Title :
Failure preventive mechanism for IPsec gateways
Author :
Palomares, Daniel ; Migault, Daniel ; Laurent, Monique
Author_Institution :
France Telecom, Orange, France
Abstract :
Operators are mainly using IPsec Virtual Private Networks (VPNs) to extend a security domain over untrusted networks. A VPN is usually established when an End-User (EU) and a Security Gateway (SG) negotiate security associations (SA). For a better QoS, the SGs are geographically distributed so they are as close as possible to EU. As such, the higher is the level of responsibility of the SG, the higher is the risk to be overloaded and to break down. This paper presents a mechanism for extracting and reinstalling security associations as well as a mechanism to transfer a given IPsec traffic from one SG to another. We also propose an additional mechanism for solving the mis-synchronization of IPsec anti-replay counters and IKEv2 Messages ID counters. Finally some performance measurements are provided in terms of delays, and packet loss, and prove feasibility of the approach. Results obtained through real implementation showed that the system time to extract an IKEv2/IPsec session is in a range of 5ms up to 15ms whereas the system time to restore an IKEv2/IPsec session can take 2ms up to 22ms.
Keywords :
IP networks; computer network reliability; computer network security; internetworking; quality of service; virtual private networks; IKEv2 message ID counters; IKEv2-IPsec session; IPsec VPN; IPsec antireplay counters; IPsec gateways; IPsec traffic; IPsec virtual private networks; QoS; end-user; failure preventive mechanism; packet loss; security associations; security domain; security gateway; time 2 ms to 22 ms; Context; IP networks; Logic gates; Protocols; Radiation detectors; Security; Virtual private networks; Failure-Preventive; IKEv2; IPsec; IPsec Clustering; QoS; Security Gateway Handover;
Conference_Titel :
Communications and Information Technology (ICCIT), 2013 Third International Conference on
Conference_Location :
Beirut
Print_ISBN :
978-1-4673-5306-9
DOI :
10.1109/ICCITechnology.2013.6579543