Re: The ultimate TOE design

From: Michael Richardson
Date: Wed Sep 15 2004 - 16:31:41 EST


-----BEGIN PGP SIGNED MESSAGE-----


>>>>> "David" == David S Miller <davem@xxxxxxxxxxxxx> writes:
>> The point was more to show people who are doing TOE _anyway_ to a decent
>> design.

David> We shouldn't be forced to refine people's non-sensible ideas which
David> we'll not support anyways.

David> If TOE is supported on Windows only, I happily welcome that.

Ha. Too hard to do :-)

The TOEs and L7 content switches that I know of are supported...
UNDER LINUX ONLY

The one that I'm most familliar with (Seaway's SW5000/NCA2000)
provides a new socket family to the host, which corresponds to streams
that terminate on the NCA2000. The host can request things like having
two TCP streams be cross-connected, even adding/subtracting SSL along
the way.

This code does not interact with the Linux IP stack at all --- so it
isn't exactly a TOE. You have to, at a minimum recompile applications.

- --
] "Elmo went to the wrong fundraiser" - The Simpson | firewalls [
] Michael Richardson, Xelerance Corporation, Ottawa, ON |net architect[
] mcr@xxxxxxxxxxxxx http://www.sandelman.ottawa.on.ca/mcr/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
Comment: Finger me for keys

iQCVAwUBQUiw3YqHRg3pndX9AQHrwQQAoK2C4btD6vk/UZ1Bv7zTgtbw/EvZuU2F
ZqPDiYfHMIsfsCYBWqLrjU2oxkkO+RgH3NOoNTJQuuVFjLlDw2pPHgH9DXaYdZy8
3To0LGdmIZR4u+mMx2WFRyYjuDM1iQ3ZbAskN5JzW3Jc77SbrJZaap1fQua5U3qg
gfNQ21OPkSI=
=+JBc
-----END PGP SIGNATURE-----
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/