I've been following this discussion with some interest, not only would
SIP-TLS help with security (SRTP is useless without key handling), but
it seems to improve the amount of calls per second due to TCP being able
to respond more quickly to lost packets.

-- 

Best regards,
  Duane

http://www.cacert.org - Free Security Certificates
http://www.nodedb.com - Think globally, network locally
http://www.sydneywireless.com - Telecommunications Freedom
http://e164.org - Because e164.arpa is a tax on VoIP

"In the long run the pessimist may be proved right,
     but the optimist has a better time on the trip."
--- Begin Message ---

Klaus, first of all thank you for producing some real results we can discuss. Just to validate some of your results - this is not the first time I have seen performance results where TLS (or more specifically TCP) has better performance that UDP. I have seen this on other products too and when I think about it, it is not that surprising.

Cullen


On Jul 24, 2006, at 10:59 AM, Klaus Darilion wrote:

Hi!

I made some tests with sipp+openser:

scenario:

UAC <-TLS-> openser <-TLS-> UAS (all of them got its own 2xP3 1,26GHz machine, linked with 100MBit). Simple forwarding configuration (like a loadbalancer), no DNS lookups or DB queries.

UDP: ~620 cps
TLS: ~680 cps (single TLS connection)

cps=calls per second = INVITE-180-200-OK-ACK-BYE-200

I think TLS performs better as because of UDP retransmissions, which "kills" the proxy if it becomes slow.

More data when I have it.

regards
klaus

_______________________________________________
Speermint mailing list
[EMAIL PROTECTED]
https://www1.ietf.org/mailman/listinfo/speermint

_______________________________________________
Speermint mailing list
[EMAIL PROTECTED]
https://www1.ietf.org/mailman/listinfo/speermint

--- End Message ---
_______________________________________________
--Bandwidth and Colocation provided by Easynews.com --

Asterisk-Security mailing list
To UNSUBSCRIBE or update options visit:
   http://lists.digium.com/mailman/listinfo/asterisk-security

Reply via email to