Re: my response to the proposed changes

Robert Elz <[email protected]> Fri, 25 Jun 2004 18:07:13 +0700
Newsgroups gmane.ietf.zeroconf
Message-ID <[email protected]>
    Date:        Fri, 25 Jun 2004 10:00:27 +0100
    From:        "Philip Nye" <[email protected]>
    Message-ID:  <005701c45a92$dc3f2f70$131010ac@aldebaran>

  | Try "DEFENSE_WINDOW" - it's snappier.

If you're going to do that, at least spell it rationally

	DEFENCE_WINDOW

(or avoid US vs English wars, and simply use a different word).
Using "window" is good though, that suggests the correct properties.

And since I'm here (I was going to avoid this discussion), I certainly
agree that preventing dueling ARPs at flat out net rate is a good
thing to do), but I cannot fathom any justification for 10 minutes
as the timeout, 1 minute would be just as good, even one second would
be adequate for that purpose (2 ARP packets a second might not be
wonderful, but it isn't going to kill any network, and is unlikely to
occur very often in any case).

It looks to me as if this number is a reaction to "I have seen very bad
things happen with no limit here, and so we must prevent that" (which is
fine) but then going to extremes to make sure nothing like the "bad things"
can possibly happen, ever, way beyond what is actually required, or reasonable.

Beyond that, I am still yet to see any justification for requiring hosts
to give up their address after receiving 2 ARPs in the window?  (Remind me,
must they be from the same host, or would 2 from anyone do it - if the latter,
the window should be made a small as reasonable, not as large.)

Suggesting that as a good thing to do is fine, but why require it?

If we have 2 hosts, and they have this conflict, then there are
3 possibilities

both abandon the address & acquire new
		That's the current expectation in the draft
		(no need to say more about it here)

one of the hosts abandons its address, the other continues using its
		Everything works fine, the host that wanted to keep its
		address continues as if the conflict had never existed,
		the other acts just the way the draft currently expects.
		No problem.

both choose to retain the conflicting address
		In this case, both hosts are screwed, and most likely
		neither can talk.    But that's what they have chosen as
		an option - better to prevent the address being used by
		a potential interloper, than to worry about keeping its own
		network operations functional.
		Also fine (it's the host's choice - and no harm comes to
			the rest of the network).

So, why are we requiring hosts to abandon their address in the case
of a conflict again?

kre