Implementation and Performance Evaluation of IPSec VPN Based on Netfilter

被引:7
|
作者
ZHAO Da-yuan
机构
关键词
IPSec; virtual private network; netfilter;
D O I
暂无
中图分类号
TP393 [计算机网络];
学科分类号
081201 ; 1201 ;
摘要
We mainly explore two problems when combining IPSec module into TCP/IP stack by porting the famous IPSec software (FreeS/WAN) into a security gateway. One is how to implement the IPSec module based on Netfilter in Linux 2.4.x kernel. The other problem is the performance evaluation. We test the throughput of our security gateway before and after applying IPSec with different encryption/decryption algorithms, including the software-based and hardware-based method. With these testing data, we analyze further system performance bottleneck. In the end, we also infer the quantitative relation between the system throughput and the speed of encryption/decryption algorithm and propose some valuable conclusions for improving performance.
引用
收藏
页码:98 / 102
页数:5
相关论文
共 50 条
  • [1] Implementation and performance evaluation of hardware accelerated IPSec VPN for the home gateway
    Park, MH
    Beom, MJ
    Park, WK
    Jeong, YK
    Paik, EH
    7th International Conference on Advanced Communication Technology, Vols 1 and 2, Proceedings, 2005, : 1007 - 1010
  • [2] 基于Netfilter框架的IPSec VPN网关实现
    高月松
    钱晶
    泰州职业技术学院学报, 2009, 9 (03) : 9 - 10+18
  • [3] Design and implementation of an embedded VPN gateway based on IPSec
    Zheng, YJ
    Liu, Q
    Li, FM
    DCABES 2004, Proceedings, Vols, 1 and 2, 2004, : 225 - 227
  • [4] THE DESIGN AND IMPLEMENTATION OF VPN TESTING TOOLS BASED ON IPSEC
    Xu, Siping
    3RD INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND COMPUTER SCIENCE (ITCS 2011), PROCEEDINGS, 2011, : 398 - 401
  • [5] Improvements based on the IPSec VPN Secuirity
    Fan, Ya-qin
    Lv, Ling
    Liu, Mei-lin
    Xie, Fei
    PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION APPLICATIONS (ICCIA 2012), 2012, : 186 - 189
  • [6] Implementation and Performance Evaluation of Embedded IPsec in Microkernel OS
    Hamad, Mohammad
    Prevelakis, Vassilis
    2015 WORLD SYMPOSIUM ON COMPUTER NETWORKS AND INFORMATION SECURITY (WSCNIS), 2015,
  • [7] Implementation of GRE Over IPsec VPN Enterprise Network Based on Cisco Packet Tracer
    Wang, Chong
    Chen, Jing-you
    PROCEEDINGS OF THE 2ND INTERNATIONAL CONFERENCE ON SOFT COMPUTING IN INFORMATION COMMUNICATION TECHNOLOGY, 2014, : 142 - 146
  • [8] Research and Implementation of Security Wireless LANs based on EAP-TLS and IPSec VPN
    Zhou Li
    Tan Fang-yong
    Gao Xiao-hui
    2010 INTERNATIONAL COLLOQUIUM ON COMPUTING, COMMUNICATION, CONTROL, AND MANAGEMENT (CCCM2010), VOL I, 2010, : 80 - 83
  • [9] IPSec VPN与MPLS VPN
    廖艳
    周振勇
    毛培法
    现代通信, 2002, (07) : 1 - 3