<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Ipsec on Aaron&#39;s Worthless Words</title>
    <link>https://efb97021.aww-3cz.pages.dev/tags/ipsec/</link>
    <description>Recent content in Ipsec on Aaron&#39;s Worthless Words</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Fri, 23 Dec 2011 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://efb97021.aww-3cz.pages.dev/tags/ipsec/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Junos - VPN Hierarchy</title>
      <link>https://efb97021.aww-3cz.pages.dev/posts/2011/12/junos-vpn-hierarchy/</link>
      <pubDate>Fri, 23 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://efb97021.aww-3cz.pages.dev/posts/2011/12/junos-vpn-hierarchy/</guid>
      <description>&lt;p&gt;Wow! A Junos post! Amazing.&lt;/p&gt;&#xA;&lt;p&gt;We all know that the configuration on a Junos box is very hierarchical. Sometimes it doesn&amp;rsquo;t make a lot of sense, but it&amp;rsquo;s all a pretty cascade of code. One of the big messes that I&amp;rsquo;ve found is the VPN configuration hierarchy; there are way more items to configure than on an IOS device.  To reinforce the stpes in my head, I thought I&amp;rsquo;d get some of the pieces into a post. These aren&amp;rsquo;t all the options, but it&amp;rsquo;s all you need to get a static IPSec tunnel up and running.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VRF-Aware IPSec Tunnels</title>
      <link>https://efb97021.aww-3cz.pages.dev/posts/2011/12/vrf-aware-ipsec-tunnels/</link>
      <pubDate>Tue, 13 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://efb97021.aww-3cz.pages.dev/posts/2011/12/vrf-aware-ipsec-tunnels/</guid>
      <description>&lt;p&gt;Man, time is hard to come by of late.  I&amp;rsquo;ve had so little time to rest that&amp;rsquo;s it&amp;rsquo;s hard to get my thoughts together.  It&amp;rsquo;s a good thing in this case, though, since it&amp;rsquo;s my fantastic job that&amp;rsquo;s taking all my time.  It&amp;rsquo;s great to see new network and learn their internals&amp;hellip;especially when they were designed by some long-time CCIEs who actually knew what they were doing.&lt;/p&gt;&#xA;&lt;p&gt;One of the big things that I&amp;rsquo;m dealing with lately is VRFs.  I&amp;rsquo;ve implemented some VRF-lite stuff, but I&amp;rsquo;ve never had any practical experience with the full force of them.  I&amp;rsquo;m definitely learning here.  Since the blog here is really about my sharing what I&amp;rsquo;ve learned, let&amp;rsquo;s go through something that came up recently - terminating VPNs on one VRF while passing traffic to another.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Network Protocol Overhead</title>
      <link>https://efb97021.aww-3cz.pages.dev/posts/2011/01/network-protocol-overhead/</link>
      <pubDate>Mon, 10 Jan 2011 00:00:00 +0000</pubDate>
      <guid>https://efb97021.aww-3cz.pages.dev/posts/2011/01/network-protocol-overhead/</guid>
      <description>&lt;p&gt;Here are some packet overhead numbers for a few popular protocols to help with doing bandwidth requirement calculations.  This may be another add-as-we-go post, so please comment with additions or corrections.&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Ethernet : 20 bytes&lt;br&gt;&#xA;Frame Relay : 4 - 6 bytes&lt;br&gt;&#xA;PPP : 6 bytes&lt;br&gt;&#xA;MLPPP: 10 bytes&lt;br&gt;&#xA;MPLS : 4 bytes&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;IP : 20 bytes&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;TCP : 20+ bytes&lt;br&gt;&#xA;UDP : 8 bytes&lt;br&gt;&#xA;GRE:  4 - 20+ bytes&lt;/p&gt;</description>
    </item>
    <item>
      <title>Stubby Post - A Story on VPN Hardware Acceleration</title>
      <link>https://efb97021.aww-3cz.pages.dev/posts/2010/11/stubby-post-a-story-on-vpn-hardware-acceleration/</link>
      <pubDate>Mon, 01 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://efb97021.aww-3cz.pages.dev/posts/2010/11/stubby-post-a-story-on-vpn-hardware-acceleration/</guid>
      <description>&lt;p&gt;We use a hosted application that requires IPSec tunnels to the provider from different properties across the country.  The ones in the lower 48 perform adequately, but the new one in Alaska is absolutely horrible. &lt;/p&gt;</description>
    </item>
  </channel>
</rss>
