nanog mailing list archives
Re[2]: [arin-announce] IPv4 Address Space (fwd)
From: Richard Welty <rwelty () averillpark net>
Date: Wed, 29 Oct 2003 09:25:50 -0500 (EST)
On Wed, 29 Oct 2003 03:14:20 -0800 Avleen Vig <lists-nanog () silverwraith com> wrote:
On Wed, Oct 29, 2003 at 11:03:11AM +0000, Simon Lockhart wrote:No. Anything that relies on knowing which host it is talking to by looking at the source address of packets breaks. Plenty of UDP based apps work over NAT.
Indeed, and IPSec tunnels are frequently done between routers on networks, rather than individual hosts on networks (at least in most multi-site enterprises i've seen).
this is true, but incomplete. there are numerous deployment strategies for IPSec, some of which work around NAT, some of which can be coerced to work through NAT, and most of which don't work around or through NAT. businesses deploying IPSec often lack the flexibility to pick and choose, especially in extranet deployments where two independent business are deploying a tunnel with mismatched equipment and limited choices. it's particularly bad when one end is a 800 lb gorilla with all the high cards, forcing a particular set of parameters on the small business on the other end. i've consulted for small businesses on the wrong end of that stick, and it's no fun at all. you ought to try it some time before you casually toss off a statement like the one quoted above. richard -- Richard Welty rwelty () averillpark net Averill Park Networking 518-573-7592 Java, PHP, PostgreSQL, Unix, Linux, IP Network Engineering, Security
Current thread:
- [arin-announce] IPv4 Address Space (fwd) Andy Dills (Oct 27)
- Re: [arin-announce] IPv4 Address Space (fwd) Petri Helenius (Oct 27)
- Re: [arin-announce] IPv4 Address Space (fwd) Cliff Albert (Oct 27)
- Re: [arin-announce] IPv4 Address Space (fwd) william (Oct 27)
- Re: [arin-announce] IPv4 Address Space (fwd) Stefan Mink (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Avleen Vig (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Dave Howe (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Simon Lockhart (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Avleen Vig (Oct 29)
- Re[2]: [arin-announce] IPv4 Address Space (fwd) Richard Welty (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Dave Howe (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Jack Bates (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Greg Maxwell (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Owen DeLong (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Stefan Mink (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Dave Howe (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Owen DeLong (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Owen DeLong (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Crist Clark (Oct 29)
- Re: [arin-announce] IPv4 Address Space (fwd) Paul Timmins (Oct 29)
- <Possible follow-ups>
- RE: [arin-announce] IPv4 Address Space (fwd) Michel Py (Oct 27)