The MPLS-OPS Archive

Cell Relay Retreat>MPLS-OPS Archive>month:2001-Mar> msg00119



[Date Prev][Date Next][Thread Prev][Thread Next]  
  [Date Index][Thread Index][Author Index][Subject Index]

RE: Questions about MPLS

  • From: Daniel Hagerty <hag@linnaean.org>
  • Date: Sun, 18 Mar 2001 14:09:34 -0500
  • Cc: <mpls-ops@mplsrc.com>
  • Resent-Date: Sun, 18 Mar 2001 15:38:52 -0500
  • To: "Tim A. Irwin" <tirwin@bellsouth.net>

 > How is this obvious or scalable??? First of all your assuming that any type
 > of CPE a SP's customer wants to use supports IPsec, which is not at all
 > true. Secondly, IPsec has a very limiting factor in scalability - the
 > encryption/decryption "tax".  Third, IPsec makes it very difficult for a SP

    A $1200 vanilla desktop PC from two years ago can fill a T3's
worth of bandwidth with high-grade IPSec.  The fact that my cisco
can't means that I'll use my cisco for what it's good at.

 > to assist a customer in troubleshooting problems since the SP intermediate
 > devices can't see what's going on inside the IPsec ESP payload.

    For some of us, that's the point.

 > By the way, in reference to your statement about "standard IP packets" take
 > a look at IPsec in transport mode and tell me if I doesn't look a lot like
 > MPLS labels...  A shim header right behind the IP header and before the TCP
 > header. Hmmm.... looks pretty similar to me!

    One requires a pile of intermediate stuff to have any meaning.
The other only cares about being delivered to the far edge of the
network.

-------
The MPLS-OPS Mailing List
Subscribe/Unsubscribe:  http://www.mplsrc.com/mplsops.shtml
Archive: http://www.mplsrc.com/mpls-ops_archive.shtml