Cloud-clustered firewall with distributed SDN devices
Yu-Wei Wayne Chang, Tsung-Nan Lin · 2018
In order to prevent network services and end hosts from Internet attacks, a firewall is an important protective component to enforce security policy on network packets. A typical firewall sits at the entry point of an Autonomous System (AS). However, it may become the congestion point because of the growing number of security policies and network traffic. Also, a SDN-based firewall can suffer from the TCAM memory limit of SDN devices and thus it can only install a limited number of security policies. This paper presents a robust algorithm to distribute security policies of a firewall into distributed SDN devices in cloud-clustered environment. While this algorithm can obtain a better performance and resolve the TCAM memory limit of SDN devices, it can also guarantee a more complete protection, by stopping insider attacks.