Volume 8 Number 7 (Jul. 2013)
Home > Archive > 2013 > Volume 8 Number 7 (Jul. 2013) >
JCP 2013 Vol.8(7): 1664-1676 ISSN: 1796-203X
doi: 10.4304/jcp.8.7.1664-1676

A Centralized State Repository Approach to Highly Scalable and High-Availability Parallel Firewall

Kasom Koht-arsa and Surasak Sanguanpong
Kasetsart University, Bangkok, Thailand

Abstract—Conventional high-availability stateful parallel firewall suffers from low scalability due to two overlapping requirements: workload distribution and redundancy. To achieve high throughput, load-distribution with complex algorithm is conventionally employed, consuming a lot of resources and making the system susceptible to state-related attacks such as SYN-flooding. On the other hand, making the system redundant usually implies N-to-N crossreplication of connection-state data among firewall nodes. These make the scaling effort very difficult at best. This paper presents the novel design and implementation of a highly scalable, high-availability, stateful parallel firewall with centralized state repository intending for high-speed connection environment. The system consists of fault sensor unit(s), fully redundant load manager units, fully redundant central state repository unit(s), and an array of Linux-based machines acting as firewall nodes under the data parallel scheme. Adding more units into the system can scale every component up. Consistent Disjoint-subset Hashing and Stateless Load balancing algorithms, chosen for their superior computing overhead, provide high performance, flexibility and scalability. Centralized State Repository further enhances reliability and scalability. Actual deployment statistics confirm that the combination of centralized state repository and on-demand state restoration largely reduces the number of state synchronization transactions when the number of firewall nodes fluctuates. Therefore, the high-scalability and load balancing are gained with minimal state replications.

Index Terms—firewall, stateful firewall, parallel firewall, high availability, fault-tolerant, fully redundant, scalable, state replication

[PDF]

Cite: Kasom Koht-arsa and Surasak Sanguanpong, " A Centralized State Repository Approach to Highly Scalable and High-Availability Parallel Firewall," Journal of Computers vol. 8, no. 7, pp. 1664-1676, 2013.

General Information

ISSN: 1796-203X
Abbreviated Title: J.Comput.
Frequency: Bimonthly
Editor-in-Chief: Prof. Liansheng Tan
Executive Editor: Ms. Nina Lee
Abstracting/ Indexing: DBLP, EBSCO,  ProQuest, INSPEC, ULRICH's Periodicals Directory, WorldCat,etc
E-mail: jcp@iap.org
  • Nov 14, 2019 News!

    Vol 14, No 11 has been published with online version   [Click]

  • Mar 20, 2020 News!

    Vol 15, No 2 has been published with online version   [Click]

  • Dec 16, 2019 News!

    Vol 14, No 12 has been published with online version   [Click]

  • Sep 16, 2019 News!

    Vol 14, No 9 has been published with online version   [Click]

  • Aug 16, 2019 News!

    Vol 14, No 8 has been published with online version   [Click]

  • Read more>>