Re: IPsec & Markers
"Michael C. Cambria" <[email protected]>
| Newsgroups | gmane.ietf.rddp |
|---|---|
| Message-ID | <[email protected]> |
Caitlin Bestler wrote: > > On Oct 8, 2004, at 6:58 PM, Michael C. Cambria wrote: > >> >> >> Caitlin Bestler wrote: >> >>> On Oct 8, 2004, at 5:10 PM, Michael C. Cambria wrote: >>> >>>> >>>> In MPA, is there any reason why, just like what is allowed with CRC, >>>> one >>>> cannot have a system administrator knob to disable the use of markers >>>> when IPsec is being used? >>>> >>>> In fact, when I know I'm using IPsec, I rather not have to go >>>> through the >>>> overhead of markers even when the remote peer sets the M bit in the >>>> Request/Reply frame. >>>> >>>> Regards, >>>> MikeC >>>> >>>> >>> The Markers are to enable the receiving side to locate the start of >>> MPA Frames even when TCP Segments are received out-of-order. >> >> >> Out of order or "unaligned"? When the entire FPDU fits in the TCP >> segment (e.g. aligned), >> I have no problem locating the start of MPA Frames, in (TCP sequence) >> order or not. >> > > You can always find the MPA Frame when it is received in-order. > It follows the previous MPA Frame. Agreed. And if out of order, I can use the first to bytes to find the CRC. If the CRC is wrong, I don't have an FPDU. >>> Even with IPSEC enabled a received out-of-order TCP Segment >>> is not necessarily an MPA Frame. Without markers how would the >>> receiver locate the MPA Frame boundary? >> >> >> Sec 5.3 says "MPA MUST encapsulate the ULPDU such that there is >> exactly one ULPDU >> contained in one FPDU." With IPsec, there will be no middlebox that >> can re-segment TCP >> segments. What I put in the IPsec (e.g.) tunnel will come out the >> other end of the tunnel. >> >> MikeC > > > You are assuming that the FPDU is submitted directly to IPSEC. > If it is submitted to the TCP layer, which submits it to IP layer and > then that is submitted to iPSEC then you no longer have a guarantee > of alignment. I'm assuming an "MPA aware TCP". On such, at a minimum, I'd like a knob to not need to waste cycles doing markers, similar to what the draft allows for CRC when IPsec exists. e.g. both sides need to agree. > I would not anticipate that many implementations will roto-till > IPSEC thru RDMAP. So layering artifacts cannot be ruled out. Since IPsec for RDMA cannot be an external box, I can rule out a lot in _my_ implementation of MPA, MPA aware TCP/IP and IPsec. You don't trust it, don't turn the "no need for markers" knob I'm suggesting when connecting to me (or ever.) But even in the general case, I still don't see any problem. BTW, what does "roto-till" mean? :-) Cheers, MikeC -- Michael C. Cambria email : [email protected] VoIP : sip:[email protected] FWD : sip:[email protected]