• DocumentCode
    2177832
  • Title

    Implementation and Performance Study of a New NAT/Firewall Signaling Protocol

  • Author

    Peters, H. ; Xiaoming Fu

  • fYear
    2006
  • fDate
    04-07 July 2006
  • Firstpage
    8
  • Lastpage
    8
  • Abstract
    The NAT/Firewall NSIS Signaling Layer Protocol (NAT/Firewall NSLP) is a path-coupled signaling protocol for explicit Network Address Translator and firewall configuration within an extensible IP signaling framework currently being developed by the IETF Next Steps in Signaling (NSIS) working group. This new protocol allows end hosts to signal along a path to configure NATs and firewalls according to the data flow needs. In this paper we present a first open source implementation and performance evaluation of NAT/Firewall NSLP. The performance study shows that our implementation scales well and is able to support firewall signaling for up to tens of thousands of flows in parallel even in a low-end PC testbed environment. The overall performance bottleneck is found to lie in the utilized firewall implementation, not depending on the NAT/Firewall NSLP implementation.
  • Keywords
    IP networks; Informatics; Middleboxes; Network address translation; Peer to peer computing; Protection; Protocols; Quality of service; Telecommunication traffic; Testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Distributed Computing Systems Workshops, 2006. ICDCS Workshops 2006. 26th IEEE International Conference on
  • ISSN
    1545-0678
  • Print_ISBN
    0-7695-2541-5
  • Type

    conf

  • DOI
    10.1109/ICDCSW.2006.63
  • Filename
    1648896