首页> 外文会议>Conference on Technologies, Protocols, and Services for Next-Generation Internet Aug 21-23, 2001, Denver, USA >Constructing high-performance firewall load-balancing clusters: practical experience and novel ideas
【24h】

Constructing high-performance firewall load-balancing clusters: practical experience and novel ideas

机译:构建高性能防火墙负载平衡集群:实践经验和新颖思路

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Security and performance are probably the top two concerns of web hosting service providers. As available bandwidth of a hosting service is approaching Giga-bits-per-second, low throughput of a single firewall quickly becomes the bottleneck. Constructing a load-balancing cluster of multiple firewall devices seems to be an effective solution. In this paper, we first present a proof-of-concept firewall cluster using web load balancing switches. Our test cluster works; but has major limitations. First, the cluster set-up is too complex to be manageable in a large-scale deployment. Furthermore, the firewall cluster works only in a local area network. It does not work across the wide area network where asymmetric routing is possible. Based on these findings, we propose two novel approaches. The first approach introduces a Firewall Cluster Control Protocol (FCCP) for routers to direct network flows to the appropriate firewall device for processing. FCCP simplifies the implementation of firewall clusters by eliminating the load balancing switch requirement. The second approach, called Stateful Packet Forwarding (SPF), allows firewall devices in a cluster to discover the "owner" of a network flow when asymmetric routing occurs. SPF can be potentially used in a geographically distributed firewall cluster.
机译:安全性和性能可能是网络托管服务提供商关注的两个主要问题。随着托管服务的可用带宽接近每秒千兆位,单个防火墙的低吞吐量很快成为瓶颈。构建多个防火墙设备的负载均衡集群似乎是一种有效的解决方案。在本文中,我们首先介绍使用Web负载平衡交换机的概念验证防火墙群集。我们的测试集群有效;但有很大的局限性。首先,集群设置过于复杂,无法在大规模部署中进行管理。此外,防火墙群集仅在局域网中工作。它不适用于可能进行非对称路由的广域网。基于这些发现,我们提出了两种新颖的方法。第一种方法引入了路由器的防火墙群集控制协议(FCCP),以将网络流定向到适当的防火墙设备进行处理。通过消除负载平衡交换机要求,FCCP简化了防火墙群集的实施。第二种方法称为状态数据包转发(SPF),它允许群集中的防火墙设备在发生非对称路由时发现网络流的“所有者”。 SPF可以潜在地用于地理分布的防火墙群集中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号