[90998] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: key change for TCP-MD5

daemon@ATHENA.MIT.EDU (Valdis.Kletnieks@vt.edu)
Fri Jun 23 16:49:17 2006

To: Bora Akyol <bora@broadcom.com>
Cc: "Barry Greene (bgreene)" <bgreene@cisco.com>,
	Ross Callon <rcallon@juniper.net>, nanog@merit.edu
In-Reply-To: Your message of "Fri, 23 Jun 2006 13:35:20 PDT."
             <03235919BBDE634289BB6A0758A20B3669F369@NT-SJCA-0751.brcm.ad.broadcom.com>
From: Valdis.Kletnieks@vt.edu
Date: Fri, 23 Jun 2006 16:45:33 -0400
Errors-To: owner-nanog@merit.edu


--==_Exmh_1151095533_3135P
Content-Type: text/plain; charset=us-ascii

On Fri, 23 Jun 2006 13:35:20 PDT, Bora Akyol said:

> The validity of your statement depends tremendously on how IPSEC is
> implemented.

If 113 million packets all show up at once, you're going to get DoS'ed,
whether or not you have IPSEC enabled.

--==_Exmh_1151095533_3135P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001

iD8DBQFEnFLscC3lWbTT17ARAjoSAKCiFVf83+lCLt/2KW2br7sJoBsMrQCgzrSC
msRoA9q7ZUijmRX65x1iPxE=
=dC/O
-----END PGP SIGNATURE-----

--==_Exmh_1151095533_3135P--

home help back first fref pref prev next nref lref last post