4 ms·
Because... • TCP-in-TCP (or ${ANY_RELIABLE_STREAM}-in-${ANY_RELIABLE_STREAM}) performs very poorly in the face of packet loss. • SSH itself becomes a bottlene
by rwg 13y ago
Because...
• TCP-in-TCP (or ${ANY_RELIABLE_STREAM}-in-${ANY_RELIABLE_STREAM}) performs very poorly in the face of packet loss.
• SSH itself becomes a bottleneck on networks with a large bandwidth-delay product because of statically sized buffers in the client and server. (Though there's been some work done in OpenSSH to mitigate that.)
• "Real" VPN software generally has niceties like MSS mangling TCP connections inside the tunnel to help prevent fragmentation of the encapsulated packets due to VPN overhead.
SSH is great when you need a quick and dirty tunnel (I use it in SOCKS mode a fair bit), but it's not something I'd want to use for long-lived tunnels that will see a lot of data.