Last Call Review of draft-ietf-opsawg-ipfix-bgp-community-07
review-ietf-opsawg-ipfix-bgp-community-07-secdir-lc-emery-2018-09-20-00

Request Review of draft-ietf-opsawg-ipfix-bgp-community
Requested rev. no specific revision (document currently at 12)
Type Last Call Review
Team Security Area Directorate (secdir)
Deadline 2018-09-24
Requested 2018-09-10
Other Reviews Opsdir Telechat review of -10 by Al Morton (diff)
Genart Early review of -04 by Joel Halpern (diff)
Rtgdir Early review of -06 by Joel Halpern (diff)
Genart Last Call review of -07 by Joel Halpern (diff)
Opsdir Last Call review of -08 by Al Morton (diff)
Genart Telechat review of -11 by Joel Halpern (diff)
Review State Completed
Reviewer Shawn Emery
Review review-ietf-opsawg-ipfix-bgp-community-07-secdir-lc-emery-2018-09-20
Posted at https://mailarchive.ietf.org/arch/msg/secdir/uC3NIGjOKTynsFa0FFwGueC1GcA
Reviewed rev. 07 (document currently at 12)
Review result Has Nits
Draft last updated 2018-09-20
Review completed: 2018-09-20

Review
review-ietf-opsawg-ipfix-bgp-community-07-secdir-lc-emery-2018-09-20

Reviewer: Shawn M. Emery
Review result: Ready with numerous nits

I have reviewed this document as part of the security directorate's
ongoing effort to review all IETF documents being processed by the IESG.
These comments were written primarily for the benefit of the security
area directors. Document editors and WG chairs should treat these
comments just like any other last call comments.

This draft specifies new Information Elements (IEs) in order to support BGP
community
information for the IP Flow Information eXport (IPFIX) protocol.

The security considerations section does exist and states that the draft
just defines
new IEs and does not introduce any new security considerations.  The
section then
goes on to state that the same security issues that apply to the IPFIX
protocol and
the corresponding Information Model applies to this specification.  I agree
with these
assertions.

General comments:

None.

Editorial comments:

s/differnt/different/g

s/Netwok/Network/

s/statistic/statistics/

s/mediator needs/the mediator needs/

s/Mediator is/The mediator is/

s/figure up/determine/g

s/mechanisum/mechanism/

s/generted/generated/

s/Please refer/Please refer to/g

s/originated from AS A and destinated/originating from AS A and destined/

s/becuse it will cause the congestion/because it will cause congestion/

s/togecher/together/

s/source IP and destination IP/source and destination IP address/g

s/both the source IP and the destination IP related/relating to both
the source and destination IP addresses/

s/length one IPFIX/length of one IPFIX/

s/to the information about the networks in the field/to information
about networks in the field/


OLD:

configure export policy of BGP communities on the exporter to limit
the BGP communities to be exported, so as to only export some specific
communities,or not to export some specific communities.

NEW:

configure the export policy of BGP communities to limit the BGP
communities by including or excluding specific communities.


s/The detailed mechanism is out of the scope of this document./The
details of increasing IPFIX message length is out of scope for this
document./

s/refer Appendix A/refer to Appendix A/

s/source or destination IP/source or destination IP address/


Shawn.

--