On 5/31/07, Darren J Moffat <[EMAIL PROTECTED]> wrote:
Since you are doing iSCSI and may not be running ZFS on the initiator
(client) then I highly recommend that you run with IPsec using at least
AH (or ESP with Authentication) to protect the transport.  Don't assume
that your network is reliable.  ZFS won't help you here if it isn't
running on the iSCSI initiator, and even if it is it would need two
targets to be able to repair.

If you don't intend to encrypt the iSCSI headers / payloads, why not
just use the header and data digests that are part of the iSCSI
protocol?

Thanks,
- Ryan
--
UNIX Administrator
http://prefetch.net
_______________________________________________
zfs-discuss mailing list
zfs-discuss@opensolaris.org
http://mail.opensolaris.org/mailman/listinfo/zfs-discuss

Reply via email to