[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: NAT Traversal



"Chinna N.R. Pellacuru" <pcn@cisco.com> writes:

> If someone has just one IP address to use as his local endpoint, then
> probably 64K IPsec connections is more than enough for him. That box has
> to first be able to handle so many IPsec connections.

You are missing one thing.  Yes, there is a potential to hold 64k
connections, except by the birthday paradox you will get a hash
collision after 256 connections.  Don't you think that 256 connections
is too few?

-derek

-- 
       Derek Atkins
       Computer and Internet Security Consultant
       derek@ihtfp.com             www.ihtfp.com