A Generic Hot–Failover State Machine for Gateway Services and its Application to a Linux Firewall
نویسنده
چکیده
Nowadays, companies of any size rely on their IT–infrastructure since it provides connectivity to the outside world. Services like firewalls, being positioned between the own domain and a foreign one, form a premises for higher level services. Therefore, such gateway services must be considered as especially mission– critical. While there exist high availability solutions for special service types, a generic solution which can be applied to arbitrary gateway services, especially for smaller sized scenarios, is missing. Fault tolerance in terms of high availability is addressed by this paper through the concept of redundancy. Presenting a generic state machine for monitoring and takeover processes, it leads to an universally applicable logic. The state machine’s basis is derived from requirements posed by the generic scenario of gateway services. Furthermore, our solution’s practical applicability is shown by presenting an implementation carried out for a Linux–based firewall system.
منابع مشابه
GateScript: A Scripting Language for Generic Active Gateways
In this paper, we present GateScript, a scripting language for active applications to be executed on generic active gateways. Unlike other active networking platforms, it offers a simple scripting language for expressing custom processing of packets at different protocol layers without the need for interpretation of complex protocol data structures. In this way, the user writes statements in a ...
متن کاملFine-Grained Failover Using Connection Migration
This paper presents a set of techniques for providing fine-grained failover of long-running connections across a distributed collection of replica servers, and is especially useful for fault-tolerant and load-balanced delivery of streaming media and telephony sessions. Our system achieves connection-level failover across both localand wide-area server replication, without requiring a frontend t...
متن کاملGrid Security Gateway on RADIUS and Packet Filter
RADIUS specified by RFC2865 and RFC2866 is used widely for remote dial-in user authentication and authorization. Packet filter such as Linux Netfilter is a primary toolkit to develop firewall or intrusion detection system. Modeling RADIUS client and packet filter together, a security gateway for grid computing is developed as an embedded or a proxy system. To reinforce the flexibility of the ga...
متن کاملResource-Aware Deployment and Configuration of QoS-enabled Middleware
Ad hoc deployment and configuration (D&C) of faulttolerance mechanisms (e.g., replica-host mapping and failover ordering of replicas) can lead to unacceptable response times, overloads, and low-availability for soft realtime applications. This paper describes how our quality-ofservice (QoS)-enabled middleware called DeCoRAM (Deployment and Configuration Reasoning via Analysis and Modeling) prov...
متن کاملVDRS: An inexpensive approach to server disaster recovery
Traditional disaster recovery solutions involve specialized data replication hardware and software, dedicated wide-area circuits, and duplicate infrastructure at primary and backup locations, and introduce considerable cost and complexity. As a results, such solutions are limited primarily to large enterprises and institutions. For smaller, more cost-conscious environments such as moderate volu...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2005