題名: Packet-Based Load Balancing Scheme for Scalable Clustered IPsec Gateways
作者: Shiuhpyng Shieh;Fu-Yuan Lee
貢獻者: Department of Computer Science and Information Engineering, National Chiao Tung University
關鍵詞: IPsec;clustering technology;security gateway 日期: 2002-05-16
上傳時間: 2009-12-08T07:38:29Z 出版者: 亞洲大學
摘要: Due to the increasing demand of secure communications over the Internet, IPsec gateway becomes one of the popular methods to provide security services to all clients in a protected subnet. The processing speed of an IPsec gateway is critical to the overall network throughput.
To accelerate processing speed and improve reliability, clustering technology was inherently applied to the design of a modern IPsec gateway. With the proposed clustered architecture, the speed of IPsec gateway increases drastically, but the packet out-of-order syndrome in the anti-replay window of IPsec protocol deteriorates. To cope with the problem, we present a packet-based load-balancing scheme for the clustered IPsec gateway, which provides even load-sharing capability and alleviates IPsec packet out-of-order syndrome. As the experiment results show, the proposed clustered architecture provides better performance and can scale up easily.