Skip to main content

Posts

Showing posts from March, 2013

NAT46 or NAT64

這問題還是有沒有需求 NAT64能work還是要靠DNS64, 所以NAT46也還要請回DNS, 所以是DNS46了 DNS64有RFC, 而且是 Category: Standards Track, 真有人要NAT46嗎? http://tools.ietf.org/html/rfc6147 DNS DNS, NAT-PT因你而bye

ipsec的 AH/ESP & Tunnel/trasnport

讀ipsec N年了, 讀了就忘, 該是有個了結 http://tools.ietf.org/html/draft-bhatia-moving-ah-to-historic-00.html AH能做的看來 ESP都OK,所以說bye吧 http://blog.ine.com/2010/05/28/when-transport-mode-becomes-tunnel-mode-free-of-charge/ 大多數的環境都不會用transport mode(你知道juniper SRX完全不支援transport mode嗎?) 因為transport mode只會protected ipsec peer的IP 所以, 只搞定ESP+tunnel mode應該就夠了 另外IPSec 是直接跑在IP上的,  PAT+IPsec要有怪招才行, 每家功能都不一樣(ALG?) IP Protocol ID of 50 (0x32) for IPSec Encapsulating Security Payload (ESP) traffic IP Protocol ID of 51 (0x33) for IPSec Authentication Header (AH) traffic

inbound/outbound + intradomain/interdomain load balancing

這問題初看不大不了, 實情是多數狀況下, 封包只會走一條路, 以前以為這問題的解法只有 BGP + IGP (maybe RSVP) plus intradomain/interdomain的招數而已 ( 我只會router) 沒想到有另一系tricks就是傳統的link balancer L4/L7 flow based LB + NAT + ACL based link selection (Geo DB) + DNS( or GSLB) 這兩類的方案的應用場景非常不同, 第一類你如沒ASN, 也就別想了

多Wifi AP compete specturm

http://radioaccess.blogspot.tw/2013/03/the-issues-with-wi-fi-offloading.html 倒是從來沒想過這問題, 因為較light weighted/less manageability + marcocell traffic explosion, wifi offload 有了機會, 但你深究就知, 大多數現在的implementation還是以便宜取向 不過, wifi打的就是便宜, 想他做多點事真的太為難他了 http://www.tomshardware.com/picturestory/571-wi-fi-beamforming-networking.html http://www.tomshardware.com/reviews/wi-fi-performance,2985.html

網路設計的誤區

Evolution of the IP Model 這篇提到的網路設計的誤區, 下面是再提醒自己的要點(或是現在很有感覺的要點) Claim: Reachability is symmetric (*****) Claim: Multicast/broadcast is less expensive than replicated unicast Claim: The end-to-end latency of the first  packet to a destination is typical Claim: Reordering is rare Claim: Loss is rare and probabilistic, not deterministic Claim: An end-to-end path exists at a single point in time Claim: A host has only one address on one interface Claim: An address used by an application is the same as the address used for routing Claim: Packets are unmodified in transit Claim: Source addresses are not forged