Exploring SDN Based Firewall and NAPT: A Comparative Analysis with Iptables and OVS in Mininet

被引:0
作者
Monir, Md Fahad [1 ]
Hasan, Azwad Fawad [1 ]
机构
[1] Independent Univ, Dept Comp Sci & Engn, Dhaka, Bangladesh
来源
ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 4, AINA 2024 | 2024年 / 202卷
关键词
Open vSwitch; OVS Firewall; NAPT; iptables; Mininet; OpenFlow; Jitter; Packet Loss;
D O I
10.1007/978-3-031-57916-5_37
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In recent years, Software-Defined Networking (SDN) has emerged as a transformative paradigm for managing and controlling computer networks while offering enhanced flexibility and scalability compared to traditional networking models. SDN-driven network modules enhance business network efficiency, aid in experimental network studies, simplify network management and automation, and improve the reliability and speed of the internet in daily use. In this study, we implemented Open vSwitch (OVS) controller-based SDN networking modules in Mininet and assessed their performance, with particular emphasis on packet loss and jitter. Network Address Port Translation (NAPT) middleware, OVS controller-based firewalls, and a mix of both in a single middleware were implemented in networking modules and tested with different networking policies. A comparative analysis was conducted between iptables and OVS policies to understand their different effects on packet loss and jitter. The objective of this research was to investigate the performance differences between various SDN-based network module types-in this case, OVS-based modules. The results indicate that multiple OVS policies increase packet loss and jitter, whereas iptables exhibit better performance. This study also provides insights into the trade-offs between OVS and iptables in SDN middleware, highlighting the scope for optimization in future research.
引用
收藏
页码:436 / 447
页数:12
相关论文
共 14 条
[1]  
[Anonymous], MININET INSTANT VIRT
[2]  
Badotra Sumit, 2019, Innovations in Computer Science and Engineering. Proceedings of the Fifth ICICSE 2017. Lecture Notes in Networks and Systems (LNNS 32), P95, DOI 10.1007/978-981-10-8201-6_11
[3]   Is Mininet the right solution for an SDN testbed? [J].
Flauzac, Olivier ;
Gallegos Robledo, Erick Mauricio ;
Nolot, Florent .
2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
[4]   A Comparative Study of Software Defined Networking Controllers Using Mininet [J].
Gupta, Neelam ;
Maashi, Mashael S. ;
Tanwar, Sarvesh ;
Badotra, Sumit ;
Aljebreen, Mohammed ;
Bharany, Salil .
ELECTRONICS, 2022, 11 (17)
[5]  
Hardin B., 2023, Int. J. Future Comput. Commun., V12
[6]   A Proposed Multi-Layer Firewall to Improve the Security of Software Defined Networks [J].
Hussein M.A. .
International Journal of Interactive Mobile Technologies, 2023, 17 (02) :153-165
[7]  
Keerthana B., 2022, Expert Clouds and Applications: Proceedings of ICOECA 2021. Lecture Notes in Networks and Systems (209), P297, DOI 10.1007/978-981-16-2126-0_26
[8]   The Optimization and Implementation of Iptables Rules Set on linux [J].
Xuan, Lei-fei ;
Wu, Pei-fei .
2015 2ND INTERNATIONAL CONFERENCE ON INFORMATION SCIENCE AND CONTROL ENGINEERING ICISCE 2015, 2015, :990-993
[9]  
Monir Md Fahad, 2020, 2020 IEEE Region 10 Conference (TENCON), P991, DOI 10.1109/TENCON50793.2020.9293713
[10]   Implementation of a Click Based IDS on SDN-NFV Architecture and Performance Evaluation [J].
Monir, Md. Fahad ;
Uddin, Ryhan ;
Pan, Dan .
2021 IEEE INTERNATIONAL BLACK SEA CONFERENCE ON COMMUNICATIONS AND NETWORKING (IEEE BLACKSEACOM), 2021, :49-54