Network security on multiple levels (was Re: NYT covers China cyberthreat)

Christopher Morrow morrowc.lists at gmail.com
Thu Feb 21 16:35:03 UTC 2013


On Thu, Feb 21, 2013 at 11:23 AM, Jack Bates <jbates at brightok.net> wrote:
> On 2/21/2013 12:03 AM, Scott Weeks wrote:
>>
>> I would sure be interested in hearing about hands-on operational
>> experiences with encryptors.  Recent experiences have left me
>> with a sour taste in my mouth.  blech!
>>
>> scott
>>
>>
>
> Agreed. I've generally skipped the line side and stuck with L3 side
> encryption for the same reason.

and... some (most?) line-side encryptors light the line up fullspeed
between the encryptors... if they are also attempting to suppress
traffic analysis... so that can be costly if you don't own the whole
pipe :)




More information about the NANOG mailing list