SORT BY:

LIST ORDER
THREAD
AUTHOR
SUBJECT


SEARCH

IPS HOME


    [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

    RE: iSCSI and the IPSEC replay window



    Hmm ... I would have thought that the separate
    TCP connections for the alternate paths
    would use separate IPsec SAs and hence would
    not share a replay window, making this a non-
    issue.  Steve Kent had a number of things to
    say in the ipsec WG about running IPsec at
    gigabit speeds, all of which are probably
    applicable to iSCSI, but best left to the
    ipsec WG.
    
    --David
    
    > -----Original Message-----
    > From:	Bernard Aboba [SMTP:aboba@internaut.com]
    > Sent:	Tuesday, January 09, 2001 12:33 PM
    > To:	ips@ece.cmu.edu
    > Subject:	iSCSI and the IPSEC replay window
    > 
    > At IETF 49, we had a presentation on use of IPSEC in
    > iSCSI. While I'm generally positive on the concept
    > of re-using IPSEC in this way, there are some things
    > to think about. 
    > 
    > One of these is the effect of the IPSEC replay window
    > on TCP behavior. At the 1+ Gbps speeds of iSCSI, it
    > strikes me that even a small variation in delay 
    > between two alternate paths will result in falling
    > outside the IPSEC replay window if it is set to a
    > small, fixed value (say 64 packets). 
    > 
    > So the size of the IPSEC replay window should probably
    > scale with transmission speed. 
    > 
    > Do we understand how this ought to work and is there
    > a potential for some unforseen effects?
    > 
    > Inquiring minds want to know ;)
    


Home

Last updated: Tue Sep 04 01:05:56 2001
6315 messages in chronological order