Paper
26 July 2001 Constructing high-performance firewall load-balancing clusters: practical experience and novel ideas
Lebin Cheng, Yan-Fa Li, Brian Jemes, Samuel Horowitz
Author Affiliations +
Proceedings Volume 4527, Technologies, Protocols, and Services for Next-Generation Internet; (2001) https://doi.org/10.1117/12.434426
Event: ITCom 2001: International Symposium on the Convergence of IT and Communications, 2001, Denver, CO, United States
Abstract
Security and performance are probably the top two concerns of web hosting service providers. As available bandwidth of a hosting service is approaching Giga-bits-per-second, low throughput of a single firewall quickly becomes the bottleneck. Constructing a load-balancing cluster of multiple firewall devices seems to be an effective solution. In this paper, we first present a proof-of-concept firewall cluster using web load balancing switches. Our test cluster works; but has major limitations. First, the cluster set-up is too complex to be manageable in a large-scale deployment. Furthermore, the firewall cluster works only in a local area network. It does not work across the wide area network where asymmetric routing is possible. Based on these findings, we propose two novel approaches. The first approach introduces a Firewall Cluster Control Protocol (FCCP) for routers to direct network flows to the appropriate firewall device for processing. FCCP simplifies the implementation of firewall clusters by eliminating the load balancing switch requirement. The second approach, called Stateful Packet Forwarding (SPF), allows firewall devices in a cluster to discover the 'owner' of a network flow when asymmetric routing occurs. SPF can be potentially used in a geographically distributed firewall cluster.
© (2001) COPYRIGHT Society of Photo-Optical Instrumentation Engineers (SPIE). Downloading of the abstract is permitted for personal use only.
Lebin Cheng, Yan-Fa Li, Brian Jemes, and Samuel Horowitz "Constructing high-performance firewall load-balancing clusters: practical experience and novel ideas", Proc. SPIE 4527, Technologies, Protocols, and Services for Next-Generation Internet, (26 July 2001); https://doi.org/10.1117/12.434426
Lens.org Logo
CITATIONS
Cited by 1 scholarly publication and 2 patents.
Advertisement
Advertisement
RIGHTS & PERMISSIONS
Get copyright permission  Get copyright permission on Copyright Marketplace
KEYWORDS
Switches

Inspection

Internet

Local area networks

Failure analysis

Control systems

Fiber reinforced polymers

RELATED CONTENT

Network systems security analysis
Proceedings of SPIE (May 14 2015)
Architectures for QKD networks
Proceedings of SPIE (July 19 2022)
Protecting sensitive data: lessons learned
Proceedings of SPIE (March 12 1996)
Security of remotely operated robotic telescopes
Proceedings of SPIE (June 02 2000)

Back to Top