DocumentCode :
1825737
Title :
High availability support for the design of stateful networking equipments
Author :
Neira, P. ; Lefevre, Laurent ; Gasca, R.M.
Author_Institution :
Dept. of Languages & Syst., ETS Ingenieria Informatica, Seville, Spain
fYear :
2006
fDate :
20-22 April 2006
Abstract :
The availability of some critical equipment like gateways, firewalls and proxies must be guaranteed in operational networks. In early equipments, the routing and filtering decisions were based on the packet information, nowadays this static approach is not longer safe. Existing high availability (HA) solutions do not cover all the aspects to ensure availability of advanced settings that are being deployed these days. Some important issues like the reduction of the downtime and the need for failure detection in such scenarios must be studied. This paper describes the implementation of high available stateful network equipments: these systems apply policies based on the state of the connections, such information is gathered in runtime by means of packet inspection. This work specifically focuses on Linux systems and firewalls because the IT industry trusts more and more OpenSource solutions to deploy critical services because of its quality and the access to the source code. We propose the SNE library (stateful network equipment), which is an add-on to current HA protocols, to solve the existing limitations. In this paper, we describe the proposed architecture and we detail a set problematic scenarios supported by our library, as well as first experiments and the evaluation.
Keywords :
Linux; authorisation; computer networks; network operating systems; performance evaluation; Linux system; OpenSource solution; data security; firewall; gateway; high availability protocol; operational network; packet inspection; stateful network equipment; Availability; Information filtering; Information filters; Inspection; Laboratories; Libraries; Linux; Local area networks; Routing; Runtime; Firewall; High Availability; OpenSource; Security; Stateful;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Availability, Reliability and Security, 2006. ARES 2006. The First International Conference on
Print_ISBN :
0-7695-2567-9
Type :
conf
DOI :
10.1109/ARES.2006.71
Filename :
1625318
Link To Document :
بازگشت