple.com, v6ops-residential-cpe-design- team@external.cisco.com
Subject: Some suggestions for draft-ietf-v6ops-cpe-simple-security-03 Hi,
I've finally found a bit of time to start having a read through the 03
version of this draft. I haven't read through all of it yet, however
here are some starting suggestions: 2. Overview
Change "requires" to "provides", just to continue to emphasise a bit
that the statefulness of NAT wasn't specifically designed into it:
"Only the perceived security benefits associated with stateful packet
filtering, which NAT (requires|*provides*) as a side effect, are
thought relevant in the IPv6 residential usage scenario."

Problem with the text is that NAT <> security, this is why it is not in v6.