QUIC experiments [pdf]
ietf.org
ietf.org
When you're looking at a range of ports used to open a connection between layer 7 and, due to the pre-negotiated encryption basically layer 3, netcat, nmap, and tcpdump aren't as informative as they were before.
I'd love to know how Google has been handling that sort of troubleshooting internally.
ISPs limiting DoS UDP flows isn't reason to not use UDP for legitimate purposes. After all, nothing stops DoS botnets from sending junk TCP packets.
Is it? Where's the citation to support the claim that UDP is widely rate-limited? Even if some network operators are daft enough to be indiscriminately rate-limiting all of UDP and not just the ports that are abused (DNS, SNMP, NTP, etc.), how is it productive to encourage more network operators to do that, as this draft does? (Section 4, "Recommendations for Network Operators" point 3.)
And since when has 'guilty by association' been a good reason to condemn anything?
Are you willing to disclose?
"If UDP must be used encapsulate it in IPSec to avoid matching IP protocol 17 filters."
And then you are going to have problems with IPSec getting filtered?
As a UDP user, that is one sad RFC. Maybe I should just write my application to use CurveCP?
Other than that, you're still open to a volumetric attack, but that's not any different from using 1480 byte TCP SYNs. Small pipes are going to be clogged regardless.
"Application and protocol developers should avoid using UDP. [...] has made UDP subject to aggressive filtering at the transport protocol level."
"In the case of QUIC [I-D.draft-tsvwg-quic-protocol] and other transport innovations, a new IANA assigned protocol number should be used [...]"
The whole point of using UDP for QUIC and other transport innovations, is because other protocol numbers are aggressively filtered by NAT routers and other middleboxes!
When you are in a controlled network, sure, you can use a new protocol number (as was done by SCTP). When you are designing a protocol to be used by end-users on networks you don't control, you have to use either TCP or UDP, or it won't work in many cases.