• DocumentCode
    2128920
  • Title

    High Availability for IPsec VPN Platforms: ClusterIP Evaluation

  • Author

    Palomares, Daniel ; Migault, Daniel ; Velasquez, Wolfgang ; Laurenty, Maryline

  • Author_Institution
    France Telecom, France
  • fYear
    2013
  • fDate
    2-6 Sept. 2013
  • Firstpage
    178
  • Lastpage
    187
  • Abstract
    To manage the huge demand on traffic, the Internet Service Providers (ISP) are offloading its mobile data from Radio Access Networks (RAN) to Wireless Access Networks (WLAN). While these RANs are considered trusted networks, WLANs need to build a similar trusted zone in order to offer the same security level and Quality of Service (QoS) to End-Users (EU). Although IPsec is widely implemented to create trusted environments through untrusted networks, the industry is increasingly interested in providing IPsec-based services with High Availability (HA) features in order to ensure reliability, QoS and security. Even though IPsec is not originally well suited to provide HA features, some mechanisms like VRRP or ClusterIP can work together with IPsec in order to offer HA capabilities. ClusterIP is actually used by strong Swan (an open source IPsec-based VPN solution) to build a cluster of IPsec Security Gateways (SG) offering HA features. This paper concentrates on how to build a cluster of IPsec SGs based on ClusterIP. We describe the main issues to overcome HA within IPsec. Then, we measure how HA may affect the EU experience, and provide recommendations on how to deploy ClusterIP. Finally, our tests over an HTTP connection showed that ClusterIP allows fast recovering during a failure.
  • Keywords
    Internet; computer network security; quality of service; radio access networks; transport protocols; virtual private networks; wireless LAN; ClusterIP evaluation; EU; HA features; HTTP connection; IPsec VPN platform; IPsec security gateway; IPsec-based services; Internet service provider; QoS; RAN; SG; VRRP; WLAN; end-user; high availability feature; mobile data; quality of service; radio access network; wireless access network; Availability; IP networks; Protocols; Radiation detectors; Security; Synchronization; Virtual private networks; ClusterIP; Fast IPsec recovering; IPsec Clustering; Security Gateway Handover;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
  • Conference_Location
    Regensburg
  • Type

    conf

  • DOI
    10.1109/ARES.2013.25
  • Filename
    6657239