Re: AoE -- was Re: todolist

"Ian Latter" <[email protected]>
Newsgroups gmane.linux.cluster.openmosix.devel
Message-ID <[email protected]>
I'm cool with all of it, 'cept;

    "AoE has much less protocol overhead also since it is
     a layer 3 protocol itself so it is faster on the network.
     But since it is not IP it is not routable. For most people
     this should be ok and even a security advantage."

  I know that the security comment has been the claim 
made by the Coraid announcements/releases;
  http://coraid.vnewscenter.com/press.jsp?id=1105632097003

  But security (encryption and authentication) not being
a feature of the protocol;

  (from;  http://www.coraid.com/technology.html)
  AoE Protocol 
  •  Coraid EtherDrive products use the AoE protocol 
      to connect disks to servers using Ethernet.	
  •  ATA-over-Ethernet (AoE) is a thin protocol layer
      directly on top of Ethernet.	
  •  ATA disk commands (ie. read disk sector x, write 
      disk sector y) are put directly into standard Ethernet
      frames using the AoE protocol. AoE is a block 
      storage protocol.	
  •  AoE is a non-routed protocol, therefore does not 
      require IP or TCP protocol layers. This eliminates 
      unnecessary processing and makes network 
      connection to disks simple.

  .. means that interception and injection is basic.  

  The proof of concept is easy - as a Linux oriented forum
try "arpspoof" and either "tcpdump" or "tethereal" from 
a shell, as root, or "ethereal" from your favourite GUI ...

  I'm fine with the protocol not supplying security, as
long as its not quoted that way ... just show people how 
to use IPSEC and L2TP to route this securely, instead of 
advertising it for what it isn't.

  (see; http://www.coraid.com/pdfs/articles/LinuxDevices.pdf)
  "AoE is not a routable protocol (this provides inherent security)"




G'day to KB .. good to see you still party here :)



----- Original Message -----
>From: "Tracy R Reed" <[email protected]>
>To: "Kris Buytaert" <mlkb-1zPVpAQ/[email protected]>
>Subject:  Re: [Openmosix-devel] AoE -- was Re:  todolist
>Date: Sat, 09 Sep 2006 12:30:33 -0700
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> Kris Buytaert wrote:
> > How does AoE compare to iSCSI ,  from what experience iSCSI is 
already
> > stable enough and ready to use, whereas people only just have 
started to
> > use AoE.
> 
> AoE is much simpler than iSCSI. The AoE spec is just a few pages long,
> the iSCSI spec is a few hundred. AoE is easier to setup. AoE has much
> less protocol overhead also since it is a layer 3 protocol itself so it
> is faster on the network. But since it is not IP it is not routable. For
> most people this should be ok and even a security advantage.
> 
> AoE has been around for quite a while actually. Coraid invented it and
> has been selling machines which are preconfigured to export AoE block
> devices and has been for a while.  I have been using it for a month at
> my shop and so far no problems. It is so great to have the flexibility
> of a SAN using only ethernet hardware!
> 
> - --
> Tracy R Reed
> http://ultraviolet.org
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.5 (GNU/Linux)
> Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org
> 
> 
iD8DBQFFAxZZ9PIYKZYVAq0RAltKAJ43CiViPIAbWuA0TGmAxirKm4kg4ACfSJQ
z
> jrE84YSKvyoVtH761WIbqX4=
> =5exk
> -----END PGP SIGNATURE-----
> 


--
Ian Latter
Late night coder ..
http://midnightcode.org/

-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642

_______________________________________________
openMosix-devel mailing list
openMosix-devel-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/openmosix-devel
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.