Title :
FT-FW: Efficient Connection Failover in Cluster-based Stateful Firewalls
Author :
Neira, P. ; Gasca, R.M. ; Lefèvre, L.
Author_Institution :
ETS Ing. Inf., Seville
Abstract :
Stateful firewalls are security solutions widely deployed in the Internet. These devices filter network traffic and keep track of the state of connections in order to make the deployment of several attacks, such as TCP resets, difficult. However, firewalls are critical equipments in the network schema since they introduce a single point of failure. Therefore, a failure may isolate networks, users and interrupt established connections. Current fault tolerant solutions mask failures by means of replication techniques based on physical redundancy and state propagation. However, these solutions do not suit well for stateful firewall scenarios since they reduce bandwidth throughput roughly, they require costful extra hardware or are stuck to wasteful and inflexible single primary-backup settings. In this work we detail FT-FW (fault tolerant firewall), a software-based transparent connection failover mechanism for stateful firewalls. Our solution has a negligible impact in terms of performance, as well as the fact that quick recovery from failures and fast responses to clients are guaranteed. The architecture is suitable for low cost off-the-shelf systems and no extra hardware is required.
Keywords :
Internet; authorisation; fault tolerant computing; telecommunication security; Internet; cluster-based stateful firewall; fault tolerant firewall; inflexible single primary-backup settings; network traffic filtering; security solutions; software-based transparent connection failover; Bandwidth; Costs; Fault tolerance; Hardware; Information filtering; Information filters; Internet; Redundancy; Telecommunication traffic; Throughput; fault tolerant; firewall; stateful;
Conference_Titel :
Parallel, Distributed and Network-Based Processing, 2008. PDP 2008. 16th Euromicro Conference on
Conference_Location :
Toulouse
Print_ISBN :
978-0-7695-3089-5
DOI :
10.1109/PDP.2008.87