ForCES-Based Firewall with Stateful Packet Inspection

Article Preview

Abstract:

In order to meet the extensibility and flexibility requirement of next generation network, ForCES working group of IETF proposes an architecture with the separation of Forwarding Element and Control Element. A firewall with ForCES architecture will have enough flexibility on security function extensibility. This paper not only designs the ForCES architecture of status package inspection firewall and related LFB (Logic Functional Block), but also implements a prototype system and carries out tests and analysis. The experiment result testifies the feasibility of ForCES specification and provides the important technical parameter for the ForCES security application.

You might also be interested in these eBooks

Info:

Periodical:

Pages:

440-444

Citation:

Online since:

March 2011

Export:

Price:

Permissions CCC:

Permissions PLS:

Сopyright:

© 2011 Trans Tech Publications Ltd. All Rights Reserved

Share:

Citation:

[1] Jianli Ding. Network security. WuHan: Wuhan University Press, (2007).

Google Scholar

[2] Wei Wang, Hui Yan, Yupeng Ning. Theory and technology of the firewall [M]. BeiJing: Mechanical Industry Press, (2004).

Google Scholar

[3] Forwarding and Control Element Separation , Dec. 2007. http: /www. ietf. org/html. charters/forces-charter. html.

Google Scholar

[4] Doria (Ed. ), et al., ForCES Protocol Specification, Internet Draft, (2006).

Google Scholar

[5] E. Haleplidis, K. Ogawa, W. Wang, and J. Hadi Salim, Implementation Report for ForCES, , work in progress, http: /www. tools. ietf. org/html/draft-ietf-forces-implementation-report.

DOI: 10.17487/rfc6053

Google Scholar

[6] E. Haleplidis, K. Ogawa, X. Wang, and C. Li, ForCES Interoperability Draft, work in progress, http: /www. tools. ietf. org/html/draft-ietf-forces-interoperability.

Google Scholar

[7] R. Haas, ForCES MIB, work in progress, http: /www. tools. ietf. org/html/draft-ietf-forces-mib.

Google Scholar

[8] J. Halpern, A base Library for use with the ForCES Protocol and Model, work in progress, http: /www. tools. ietf. org/html/draft-halpern-forces-lfblibrary-base.

Google Scholar

[9] J. Halpern and Huaiyuan Ma, A VPN Library for use with the ForCES Protocol and Model, work in progress, http: /www. ietf. org/internet-drafts/draft-halpern-forces-lfblibrary-vpn-00. txt.

Google Scholar

[10] Weiming Wang, E. Haleplidis, K. Ogawa, F. Jia, and J. Halpern, ForCES LFB Library, work in progress, http: /www. tools. ietf. org/html/draft-ietf-forces-lfb-lib.

DOI: 10.17487/rfc6956

Google Scholar

[11] Yu Sun. Firewall System Based on Network Processor Design. Southeast University, (2006).

Google Scholar