[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Source address selection insufficient?



Iljitsch;

I think that this is getting more complex than necessary.

This isn't complexity invented by us; it's just reality that we have to deal with.

It is true that routing is frequently asymmetric.
However, that is a very different statement from saying that connectivity is asymettric.

Asymmetric routing + ingress filtering = asymmetric connectivity.

An interesting implication is that site internal routers must use proper source address for ICMP reply to a host in a peer site, which makes connection oriented maintenance of source address impossible.

Of course, for those believing in NAT or connection oriented
IP layer, it is not impossible but just to make all the routers
maintain transport layer states without having any knowledge
on transport layer connectivity.

Masataka Ohta