[138680] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Internet Edge Router replacement - IPv6 route

daemon@ATHENA.MIT.EDU (Dobbins, Roland)
Fri Mar 11 23:34:41 2011

From: "Dobbins, Roland" <rdobbins@arbor.net>
To: nanog group <nanog@nanog.org>
Date: Sat, 12 Mar 2011 04:33:00 +0000
In-Reply-To: <AANLkTin5y+29qXh7T0mn9AuxYDB97zdP0wEMVU_4-5pK@mail.gmail.com>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org


On Mar 12, 2011, at 11:14 AM, Jeff Wheeler wrote:

> Of course, I don't really mean to call Owen a liar, or foolish, or anythi=
ng else. =20

Please don't; even though I disagree with him and agree with you very stron=
gly on this set of issues, Owen is a smart and straightforward guy, and is =
simply speaking from his (selective on this particular set of topics, IMHO)=
 own individual viewpoint.

;>

> and if the most popular fix becomes dependent on NDP inspection


If that comes to pass, then the fix will be useless, unfortunately, just as=
 dynamic ARP inspection (DAI) is useless today; it self-DoSes the box.

Any form of 'inspection' will not scale for this problem, as it will be CPU=
-bound even on ASIC-based platforms.

All this ICMPv6 weirdness and outright brokenness is the Achilles' heel of =
IPv6, and I see no ready solution in sight for the set of problems it engen=
ders.

-----------------------------------------------------------------------
Roland Dobbins <rdobbins@arbor.net> // <http://www.arbornetworks.com>

		The basis of optimism is sheer terror.

			  -- Oscar Wilde



home help back first fref pref prev next nref lref last post