首页> 外文会议>IEEE International Conference on Network Protocols >SDIG: Toward Software-Defined IPsec Gateway
【24h】

SDIG: Toward Software-Defined IPsec Gateway

机译:SDIG:走向软件定义的IPsec网关

获取原文

摘要

The current IPsec gateway integrates many functions of IPsec operation, tunnel management and forwarding decision, which makes the IPsec gateway complicated in maintenance and deployment. The problem of maintaining such devices prevents IPsec VPN from applying widely. The emergence of SDN provides an innovative way to decouple the control plane and data plane. In this paper, a Software-Defined IPsec Gateway (SDIG) is proposed to achieve net2net IPsec VPN. Different from the traditional IPsec gateway, the SDIG device serves as a data plane equipment that just concentrates on exchanging IKE packets and encrypting/decrypting IP packets. A global view of SDIG devices can be constructed in the SDN controller by collecting the status of all devices. Therefore the controller can manage and configure SDIG devices centrally, and simplify deployment complexity. Outbound IP packets for the SDIG device can be viewed as a trigger to control the establishment of IPsec tunnels. The SDIG device and the controller exchange information through a customized southbound protocol. The prototype system of SDIG is implemented, and the preliminary experimental results show that the method is feasible and effective.
机译:当前的IPsec网关集成了IPsec操作,隧道管理和转发决策的许多功能,这使得IPsec网关的维护和部署变得复杂。维护此类设备的问题阻止了IPsec VPN的广泛应用。 SDN的出现提供了一种创新的方式来分离控制平面和数据平面。本文提出了一种软件定义的IPsec网关(SDIG)来实现net2net IPsec VPN。与传统的IPsec网关不同,SDIG设备用作数据平面设备,仅专注于交换IKE数据包和加密/解密IP数据包。通过收集所有设备的状态,可以在SDN控制器中构造SDIG设备的全局视图。因此,控制器可以集中管理和配置SDIG设备,并简化部署复杂性。 SDIG设备的出站IP数据包可以看作是控制IPsec隧道建立的触发器。 SDIG设备和控制器通过定制的南向协议交换信息。实现了SDIG的原型系统,初步实验结果表明该方法是可行和有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号