Re: NAT Traversal

"Chinna N.R. Pellacuru" <pcn@cisco.com> Thu, 07 March 2002 20:17 UTC

Received: from lists.tislabs.com (portal.gw.tislabs.com [192.94.214.101]) by above.proper.com (8.11.6/8.11.3) with ESMTP id g27KHt816477; Thu, 7 Mar 2002 12:17:55 -0800 (PST)
Received: by lists.tislabs.com (8.9.1/8.9.1) id OAA28347 Thu, 7 Mar 2002 14:31:21 -0500 (EST)
Date: Thu, 07 Mar 2002 11:41:54 -0800
From: "Chinna N.R. Pellacuru" <pcn@cisco.com>
To: Derek Atkins <derek@ihtfp.com>
cc: Stephen Kent <kent@bbn.com>, ipsec mailling list <ipsec@lists.tislabs.com>
Subject: Re: NAT Traversal
In-Reply-To: <sjmadtkw6s4.fsf@kikki.mit.edu>
Message-ID: <Pine.GSO.4.33.0203071134090.11244-100000@cypher.cisco.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
Sender: owner-ipsec@lists.tislabs.com
Precedence: bulk

On 7 Mar 2002, Derek Atkins wrote:

> "Chinna N.R. Pellacuru" <pcn@cisco.com> writes:
>
> > If someone has just one IP address to use as his local endpoint, then
> > probably 64K IPsec connections is more than enough for him. That box has
> > to first be able to handle so many IPsec connections.
>
> You are missing one thing.  Yes, there is a potential to hold 64k
> connections, except by the birthday paradox you will get a hash
> collision after 256 connections.  Don't you think that 256 connections
> is too few?
>
> -derek
>

Yes, I stumped on the "birthday paradox". Thanks to Paul and you too for
pointing that out.

Hey, I haven't given out the full details of my "hash function". I think
we should be more careful and not to pick a real hash fuction :-)

A hash fuction could just be: output the last two bytes of the SPI,
assuming that the SPI was generated randomly or atleast the last two
bytes of the initiator SPI was generated randomly.

I would like to request help in coming up with a good hash function for
this specific purpose. I am still waiting on the help in general that I
requested earlier too.

    thanks,
    chinna

chinna narasimha reddy pellacuru
s/w engineer