A clustering and traffic-redistribution scheme for high-performance IPsec VPNs

Pan Lung Tsai*, Chun-Ying Huang, Yun Yin Huang, Chia Chang Hsu, Chin Laung Lei

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution

4 Scopus citations

Abstract

CPE-based IPsec VPNs have been widely used to provide secure private communication across the Internet. As the bandwidth of WAN links keeps growing, the bottleneck in a typical deployment of CPE-based IPsec VPNs has moved from the last-mile connections to the customer-edge security gateways. In this paper, we propose a clustering scheme to scale the throughput as required by CPE-based IPsec VPNs. The proposed scheme groups multiple security gateways into a cluster using a transparent self-dispatching technique and allows as many gateways to be added as necessary until the resulting throughput is again limited by the bandwidth of the last-mile connections. It also includes a flow-migration mechanism to keep the load of the gateways balanced. The results of the performance evaluation confirm that the clustering technique and the traffic-redistribution mechanism together create a transparent, adaptive, and highly scalable solution for building high-performance IPsec VPNs.

Original languageEnglish
Title of host publicationHigh Performance Computing, HiPC 2005 - 12th International Conference, Proceedings
Pages432-443
Number of pages12
DOIs
StatePublished - 1 Dec 2005
Event12th International Conference on High Performance Computing, HiPC 2005 - Goa, India
Duration: 18 Dec 200521 Dec 2005

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume3769 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference12th International Conference on High Performance Computing, HiPC 2005
CountryIndia
CityGoa
Period18/12/0521/12/05

Fingerprint Dive into the research topics of 'A clustering and traffic-redistribution scheme for high-performance IPsec VPNs'. Together they form a unique fingerprint.

  • Cite this

    Tsai, P. L., Huang, C-Y., Huang, Y. Y., Hsu, C. C., & Lei, C. L. (2005). A clustering and traffic-redistribution scheme for high-performance IPsec VPNs. In High Performance Computing, HiPC 2005 - 12th International Conference, Proceedings (pp. 432-443). (Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics); Vol. 3769 LNCS). https://doi.org/10.1007/11602569_45