Firewall Wizards mailing list archives

R: IPSEC over load-shared T1s (per packet)


From: "Francesco Trentini - Uff. EDP" <francesco.t () acerbis it>
Date: Mon, 29 Sep 2003 13:02:03 +0200


The "bit-map" they're talking about is the same thing I was
talking about. I say re-open the ticket. Reordering happens.
Implementations that do not take that into account are broken.

Really.
You can spend all of your efforts assuring that in your border router
packets flow in sequence (flow balancing, trunk based solutions), but you
can never be sure the packets don't get out of sequence in the *Internet*
(ie. flapping routes with different latencies).

Yes, you are right, implementation is broken.
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: