User: Password:
|
|
Subscribe / Log in / New account

That's what dot1x is for

That's what dot1x is for

Posted Jul 15, 2012 15:31 UTC (Sun) by hummassa (subscriber, #307)
In reply to: That's what dot1x is for by Cyberax
Parent article: Cyberoam deep packet inspection and certificates

> Besides, once you implement the parallel infrastructure that actually works _better_ than your secured-down-to-the-wire IPSec network, people start asking: "Why have we even bothered with this ipsec crap?"

We deal with this limiting EXTREMELY the bandwidth and reliability of the secondary infrastructure. If you want to use a non-standard thing, pay the price.

> So that's why middlebox vendors make a killing selling various DPI tools to organizations. Sure, they violate all the possible RFCs and all the notions of protocol layering. But at the same time they actually work in RealLife(tm).

For a really wide definition of working...


(Log in to post comments)

That's what dot1x is for

Posted Jul 15, 2012 17:16 UTC (Sun) by Cyberax (✭ supporter ✭, #52523) [Link]

>We deal with this limiting EXTREMELY the bandwidth and reliability of the secondary infrastructure. If you want to use a non-standard thing, pay the price.

Nice. Increasing success by lowering expectations.

That's exactly why more and more people ditch all the 'standards compliant' crap and instead install something that is simple and stupid, but actually usable.

> For a really wide definition of working...
It gets stuff done. It doesn't annoy people. It's fairly easy to troubleshoot.

What more do you need?

That's what dot1x is for

Posted Jul 15, 2012 18:18 UTC (Sun) by hummassa (subscriber, #307) [Link]

> What more do you need?

No exposure to huge liabilities?


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds