[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: GxSE & ESP/AH




> architecture for The Internet.  The right answer has always been
> to use a topologically-independent namespace for ESP/AH purposes,
> but no such namespace exists and is widely deployed today.  Note
> well that DNS does NOT work for this because a FQDN does NOT uniquely
> name a single TCP/IP stack -- instead an FQDN quite often names a
> service or content (e.g. www.cnn.com is NOT a system, but rather a
> cluster of servers with a middle box in front).
>

The fact that DNS does not *always* uniquely name a single TCP/IP stack does
not mean that it never does, and that when it does it couldn't be used to
uniquely identify the host.

Thinking off the top of my head, what you would need is for www.cnn.com type
hosts to have multiple FQDNs, at least one of them unique, and it would have
to know it was unique so that it could use it for identification.

Now I'm sure y'all have thought of this, so there must be some gotcha's in
there.  Perhaps Ran we could find some nice pub in London where you could
explain it all to me...

PF