Hi, I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written with the intent of improving security requirements and considerations in IETF drafts. Comments not addressed in last call may be included in AD reviews during the IESG review. Document editors and WG chairs should treat these comments just like any other last call comments. Summary: Ready to publish with small edits. Details: This document doesn't specify any protocols. There appears to be a missing word in the end of the Security Considerations section which says: It is important to proper AAA [RFC2904] to authorize access to the network and access to the I2NSF management stream. I'm not sure if this is missing "proper AAA [something] [RFC2904] to authorize" or if there is a different phrasing. I'm not sure what is trying to be said about AAA, but this sentence is clearly missing an article (as "proper AAA" by itself is not a noun"). -derek -- Derek Atkins 617-623-3745 derek@ihtfp.com www.ihtfp.com Computer and Internet Security Consultant