[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Suggestion for SOI wrt PFS



Angelos D. Keromytis writes:
 > So you're saying that you *do* have a business need for a box that can
 > support a sustained SA setup rate of 1000 tunnels/second ? Could you
 > expand on it ?

Oh please. Not everything is a site-site VPN. IKE
was specifically deemed useless by Packetcable for
cable telephony because restart avalanches of tens
or hundreds of *thousands* subscriber boxes would
lead to unacceptible down times. That's *one*
business need, and hardly a unique one. Any high
fan out use of IPsec is going to care a great deal
about how the high fan in box behaves, and the
number of SA's per second is an important number.

	  Mike