[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Source address selection insufficient?
Iljitsch;
I think that this is getting more complex than necessary.
This isn't complexity invented by us; it's just reality that we have to
deal with.
It is true that routing is frequently asymmetric.
However, that is a very different statement from saying that
connectivity is asymettric.
Asymmetric routing + ingress filtering = asymmetric connectivity.
An interesting implication is that site internal routers
must use proper source address for ICMP reply to a host in
a peer site, which makes connection oriented maintenance
of source address impossible.
Of course, for those believing in NAT or connection oriented
IP layer, it is not impossible but just to make all the routers
maintain transport layer states without having any knowledge
on transport layer connectivity.
Masataka Ohta