Re: WG status 2003/08/13
Pekka Savola <[email protected]> Thu, 14 Aug 2003 16:35:31 +0300 (EEST)
| Newsgroups | gmane.ietf.itrace |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 14 Aug 2003, Marcus D. Leech wrote: > > 2) iTrace is relatively lightweight, some vendors' ACL implementations > > can't handle linespeed. E.g. with STM-16 (2.5 Gbit/s) interface, iTrace > > might result in some 10-20 iTrace packets a second. Could be doable even > > on sloppy CPU's if there are no crypto requirements :-) > > > At 10-20 iTrace packets a second, even with HMAC-MD5, the CPU > consumption > from the HMAC computation will be down in the noise. > > Look at the "Performance Assumptions" section of RFC3562 to get an > idea of MD5 performance numbers. I don't disagree with that, but my main point was that it causes code/implementation complexity and also some more _operational_ complexity (configuring certificates/keys, putting them available, etc. -- not so straightforward as "just turn it on"). Note that CPU's used in some routers are _really_ not that effective though, and the vendors may also loath to add functions like these on them (in practice, they alsready have to add at least something, for BGP MD5 implementation). Just another possible hindrance to implementation and deployment (even though probably not a real one). -- Pekka Savola "You each name yourselves king, yet the Netcore Oy kingdom bleeds." Systems. Networks. Security. -- George R.R. Martin: A Clash of Kings