Why IPsec is needed for iSCSI but might not be needed for RDDP/iWARP

John Hufferd <[email protected]>
Newsgroups gmane.ietf.rddp
Message-ID <OF2F73D453.AAEF1574-ON88256EAD.0064E71F-88256EAD.0067D853@us.ibm.com>
David,

Perhaps you could explain again for me and perhaps some other "dense" 
folks why IPsec would be a MUST implement (but optional to use) for iSCSI 
but we are attempting to not say similar things for RDMA/iWARP.

I am not pushing an agenda here, I know that if we do not need IPsec for 
RDMA/iWARP on clusters and other such reasonably secure environments, the 
requirements of IPsec as a MUST implement in all cases will NOT be 
approprate.  (And often the RNIC used for such clustering environment is 
on its own Subnet and not part of a general communication network.) But I 
also feel that when RNICs are used on less secure environments, that the 
environment looks similar to iSCSI.  Perhaps even less secure because of 
the RNIC holding the placement open to a storage location were with HW 
iSCSI, the direct placement and the protocol are closely combined so that 
Buffers are not left open for the intruder (at least not as much). 

So based on the above thoughts, I am not sure why it was required for 
iSCSI to use IPsec (when iSCSI HW is more secure than RNICs) and not an 
issue for RDMA/iWARP.

I get (but do not buy) the arguments that RDMA/iWARP is just using the 
TCP/IP (or SCTP) and as such does not need any other protection that is 
given to that, but then so was iSCSI.

So your thoughts about why it would be needed in one and not the other 
would be of interest.  Since I do not see that a solution for protecting 
the Buffers (single shot or what ever) changes the issue of why iSCSI and 
not RDMA/iWARP.  If we protect the Buffers, then the results will have a 
similar profile to iSCSI.  So that alone can not be a full solution.

If your position is that it is needed for both regardless of the buffer 
protection, and you are suggesting that we might come up with something 
that handles "authentication" at the DDP layer via Cryptographic 
approaches as a possible approach to meeting the need, then I can 
understand the logic as far as it goes.  But you have not said anything 
about the need for Privacy (Encryption).  I thought that was also an 
important consideration. 

Anyway, perhaps you could address the above, and help clarify the issues 
for some of us.

Also as a second point, does it make since to attempt to define 
environments where RDMA/iWARP would be approprate without the additional 
Cryptographic or IPsec implementations (such as within clusters on their 
own physical subnets, etc.), and then require IPsec in other less secure 
environments?

.
.
John L. Hufferd
Senior Technical Staff Member (STSM)
IBM/System Group, San Jose CA
Main Office: (408) 256-0403, Tie: 276-0403, eFax: (408) 904-4688
Alt Office: (408) 997-6136, Cell: (408) 499-9702
Internet Address: [email protected]

_______________________________________________
rddp mailing list
[email protected]
https://www1.ietf.org/mailman/listinfo/rddp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.