mglt / draft-mglt-nvo3-geneve-security-requirements

0 stars 1 forks source link

flow granuarity #25

Open mglt opened 5 years ago

mglt commented 5 years ago
  1. Section 5.5 – Same comment as above applies to this section SEC-OP-7, 8 and SEC-GEN-11. So the requirements needing flow level granularity to be removed. These are prescribing implementations and undue burden on NVEs that are not needed to secure communication between NVEs.
mglt commented 5 years ago

My understanding is that a communication is characterized by flows. There is a need to define what is being encrypted and this si characterized by a flow.

I believe the concern is about reducing the granularity of the flows. I believe more discussion is needed to define the right set of granularity.