Title :
High Availability for IPsec VPN Platforms: ClusterIP Evaluation
Author :
Palomares, Daniel ; Migault, Daniel ; Velasquez, Wolfgang ; Laurenty, Maryline
Author_Institution :
France Telecom, France
Abstract :
To manage the huge demand on traffic, the Internet Service Providers (ISP) are offloading its mobile data from Radio Access Networks (RAN) to Wireless Access Networks (WLAN). While these RANs are considered trusted networks, WLANs need to build a similar trusted zone in order to offer the same security level and Quality of Service (QoS) to End-Users (EU). Although IPsec is widely implemented to create trusted environments through untrusted networks, the industry is increasingly interested in providing IPsec-based services with High Availability (HA) features in order to ensure reliability, QoS and security. Even though IPsec is not originally well suited to provide HA features, some mechanisms like VRRP or ClusterIP can work together with IPsec in order to offer HA capabilities. ClusterIP is actually used by strong Swan (an open source IPsec-based VPN solution) to build a cluster of IPsec Security Gateways (SG) offering HA features. This paper concentrates on how to build a cluster of IPsec SGs based on ClusterIP. We describe the main issues to overcome HA within IPsec. Then, we measure how HA may affect the EU experience, and provide recommendations on how to deploy ClusterIP. Finally, our tests over an HTTP connection showed that ClusterIP allows fast recovering during a failure.
Keywords :
Internet; computer network security; quality of service; radio access networks; transport protocols; virtual private networks; wireless LAN; ClusterIP evaluation; EU; HA features; HTTP connection; IPsec VPN platform; IPsec security gateway; IPsec-based services; Internet service provider; QoS; RAN; SG; VRRP; WLAN; end-user; high availability feature; mobile data; quality of service; radio access network; wireless access network; Availability; IP networks; Protocols; Radiation detectors; Security; Synchronization; Virtual private networks; ClusterIP; Fast IPsec recovering; IPsec Clustering; Security Gateway Handover;
Conference_Titel :
Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
Conference_Location :
Regensburg
DOI :
10.1109/ARES.2013.25