P4-IPsec: Implementation of IPsec Gateways in P4 with SDN Control for Host-to-Site Scenarios

07/08/2019
by   Frederik Hauser, et al.
0

In this paper we propose P4-IPsec which follows the software-defined networking (SDN) paradigm. It comprises a P4-based implementation of an IPsec gateway, a client agent, and a controller-based, IKE-less signalling between them. P4-IPsec features the Encapsulation Security Payload (ESP) protocol, tunnel mode, and various cipher suites for host-to-site virtual private networks (VPNs). We consider the use case of a roadwarrior and multiple IPsec gateways steered by the same controller. P4-IPsec supports on-demand VPN which sets up tunnels to appropriate resources within these sites when requested by applications. To validate the P4-based approach for IPsec gateways, we provide three prototypes leveraging the software switch BMv2, the NetFPGA SUME card, and the Edgecore Wedge 100BF-32X switch as P4 targets. For the latter, we perform a performance evaluation giving experimental results on throughput and delay.

READ FULL TEXT

page 11

page 14

research
12/13/2020

Network Traffic Control for Multi-homed End-hosts via SDN

Software Defined Networking (SDN) is an emerging technology of efficient...
research
10/22/2020

Strengthening SDN Security: Protocol Dialecting and Downgrade Attacks

Software-defined networking (SDN) has become a fundamental technology fo...
research
01/20/2019

The Road to BOFUSS: The Basic OpenFlow User-space Software Switch

Software switches are pivotal in the Software-Defined Networking (SDN) p...
research
08/07/2020

Role-Based Deception in Enterprise Networks

Historically, enterprise network reconnaissance is an active process, of...
research
03/30/2020

Performance Benchmarking of State-of-the-Art Software Switches for NFV

With the ultimate goal of replacing proprietary hardware appliances with...
research
06/23/2019

Experimental Security Analysis of Controller Software in SDNs: A Review

The software defined networking paradigm relies on the programmability o...
research
08/01/2020

Joint Switch-Controller Association and Control Devolution for SDN Systems: An Integration of Online Control and Online Learning

In software-defined networking (SDN) systems, it is a common practice to...

Please sign up or login with your details

Forgot password? Click here to reset