Re: [PATCH] 802.1p priority (fixed)

From: Brooks Davis (brooks_at_one-eyed-alien.net)
Date: 01/22/05

  • Next message: Ingo: "Re: [PATCH] 802.1p priority (fixed)"
    Date: Fri, 21 Jan 2005 15:07:26 -0800
    To: Ingo <chaoztc@confusion.at>
    
    
    

    On Sat, Jan 22, 2005 at 12:01:10AM +0100, Ingo wrote:
    > Hi,
    >
    > > My concern is that 802.1p is like the TOS bits in that it differentiates
    > > packets within a network rather then segregating them in to networks
    > > like 802.1Q. In a switch it makes sense to handle priorities as separate
    > > networks, but I'm not sure it makes sense in a host. If nothing else,
    > > it seems to make sense to be able to set priorities on vlan encapsulated
    > > frames.
    >
    > In an Isp backbone I trust 802.1Q packets because no customer has access
    > to tagged vlan connections.
    > Trusting in TOS bit is in such a network no good idea because every
    > customer could send IP traffic. And overwriting the TOS bit at all network
    > edges could be a pain to not miss some edges.
    > 802.1Q is some kind of "out of band" QOS for IP.
    >
    > L2 Ethernet switches could also handle 802.1Q but not the TOS bits in the
    > IP header.

    I'm not sure what your point is. It's certaintly the case that they are
    only useful if you trust all hosts on the ethernet.

    -- Brooks

    -- 
    Any statement of the form "X is the one, true Y" is FALSE.
    PGP fingerprint 655D 519C 26A7 82E7 2529  9BF0 5D8E 8BE9 F238 1AD4
    
    



  • Next message: Ingo: "Re: [PATCH] 802.1p priority (fixed)"

    Relevant Pages

    • Re: Ethernet issue: works one way but not another
      ... packets transmitted, 5 packets received, 0% packet loss ... (This is when connected directly to internet through ... FBSD, I have been working with BSDI at the isp I work for for the last ... As for my network topology, I have an internal network that goes ...
      (freebsd-questions)
    • Re: Update: UDP 770 Potential Worm
      ... > the network immediately after the 'attack', ... were no packets indicating some form of replication. ... I noticed that the UDP ... > of the UDP datagrams is the IP address of the proxy? ...
      (Incidents)
    • Re: IDSIPS that can handle one Gig
      ... especially with 64-byte UDP packets. ... There are plenty of network IPS's ... IDS/IPS devices through use of fragments. ... Find out quickly and easily by testing it with real-world attacks from ...
      (Focus-IDS)
    • Re: iptables and dhcp
      ... > the same physical network segment as the firewall and the remote DHCP ... You used INPUT and not FORWARD chain ... # This target allows packets to be marked in the mangle table ...
      (comp.os.linux.networking)
    • Re: Update: UDP 770 Potential Worm
      ... > were no packets indicating some form of replication. ... > my capture was limited due to the switched ... to see if the problem occurs on the test network, ... The proxy had already been isolated from the ...
      (Incidents)