High Availability for IPsec VPN Platforms: ClusterIP Evaluation - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2013

High Availability for IPsec VPN Platforms: ClusterIP Evaluation

Résumé

To manage the huge demand on traffic, the Internet Service Providers (ISP) are offloading its mobile data from Radio Access Networks (RAN) to Wireless Access Networks (WLAN). While these RANs are considered trusted networks, WLANs need to build a similar trusted zone in order to offer the same security level and Quality of Service (QoS) to End-Users (EU). Although IPsec is widely implemented to create trusted environments through untrusted networks, the industry is increasingly interested in providing IPsec-based services with High Availability (HA) features in order to ensure reliability, QoS and security. This paper concentrates on how to build a cluster of IPsec SGs based on ClusterIP. We describe the main issues to overcome HA within IPsec. Then, we measure how HA may affect the EU experience, and provide recommendations on how to deploy ClusterIP. Finally, our tests over an HTTP connection showed that ClusterIP allows fast recovering during a failure.
Fichier principal
Vignette du fichier
High_Availability_for_IPsec_VPN_Platforms-ClusterIP_Evaluation-ARES2013.pdf (821.07 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00863418 , version 1 (18-09-2013)

Identifiants

  • HAL Id : hal-00863418 , version 1

Citer

Daniel Palomares, Daniel Migault, Wolfgang Velasquez, Maryline Laurent. High Availability for IPsec VPN Platforms: ClusterIP Evaluation. 8th International Conference on Availability, Reliability and Security (ARES 2013), Sep 2013, Regensburg, Germany. pp.1. ⟨hal-00863418⟩
195 Consultations
2008 Téléchargements

Partager

Gmail Facebook X LinkedIn More