首页> 外文会议>Security Technology, Proceedings 42nd Annual 2008 International Carnahan Conference on >A practical approach for building a parallel firewall for ten gigabit Ethernet backbone
【24h】

A practical approach for building a parallel firewall for ten gigabit Ethernet backbone

机译:为十个千兆位以太网骨干网构建并行防火墙的实用方法

获取原文

摘要

In a very high-speed network environment such as gigabit Ethernet network, firewalls that have to inspect and filter all flowing packets are reaching their limits. A firewall running on a single machine is potential bottleneck and cannot scale over certain thresholds, even if it has particular hardware built-in. Hence, parallel system appears as an alternative approach under this circumstance. This paper describes a design and implementation of parallel firewall architecture that is able to handle packets for high-speed network. The implementation utilizes arrays of Linux-based firewall under data parallel scheme running incorporate with specific ASIC switch. The load balancing mechanism, using hashing of disjoint subset, distributes the traffic among a configurable number of parallel machines, providing high performance with reliability, flexibility, and scalability. Implementation and measurements in a real network show that the proposed system is scalable to handle a data rate of 10 gigabit per second.
机译:在千兆以太网等超高速网络环境中,必须检查和过滤所有流动数据包的防火墙已达到极限。在单台计算机上运行的防火墙是潜在的瓶颈,即使内置了特定的硬件,也无法超过某些阈值。因此,在这种情况下,并行系统似乎是一种替代方法。本文介绍了能够处理高速网络数据包的并行防火墙体系结构的设计和实现。该实现利用运行在数据并行方案下并结合特定ASIC交换机的基于Linux的防火墙阵列。负载平衡机制使用不连续子集的散列,在可配置数量的并行计算机之间分配流量,从而提供具有可靠性,灵活性和可伸缩性的高性能。实际网络中的实现和测量表明,所提出的系统可扩展以处理每秒10吉比特的数据速率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号