[166646] in North American Network Operators' Group
Re: Reverse DNS RFCs and Recommendations
daemon@ATHENA.MIT.EDU (Masataka Ohta)
Sat Nov 2 03:15:20 2013
Date: Sat, 02 Nov 2013 16:17:48 +0900
From: Masataka Ohta <mohta@necom830.hpcl.titech.ac.jp>
To: nanog@nanog.org
In-Reply-To: <CAAAwwbV2zgqNeQ=t8mpW-xh7ZqBqqktTjYaM7DQue7sSGobZEA@mail.gmail.com>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
Jimmy Hess wrote:
> The trouble with end-to-end encryption as a solution; is the
> difficulty/impossibility of establishing ipsec SAs with arbitrary
> hosts on the internet; without manual pre-configuration of every pair of
> hosts.
In this case, the ISP and the CPE are physically and directly
connected with modest security, which makes automation possible.
Masataka Ohta