Evaluation of TCP State Replication Methods for High-Availability Firewall Clusters

被引:2
作者
Feng, Yi-Hsuan [1 ]
Huang, Nen-Fu [1 ]
Wu, Yen-Min [1 ]
机构
[1] Natl Tsing Hua Univ, Dept Comp Sci, Hsinchu, Taiwan
来源
GLOBECOM 2008 - 2008 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE | 2008年
关键词
firewall; state replication; high availability; failover;
D O I
10.1109/GLOCOM.2008.ECP.389
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
To provide the reliable connectivity between two endpoints over the Internet, a firewall cluster for stateful high availability removes the single-point failure by replicating and maintaining TCP connection states to a backup firewall node, at the expense of the costs of network and system resources. In this paper, through trace-based simulations on a prototype implementation, we evaluate the overheads of different state replication methods with a tunable time-triggering parameter. Our evaluation results show that the overheads of precise replication are very high, especially for short flows. We find that a compact data structure employing randomization, a small delay on the replication operations, and host-level aggregation yield significant overhead reductions. Typically, the policy of delayed replication reducing 50% and 74.4% of bandwidth costs only excludes 1.9% and 3.4% of the protection on the pass-through traffic, respectively. These schemes and policies are efficient for alleviating peak system load, reducing the replication bandwidth consumption and still protecting the majority of Internet traffic bytes.
引用
收藏
页数:6
相关论文
共 25 条
  • [11] KOCH RR, 2003, P IEEE INT C DEP SYS
  • [12] Lee D., 2007, P ACM SIGCOMM
  • [13] MARWAH M, 2003, P IEEE INT C DEP SYS
  • [14] MCBRIDE R, FIREWALL FAILOVER PF
  • [15] Shaikh A., 1999, P ACM SIGCOMM SEPT
  • [16] Shieh A, 2005, USENIX ASSOCIATION PROCEEDINGS OF THE 2ND SYMPOSIUM ON NETWORKED SYSTEMS DESIGN & IMPLEMENTATION (NSDI '05), P175
  • [17] SMITH FD, 2001, P ACM SIGMETRICS JUN
  • [18] SNOEREN AC, 2001, P 3 USENIX S INT TEC
  • [19] STEWART R, 2001, IEEE INTERNET COMPUT
  • [20] Migratory TCP: Connection migration for service continuity in the Internet
    Sultan, F
    Srinivasan, K
    Iyer, D
    Iftode, L
    [J]. 22ND INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, PROCEEDINGS, 2002, : 469 - 470