[67158] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Strange public traceroutes return private RFC1918 addresses

daemon@ATHENA.MIT.EDU (Niels Bakker)
Tue Feb 3 14:36:51 2004

Date: Tue, 3 Feb 2004 20:34:26 +0100
From: Niels Bakker <niels=nanog@bakker.net>
To: nanog@merit.edu
Mail-Followup-To: nanog@merit.edu
In-Reply-To: <401FEBE8.7010506@he.iki.fi>
Errors-To: owner-nanog-outgoing@merit.edu



--HcAYCG3uE/tztfnV
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

> Leo Bicknell wrote:
>> because at the higher data rates (eg 40 gige) it makes a huge difference
>> in host usage.  You can fit 6 times in the data in a 9K packet that you
>> can in a 1500 byte packet, which means 1/6th the interrupts, DMA
>> transfers, ACL checks, etc, etc, etc.

* pete@he.iki.fi (Petri Helenius) [Tue 03 Feb 2004, 19:47 CET]:
> This is wrong. Interrupt moderation has been there for quite a while,=20
> DMA is chained and predictive.

Just like the extra chopping up of the data you want to send into more
packets, it's things you have to do a few extra times.  That takes time.
There is no way around this.  What Leo wrote is in no way wrong.


> ACL checks I can agree on, but if you are optimizing the system, what
> do you need ACL?s for anyway because you can make the applications
> secure in the first place?

You're trolling, right?


	-- Niels.

--=20
Blessed are the Watchmakers, for they shall inherit the earth.

--HcAYCG3uE/tztfnV
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----

iD8DBQFAH/fBr7WIsA3LmMURAhW+AJ9Lbra31xAes9C8yerQgtJ7mqUiswCeMp09
a9KlrchelzWx0T6mO6Nm8yQ=
=O11W
-----END PGP SIGNATURE-----

--HcAYCG3uE/tztfnV--

home help back first fref pref prev next nref lref last post