On Wed, 22 Sep 2010, Hesham Soliman wrote:

=> But you're saying that as an operator need, when in fact your rationale
is to reduce vendor code. Is any vendor complaining about this? Is this an

Well, yes, I want to reduce vendor code and to simplify the deployment. In my deployment model there also is no dynamic happening on the ISP-WAN segment, so there is little need for ND.

There are very few vendors that support at all the SAVI L2 functions needed, I want to ease the implementation.

But yes, you're correct, this is to simplify the code so there is shorter time to market and less test cases for us to run to make sure the vendor software runs properly. I'm also hoping it'll make the devices cheaper.

I'm trying to understand where the problem is.

Multiple levels. ND is one more thing to go wrong. The less functionality needed, the easier it is for all involved. Static filtering is easier than dynamic inspection and filtering based on that. It means less punting packets to CPU in the L2 devices, less DoS vectors, less everything.

--
Mikael Abrahamsson    email: swm...@swm.pp.se
--------------------------------------------------------------------
IETF IPv6 working group mailing list
ipv6@ietf.org
Administrative Requests: https://www.ietf.org/mailman/listinfo/ipv6
--------------------------------------------------------------------

Reply via email to