Performance analysis of virtualized VPN endpoints

D. Lackovic, Mladen Tomic
{"title":"Performance analysis of virtualized VPN endpoints","authors":"D. Lackovic, Mladen Tomic","doi":"10.23919/MIPRO.2017.7973470","DOIUrl":null,"url":null,"abstract":"Virtual Private Networks (VPN) are an established technology that provides users a way to achieve secure communication over an insecure communication channel, such as the public Internet. It has been widely accepted due to its flexibility and availability on many platforms. It is often used as an alternative to expensive leased lines. In traditional setups, VPN endpoints are set up in hardware appliances, such as firewalls or routers. In modern networks, which utilize Network Functions Virtualization (NFV), VPN endpoints can be virtualized on common servers. Because data encryption and decryption are CPU intensive operations, it is important to investigate limits of such setups so that feasibility of endpoint virtualization can be evaluated. In this paper, we analyze performance of two industry standard VPN implementations - IPSec and OpenVPN. We examine TCP throughput in relation to encryption algorithm used and packet size. Our experiments suggest that moving VPN endpoints from a specialized hardware appliance to a virtualized environment can be a viable and simple solution if traffic throughput requirements are not too demanding. However, it is still difficult to replace high-end appliances with large throughput capabilities.","PeriodicalId":203046,"journal":{"name":"2017 40th International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO)","volume":"45 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-05-22","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"13","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 40th International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.23919/MIPRO.2017.7973470","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 13

Abstract

Virtual Private Networks (VPN) are an established technology that provides users a way to achieve secure communication over an insecure communication channel, such as the public Internet. It has been widely accepted due to its flexibility and availability on many platforms. It is often used as an alternative to expensive leased lines. In traditional setups, VPN endpoints are set up in hardware appliances, such as firewalls or routers. In modern networks, which utilize Network Functions Virtualization (NFV), VPN endpoints can be virtualized on common servers. Because data encryption and decryption are CPU intensive operations, it is important to investigate limits of such setups so that feasibility of endpoint virtualization can be evaluated. In this paper, we analyze performance of two industry standard VPN implementations - IPSec and OpenVPN. We examine TCP throughput in relation to encryption algorithm used and packet size. Our experiments suggest that moving VPN endpoints from a specialized hardware appliance to a virtualized environment can be a viable and simple solution if traffic throughput requirements are not too demanding. However, it is still difficult to replace high-end appliances with large throughput capabilities.
虚拟化VPN端点性能分析
虚拟专用网(VPN)是一种成熟的技术,它为用户提供了一种在不安全的通信通道(如公共Internet)上实现安全通信的方法。由于其在许多平台上的灵活性和可用性,它已被广泛接受。它通常被用作昂贵的租用线路的替代方案。在传统设置中,VPN端点设置在硬件设备中,例如防火墙或路由器。在使用NFV (Network Functions Virtualization)技术的现代网络中,VPN端点可以在普通服务器上虚拟化。由于数据加密和解密是CPU密集型操作,因此调查此类设置的限制非常重要,这样可以评估端点虚拟化的可行性。本文分析了两种行业标准VPN实现IPSec和OpenVPN的性能。我们检查TCP吞吐量与使用的加密算法和数据包大小的关系。我们的实验表明,如果流量吞吐量要求不太高,将VPN端点从专用硬件设备移动到虚拟环境可能是一种可行且简单的解决方案。然而,要取代具有大吞吐量能力的高端设备仍然很困难。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信