[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

"Pillage first, then burn" - Attila the Hun



"Compress first, then encrypt" - Bob Monsure

Bob,

I have watched the IPSec mailing list debates pretty much from the sidelines
so far. I am heartened by the lively debate, but disappointed by closure on
key aspects of the standards effort (no slam intended against anyone). I
agree with Ran - there isn't a consensus at this point.

Email to the IPSec list has its place, and formal presentations have their
place, but I believe you (HiFn) and I (Cisco) need to host an informal
BOF-like discussion in Memphis around this topic in the hope that it can
help move opinion forward. Maybe Tuesday evening would work.

At that session, I propose that we discuss Cisco's results with compression
in an IPSec-type environment. We have tied LZS into our client stack and are
now accumulating data on what it can do for you. We should present that data
to the community, even if it's in pretty raw form (which it will be!) at
that time. Who knows, we may even be ready to demo a compression-enabled
IPSec implementation by then (watch as five Cisco engineers slaughter me in
Email for saying this...). I will also be prepared to discuss ways that
Cisco can assist others with their implementations.

One final point. Some people worry that working on compression now will slow
down IPSec standards work. While I understand that concern, it is more than
outweighed in my mind by how seriously a lack of compression would impede
actual customer adoption of this technology. In fact, Cisco does not plan to
release an IPSec implementation until there is a plan, which we can
communicate clearly to customers, about how and when we will be doing
compression in that environment. This is the result of significant customer
backlash to lack of compression in our now-shipping but non-standard
encryption offering.

In closing, let me emphatically state my support for proper process in the
IETF, and my strong desire for a standard in this important area. Thanks,
Bob, for your help with this. Anybody on the IPSec list who wants to discuss
this more in private is encouraged to send me private Email.

         \|||/
         (. .)
------ooO-(_)-Ooo------------------------------------------------------------
      ^^         ^^        Cisco Systems, Inc.      STEVE SNEDDON
     .||.       .||.       IOS Development          Director, IOS Client Tech
    .||||.     .||||.      170 West Tasman Drive    Phone: 408-527-1035
..:||||||||:..:|||||||:..  SJ-F2                    Pager: 800-365-4578
    Cisco Systems Inc.     San Jose, CA 95134-1706  EMAIL: sned@cisco.com
-----------------------------------------------------------------------------





Follow-Ups: