Received: by oss.sgi.com id ; Sun, 7 Jan 2001 16:31:32 -0800 Received: from lox.sandelman.ottawa.on.ca ([209.151.24.2]:63475 "EHLO lox.sandelman.ottawa.on.ca") by oss.sgi.com with ESMTP id ; Sun, 7 Jan 2001 16:31:17 -0800 Received: from nox.sandelman.ottawa.on.ca (nox.sandelman.ottawa.on.ca [209.151.24.6]) by lox.sandelman.ottawa.on.ca (8.8.7/8.8.8) with ESMTP id TAA03677 for ; Sun, 7 Jan 2001 19:31:16 -0500 (EST) Received: from sandelman.ottawa.on.ca ([63.70.211.130]) by nox.sandelman.ottawa.on.ca (8.11.0/8.11.0) with ESMTP id f080s0814712 (using TLSv1/SSLv3 with cipher EDH-RSA-DES-CBC3-SHA (168 bits) verified OK) for ; Sun, 7 Jan 2001 16:55:24 -0800 (PST) Received: from localhost (localhost [127.0.0.1]) by sandelman.ottawa.on.ca (8.11.0/8.11.0) with ESMTP id f080QE120377 for ; Sun, 7 Jan 2001 19:26:15 -0500 (EST) Message-Id: <200101080026.f080QE120377@sandelman.ottawa.on.ca> To: "netdev@oss.sgi.com" Subject: Re: routable interfaces WAS( Re: [PATCH] hashed device lookup(DoesNOT meet Linus' sumission policy!) In-reply-to: Your message of "Sun, 07 Jan 2001 13:42:05 MST." <3A58D49D.C4152BD5@candelatech.com> Mime-Version: 1.0 (generated by tm-edit 7.108) Content-Type: text/plain; charset=US-ASCII Date: Sun, 07 Jan 2001 19:26:14 -0500 From: Michael Richardson Sender: owner-netdev@oss.sgi.com Precedence: bulk Return-Path: X-Orcpt: rfc822;netdev-outgoing Content-Length: 812 Lines: 14 The nicest thing about routable interfaces (vs what FreeSWAN and many other IPsec's use now) is that it makes the choice of outgoing IP address (the one inside the tunnel) behave like all other multihoming. I think the same criteria applies to VLAN interfaces as well. My hunch is that the having a dozen VLAN/IPsec interfaces on a box may be rather reasonable. Having 4000 of them is a pretty rare situation, that can be dealt with via expansion of the hash table at compile time. ] Train travel features AC outlets with no take-off restrictions|gigabit is no[ ] Michael Richardson, Solidum Systems Oh where, oh where has|problem with[ ] mcr@solidum.com www.solidum.com the little fishy gone?|PAX.port 1100[ ] panic("Just another NetBSD/notebook using, kernel hacking, security guy"); [