Evaluation of TCP State Replication Methods for High-Availability Firewall Clusters

被引:2
作者
Feng, Yi-Hsuan [1 ]
Huang, Nen-Fu [1 ]
Wu, Yen-Min [1 ]
机构
[1] Natl Tsing Hua Univ, Dept Comp Sci, Hsinchu, Taiwan
来源
GLOBECOM 2008 - 2008 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE | 2008年
关键词
firewall; state replication; high availability; failover;
D O I
10.1109/GLOCOM.2008.ECP.389
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
To provide the reliable connectivity between two endpoints over the Internet, a firewall cluster for stateful high availability removes the single-point failure by replicating and maintaining TCP connection states to a backup firewall node, at the expense of the costs of network and system resources. In this paper, through trace-based simulations on a prototype implementation, we evaluate the overheads of different state replication methods with a tunable time-triggering parameter. Our evaluation results show that the overheads of precise replication are very high, especially for short flows. We find that a compact data structure employing randomization, a small delay on the replication operations, and host-level aggregation yield significant overhead reductions. Typically, the policy of delayed replication reducing 50% and 74.4% of bandwidth costs only excludes 1.9% and 3.4% of the protection on the pass-through traffic, respectively. These schemes and policies are efficient for alleviating peak system load, reducing the replication bandwidth consumption and still protecting the majority of Internet traffic bytes.
引用
收藏
页数:6
相关论文
共 25 条
  • [1] Client-transparent fault-tolerant Web service
    Aghdaie, N
    Tamir, Y
    [J]. CONFERENCE PROCEEDINGS OF THE 2001 IEEE INTERNATIONAL PERFORMANCE, COMPUTING, AND COMMUNICATIONS CONFERENCE, 2001, : 209 - 216
  • [2] ALLMAN M, 2000, ACM COMPUTER COM OCT
  • [3] Alvisi L, 2001, IEEE INFOCOM SER, P329, DOI 10.1109/INFCOM.2001.916715
  • [4] Boutremans C, 2002, P 12 INT WORKSH NETW, P63
  • [5] Understanding Internet traffic streams: Dragonflies and tortoises
    Brownlee, N
    Claffy, KC
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2002, 40 (10) : 110 - 117
  • [6] DAHLIN M, 2003, IEEE ACM T NETWORKIN
  • [7] FENG YH, 2007, IEEE ICC 2007 JUN
  • [8] Hernández-Campos F, 2003, PROCEEDINGS OF THE 11TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON MODELING, ANALYSIS AND SIMULATION OF COMPUTER TELECOMMUNICATIONS SYSTEMS, P16
  • [9] Hinden R., 2004, 3768 RFC
  • [10] KATZ D, 2005, BIDIRECTION IN PRESS