Re: [IPsec] Teaser for pitch talk at IETF 108

2020-07-24 Thread Michael Rossberg
Wiliam, Yoav, thanks for the comments, I’ll try to elaborate in a single mail as you are heading in a similar direction. > RFC 6311 allows multiple members in a cluster of IPsec gateways to have > independent parallel SAs so as to solve the problem of synchronization and > counter re-use among

Re: [IPsec] Teaser for pitch talk at IETF 108

2020-07-24 Thread Yoav Nir
Hi, Michael. Thanks for bringing this to the group. > On 22 Jul 2020, at 13:26, Michael Rossberg > wrote: > > > We have been analyzing issues ESP has in current data-center networks and > came to > the conclusion that changes in the protocol could significantly improve its > behavior. Some

Re: [IPsec] multiple windows need multiple SPIs

2020-07-24 Thread William Allen Simpson
No firestorm on the previous message, so here's more fuel On 7/22/20 6:26 AM, Michael Rossberg wrote: * Allow multiple windows per SA to allow for scaling over CPUs, windows per QoS class & replay protection in multicast groups In the SIPP (IPv6) IPng WG, where we were d

Re: [IPsec] Teaser for pitch talk at IETF 108

2020-07-24 Thread William Allen Simpson
I was forwarded this message. As a matter of fact, I've never left the list, but very rarely read it. Speaking as one of the original designers of ESP, I'm delighted that folks are finally catching up to our original design of 25+ years ago! There's no need to rename ESP. The Security Paramete