DocumentCode
2177832
Title
Implementation and Performance Study of a New NAT/Firewall Signaling Protocol
Author
Peters, H. ; Xiaoming Fu
fYear
2006
fDate
04-07 July 2006
Firstpage
8
Lastpage
8
Abstract
The NAT/Firewall NSIS Signaling Layer Protocol (NAT/Firewall NSLP) is a path-coupled signaling protocol for explicit Network Address Translator and firewall configuration within an extensible IP signaling framework currently being developed by the IETF Next Steps in Signaling (NSIS) working group. This new protocol allows end hosts to signal along a path to configure NATs and firewalls according to the data flow needs. In this paper we present a first open source implementation and performance evaluation of NAT/Firewall NSLP. The performance study shows that our implementation scales well and is able to support firewall signaling for up to tens of thousands of flows in parallel even in a low-end PC testbed environment. The overall performance bottleneck is found to lie in the utilized firewall implementation, not depending on the NAT/Firewall NSLP implementation.
Keywords
IP networks; Informatics; Middleboxes; Network address translation; Peer to peer computing; Protection; Protocols; Quality of service; Telecommunication traffic; Testing;
fLanguage
English
Publisher
ieee
Conference_Titel
Distributed Computing Systems Workshops, 2006. ICDCS Workshops 2006. 26th IEEE International Conference on
ISSN
1545-0678
Print_ISBN
0-7695-2541-5
Type
conf
DOI
10.1109/ICDCSW.2006.63
Filename
1648896
Link To Document