Why would anyone use Authentication Header in a transform set ?

I came across a configuration that uses an IPSEC transform-set of ah-sha-hmac esp-3des.  This is a Cisco router, and it is running inside an MPLS tunnel.  Since ESP does all of what AH does, are there any good reasons to use AH?

Most cases I've seen for IPSec on MPLS are due to being prudent about trusting the service provider. Others want to deploy technologies like DMVPN over MPLS to maintain discreet internal routing between sites without having to get the service provider involved for changes in how traffic flows.
In the first case, it's usually GET VPN that is used to provide a blanket encryption policy over the entire MPLS VRF. In the second, encryption sometimes isn't used at all.
When it comes to running this sort of thing, the decision isn't usually made due to technical factors. It's more about policy.

Similar Messages

  • Why would anyone use gstreamer legacy? and Firefox x264 HTML5 support

    https://wiki.archlinux.org/index.php/Gstreamer
    The wiki says gstreamer legacy is... "Legacy but widely used". On top of that every single linux tutorial on gstreamer I've seen talks about gstreamer0.10 i.e. the legacy one. Including the arch wiki page on Firefox H264 https://wiki.archlinux.org/index.php/Fi … 4_playback Can I rely on the following setup?
    gst-libav 1.2.3-1
    gst-plugins-bad 1.2.3-2
    gst-plugins-base 1.2.3-1
    gst-plugins-base-libs 1.2.3-1
    gst-plugins-good 1.2.3-2
    gst-plugins-ugly 1.2.3-2
    gst-vaapi 0.5.8-1
    gstreamer 1.2.3-1
    What is the required set to enable Firefox H264 support? Should I uninstall all *0.10* packages if I use the current version of gstreamer?
    Last edited by bbarcher (2014-03-31 18:18:28)

    So, should I remove all 1.0 packages if I plan on enabling HTML5 video for Firefox using 0.10?
    When I tried to leave only gstreamer 0.10 components I got an error:
    pacman -R gst-libav gst-plugins-bad gst-plugins-base gst-plugins-base-libs gst-plugins-good gst-plugins-ugly gst-vaapi gstreamer
    checking dependencies...
    error: failed to prepare transaction (could not satisfy dependencies)
    :: brasero: requires gst-plugins-good
    :: cheese: requires gstreamer
    :: cheese: requires gst-plugins-bad
    :: cheese: requires gst-plugins-base
    :: cheese: requires gst-plugins-good
    :: clutter-gst: requires gst-plugins-base-libs
    :: clutter-gst: requires gst-plugins-bad
    :: farstream: requires gst-plugins-base-libs
    :: gnome-getting-started-docs: requires gst-plugins-base
    :: gnome-getting-started-docs: requires gst-plugins-good
    :: gnome-shell: requires gstreamer
    :: gupnp-dlna: requires gst-plugins-base-libs
    :: libdmapsharing: requires gst-plugins-base-libs
    :: totem: requires gst-plugins-base
    :: totem: requires gst-plugins-good
    :: totem: requires gst-plugins-bad
    :: webkitgtk: requires gst-plugins-base-libs
    :: webkitgtk2: requires gst-plugins-base-libs
    Last edited by bbarcher (2014-04-01 17:06:44)

  • Why would anyone want to use ASM Clustered File system?

    DB Version: 11gR2
    OS : Solaris, AIX, HP-UX
    I've read about the new feature ACFS.
    http://www.oracle-base.com/articles/11g/ACFS_11gR2.php
    But why would anyone want to store database binaries in a separate Filesystem created by Oracle?

    Hi Vitamind,
    how do these binaries interact with the CPU when they want something to be done?
    ACFS should work with Local OS (Solaris) to communicate with the CPU . Isn't this kind of double work?ACFS dont work with .... but provide filesystem to Local S.O
    There may be extra work, but that's because there are more resources that a common filesystem.
    Oracle ACFS executes on operating system platforms as a native file system technology supporting native operating system file system application programming interfaces (APIs).
    ACFS is a general purpose POSIX compliant cluster file system. Being POSIX compliant, all operating system utilities we use with ext3 and other file systems can also be used with Oracle ACFS given it belongs to the same family of related standards.
    ACFS Driver Model
    An Oracle ACFS file system is installed as a dynamically loadable vendor operating system (OS) file system driver and tool set that is developed for each supported operating system platform. The driver is implemented as a Virtual File System (VFS) and processes all file and directory operations directed to a specific file system.
    It makes sense you use the ACFS if you use some of the features below:
    • Oracle RAC / RAC ONE NODE
    • Oracle ACFS Snapshots
    • Oracle ASM Dynamic Volume Manager
    • Cluster Filesystem for regular files
    ACFS Use Cases
    • Shared Oracle DB home
    • Other “file system” data
    • External tables, data loads, data extracts
    • BFILES and other data customer chooses not to store in db
    • Log files (consolidates access)
    • Test environments
    • Copy back a previous snapshot after testing
    • Backups
    • Snapshot file system for point-intime backups
    • General purpose local or cluster file system
    • Leverage ASM manageability
    Note : Oracle ACFS file systems cannot be used for an Oracle base directory or an Oracle grid infrastructure home that contains the software for Oracle Clusterware, Oracle ASM, Oracle ACFS, and Oracle ADVM components.
    Regards,
    Levi Pereira

  • HT4221 I really want my Apple TV, iPad and iPhone to sort them in date taken like in iPhoto on my iMac. How do I do that? Sorting on date modified seems so stupid to me, why would anyone need this? Date taken gives a timeline in your event.

    I really want my Apple TV, iPad and iPhone to sort them in date taken like in iPhoto on my iMac. How do I do that? Sorting on date modified seems so stupid to me, why would anyone need this? Date taken gives a timeline in your event.

    The unix commands you need are:
    GetFileInfo
    SetFileInfo
    and maybe find
    for cryptic details use the man command
    Macintosh-HD -> Applications -> Utilities -> Terminal
    man SetFileInfo
    You may use the SetFileInfo command to set the file type & the program which will open the file.
    # This little gem will do a get info on all files in a directory.
    mac $ ls  | xargs -I {} GetFileInfo "{}"
    file: "/Users/mac/playdoc/oddadocodd"
    type: ""
    creator: ""
    attributes: avbstclinmedz
    created: 05/01/2011 14:53:22
    modified: 05/01/2011 14:53:22
    file: "/Users/mac/playdoc/one.docx"
    type: ""
    creator: ""
    attributes: avbstclinmedz
    created: 05/01/2011 13:57:48
    modified: 05/01/2011 13:57:48
    file: "/Users/mac/playdoc/oneLineFile"
    type: "TEXT"
    creator: "!Rch"
    attributes: avbstclinmedz
    created: 05/07/2011 14:27:17
    modified: 05/07/2011 14:27:17
    file: "/Users/mac/playdoc/oneLineFile.txt"
    type: "TEXT"
    creator: "!Rch"
    attributes: avbstclinmedz
    created: 05/07/2011 14:27:49
    modified: 05/07/2011 14:27:49
    file: "/Users/mac/playdoc/three.docx"
    type: ""
    creator: ""
    attributes: avbstclinmedz
    created: 05/01/2011 13:58:03
    modified: 05/01/2011 13:58:03
    file: "/Users/mac/playdoc/two.docx"
    type: ""
    creator: ""
    attributes: avbstclinmedz
    created: 05/01/2011 13:57:56
    modified: 05/01/2011 13:57:56
    file: "/Users/mac/playdoc/weirder.doc.docx"
    type: ""
    creator: ""
    attributes: avbstclinmedz
    created: 05/01/2011 14:50:03
    modified: 05/01/2011 14:50:03
    # well, ! is a funnie character so we escape it.
    mac $ SetFile -t TEXT -c \!Rch two.docx
    mac $ GetFileInfo two.docx
    file: "/Users/mac/playdoc/two.docx"
    type: "TEXT"
    creator: "!Rch"
    attributes: avbstclinmedz
    created: 05/01/2011 13:57:56
    modified: 05/01/2011 13:57:56
    mac $
    mac $ date
    Sat May  7 14:40:56 EDT 2011
    mac $

  • Why would anyone buy these products that don't work with Win 8?

    Why would anyone buy these products that do not work with Win8?

    What are you referring to? If you have specific problems, explain them. Otherwise there's no point in posting false generalizations.
    Mylenium

  • I first thought the Ipad would be used by my wife so I set up her email account.  She didn't use it that much so I did and set up my accounts and took her off.  Now when I send an email it shows her address as the sending party - how do I fix this

    I first thought the Ipad would be used by my wife so I set up her email account.  She didn't use it that much so I did and set up my accounts and took her off.  Now when I send an email it shows her address as the sending party (some of the time and I don't know why only some of the time) - how do I fix this

    Have a look here...
    http://macmost.com/setting-up-multiple-ios-devices-for-messages-and-facetime.htm l
    SHARING iTunes MUSIC
    http://macmost.com/five-ways-to-share-music-in-itunes.html
    Also... Create your Own Apple ID for Your iPhone...
    It should be Noted that anything Downloaded with a Particular Apple ID is tied to that Apple ID and Cannot be Merged or Transferred to a Different Apple ID
    Apple ID FAQs  >  http://support.apple.com/kb/HT5622
    And... Have a read here...
    https://discussions.apple.com/message/18409815?ac_cid=ha
    See Here for  >  How to Use Multiple iDevices with One Computer
    Have a read here...
    https://discussions.apple.com/message/18409815?ac_cid=ha

  • Why would anyone not use VBR?

    FYI, I'm not an audio guru, and while I don't use the best audio equipment, I also don't buy the cheapest stuff out there.
    All that aside, my question to the many very knowledgeable people here is: why would someone not want to check the VBR option when encoding?

    Brenton Bills wrote:
    FYI, I'm not an audio guru, and while I don't use the best audio equipment, I also don't buy the cheapest stuff out there.
    All that aside, my question to the many very knowledgeable people here is: why would someone not want to check the VBR option when encoding?
    Because it can sometimes interfere with importing for one and not everyone can appreciate the difference.

  • Why would you use a managed service account rather than a virtual account in SQL Server 2012?

    In SQL Server 2012, service accounts are created as
    virtual accounts (VAs), as described
    here, as opposed to
    managed service accounts (MSAs).
    The important differences I can see for these, based on the descriptions:
    MSAs are domain accounts, VAs are local accounts
    MSAs use automagic password management handled by AD, VAs have no passwords
    in a Kerberos context, MSAs register SPNs automatically, VAs do not
    Are there any other differences? If Kerberos is not in use, why would a DBA ever prefer an MSA?
    UPDATE:
    Another user has noted a
    possible contradiction in the MS docs concerning VAs:
    The virtual account is auto-managed, and the virtual account can access the network
    in a domain environment.
    versus
    Virtual accounts cannot be authenticated to a remote location. All virtual accounts
    use the permission of machine account. Provision the machine account in the format
    <domain_name>\<computer_name>$.
    What is the "machine account"? How/when/why does it get "provisioned"? What is the difference between "accessing the network in a domain environment" and "authenticating to a remote location [in a domain environment]"?

    Hi,
    “Virtual accounts cannot be authenticated to a remote location. All virtual accounts use the permission of machine account. Provision the machine account in the format <domain_name>\<computer_name>$.”
    “The virtual account is auto-managed, and the virtual account can access the network in a domain environment. If the default value is used for the service accounts during SQL Server setup on Windows Server 2008 R2 or Windows 7, a virtual account
    using the instance name as the service name is used, in the format NT SERVICE\<SERVICENAME>”
    Per the above description, they are two concepts and not conflict with each other.
    As you understand, virtual account access network resources by using the credentials of the computer account. Generally, computer account will not be granted permission unless giving the computer account permission on the shared folder manually.
    Thanks.
    Tracy Cai
    TechNet Community Support

  • Why would I use Pages if I have to buy Endnote when Word will let me cite for free?

    Since buying my first Mac, I am trying to switch to all Apple software.  I have Office 365, but wanted to begin using Pages. However, the only way I have found to cite sources for my reseach papers is to purchase an Endnote program which is like $300.  Why would I do that? In Word, I can create a Works Cited library and cite while I type the paper. It is included in Word.  Pages is usless to me if I cannot cite sources.  Am I missing something?

    Word/Pages issue aside, your new MBA should NOT have difficulty connecting or staying connected to the Internet.  If you have an opportunitiy, you should make a genius bar appointment if you have an Apple Retail store nearby to have them look at the MBA.  If you have had the computer for less than 90 days, it still has phone support- Call applecare.  If you Purchased Apple Care protection, you have phone support for 3 years.  Use the resources.
         I won't comment on software, but the MBA SHOULD reliably connect to a WiFi network (assuming the network isn't the issue).
    Make a Genius Bar Reservation (or cancel an existing reservation)
    http://www.apple.com/retail/geniusbar/
    Sign in using your Apple ID

  • How/why would I use iTunes app on iPhone?

    I enjoy using my iPod app on my iPhone, and regularly sync it with iTunes on my MacBook. Works great.
    What confuses me is the iTunes icon on the home screen of my iPhone. What's it for? When would I use it? How does it relate to the setup of iTunes on my Mac?
    Thanks.

    What's it for?
    To buy music, videos & ringtones from the iTunes Store directly on your phone.
    When would I use it?
    When you want to buy music, videos & ringtones directly on your phone, instead of buying on your computer and then syncing them to your phone.
    How does it relate to the setup of iTunes on my Mac?
    It doesn't. It's an iPhone version of the iTunes Store section of the iTunes application on your computer.
    Have you actually tried loading it and exploring it?
    All this is explained in the manual:
    http://manuals.info.apple.com/enUS/iPhone_UserGuide.pdf
    Chapter 20

  • Why would you use JavaFX over JavaEE or JavaSE?

    Just curious why you would use FX over the others? Is it because of the GUI, and some added features, or what makes FX better?
    Also what exactly is the differences between the 3? It seems like SE is the basic, then EE is used for client-server and maybe security and such? FX seems to just have advanced GUI and stuff like that? Does anyone have a link or a list of what features are different and such?
    Thanks a lot!!!
    ~KZ
    Edited by: KonradZuse on Jul 6, 2012 8:41 AM

    KonradZuse wrote:
    I usually use swing, but I am starting a new business application for real world use, so I want it to be the best it can be. FX's Gui is great, but is it worth it to start using that right away? I also want to be able to use 3D, and as someone said you can do 2D in a 3D space, so that is basically what I need for now, but I would like to be able to do full 3D.JFX isn't exactly built to do 3D stuff right now. But neither is Java2D (the base for AWT and Swing), so nothing is different really.
    So what I really want to know is what is the differences between SE and EE?One is "Java", the other is a specification. For more information I refer to Google.

  • Why would someone use x:ClassModifier="internal" ?

    I was looking through some views and one was marked at the top with "internal".
    It's a bit confusing because isn't it internal by default?

    Nope. The other way round.
    The default for a XAML based class is Public.
    The person who wrote that page chose the VB version of syntax.
    https://msdn.microsoft.com/en-us/library/ms754029%28v=vs.110%29.aspx?f=255&MSPPError=-2147217396
    Default is:
    <object x:Class="namespace.classname" x:ClassModifier="Public">
    </object>
    Presumably what you're seeing:
    <object x:Class="namespace.classname" x:ClassModifier="Internal">
    </object>
    I can't really see why anyone would bother.  Can't recall ever seeing that used in a project I've worked on or code reviewed. There again it'd be up the top where I wouldn't usually pay much attention.
    If you're working on a project and you don't know the reason then maybe there is actually no good reason.
    Devs will sometimes see something and they use it just because they can.  I see all sorts of odd things and there's no real reason at all for using them other than "because I could".
    Hope that helps.
    Recent Technet articles: Property List Editing;
    Dynamic XAML

  • N00b query: Why would anyone ever want to define their own Exception class?

    I've been reading thru my Java textbook for the past couple hours.
    Exceptions are a wonderful thing. I already found several instances where I could've implemented try/cacth in my earlier programs.
    Anyway, getting back to the point. My question is, can someone give me a realistic situation/example where a custom Expcetion class is REQUIRED? (the key word here is "required"!)
    I can see why someone would want to have his own Exception class..... e.getMessage() as custom error messages are SO DAMN COOL!!!!!! :P
    hehe
    But seriously, if you are making intermidiate/advanced Java programs, would you ever REQUIRE to make your own Exception class? Afterall, even a custom made Exception class always "extends" from a pre-defined Java class, right?
    Let me make this a bit more clear... public class CustomException extends IOException{  }Now, if I am making a try/catch statement, I can simply say
    try{
    throw new CustomException;
    catch (IOException e) { }
    Now as you can see, the CustomException was caught by the catch claus, because IOException is the superclass of CustomException. So, in other words, the whole CustomException thingy didnt do anything useful.
    I know I know, I am so naive. Enlighten me >.<

    Sure. Say you want to have a system where you want to include a custom error code which maps to some internationalized error messages. You would create an Exception subclass with a field to hold that value separate from the normal "default" message. Then you could throw that exception in all your code. Other code can catch it as a plain Exception if they want and use the "default" message, which is okay if they don't really care about the error code.
    I don't think you are ever "required" to make your own exceptions. I have done so, but I don't often. It depends. See, there are plenty of Exception subclasses in the standard packages, and most of them cover many of the things you need. So more often if I'm throwing an exception, I'll be using the already existing ones, like IllegalArgumentException or IOException (whatever is relevant to the code).
    Yes, you can do what you did below with CustomException. However the reason you might do that is cuz you really want to do this:
    try {
       // call some code that may throw IOException from some standard IO package
       // or may throw CustomException from some of my methods...
    } catch (CustomException ce) {
       // handle cusotm exception
    } catch (IOException ioe) {
       // handle IO exception
    }Cuz you may want to differentiate between your exceptions vs. IOExceptions that might be thrown from some java.io class.
    Usually when you use an exception class it's a named class that relates to some condition. It may hold additional information besides the standard message, but I think most of the time it's just the class name which describes the problem. And if there isn't one that describes the problem that you're code might encounter, then create a subclass.

  • HT6027 What the heck is switch control for and why would I use it?

    This doesn't begin to explain what this function is or why I would want to use it. What would it do for me exactly? "Switch Control helps you navigate your Mac using switches to enter text, interact with various items on the screen, play games, and ..."

    Switch Control is a feature that enables users with fine motor impairments to access their iPhone, iPod touch, or iPad through the use of one or more switches. Switch Control highlights items and item groups one by one on the device screen. To make a selection, the user activates a switch when the desired item or item group is highlighted.
    iOS: Using Switch Control - Support - Apple

  • Why would you use Java over C/C++

    This thread :
    http://forum.java.sun.com/thread.jspa?threadID=689490
    Brought back to mind a problem I had in the first C program I worked on -
    I'd declared an array and a file pointer on the stack in a function, overwrote the end of the array by mistake, and trashed the file pointer. The file pointer was used a while after the array was overwritten - took me 2 days to work out what was happening. Array overwrites like this are just not possible in Java - that's a reason to use Java over C or C++.
    Anyone else got their own scare stories like this ? Maybe someone's got a Java scare story that would make you use C ?

    A C++ based bond trading system had the description database varchar field width of 60 characters. The GUI software to display this had buffers 60 characters wide. New bonds came along with widths of over 60 characters so the database field width was changed to 80 characters but nobody told us (the GUI maintenance team) about the change.
    There was no real problem for about 4 days after the first long named bond was inserted. Then, at random times, the GUI application would crash. It took many many days to find the source of the problem and to fix it. The blame was laid at the door of the GUI maintenance team even though we had not written the code and we had logged the potential problem in the bug database months before but management decided that it was not a problem so should not be 'fixed'.
    This literally cost millions because the traders could not be sure of their positions.
    I left as soon as my contract ran out.

Maybe you are looking for

  • Tomcat server is not running automatically

    Hi BO experts, I have installed SAP Business Objects XI 3.1 in my system and noticed that Tomcat server is not running in Central Configuration Manager where the status is "Stopped". If I start manually also it's not starting (In properties, the star

  • Projector not being outputted by iMac

    I am trying to connect a projector to my iMac (2011) and the video will not output. Is this simply because there is no cables that work with the Thunderbolt yet?

  • How to find the partition column in a partitioned table

    Hi, I have a partition table and I need to find out what column was used to partition the table. Range partition. Thanks, Maria Sanchez

  • 4th Gen scroll wheel not working

    The wheel hasn't been working for the past couple days. It shows that its charging (at this very minute) but when I click the menu, or any other button it doesn't respond. If I slide the hold button over to the left, the backlight comes on, when I sl

  • Photoshop CS3 Artistic Filters

    I am applying Artistic filters to an image in Photoshop. Some of the filters are turning the image into a black and white image, for example, the "torn edges filter." And it then does not seem possible to change that layer into a colored layer. Other