| With the computer network in the political, economic, cultural and many other aspects of the rapid development of network has been gradually become indispensable in our daily life an important part. At the same time, network security issues also highlights out and network application gradually become the important issues faced by the network security technology is more and more attention. The firewall is currently the most popular is the most widely used a network information security technology. And the current widespread use of IPv4 compared, IPv6 as the basis of the area under the agreement, has many advantages. For example, IPv6 to solve the shortage of IP addresses number of issues; IPv6 to IPv4 agreement in the number of shortcomings in the conduct of the larger improvements, IPsec will be integrated into the internal agreement, IPsec no longer stand alone, and so on. Papers on IPv6 firewall technology and the new features of IPv6 firewall distributed under the key technology research, completed the following aspects of work:(1) outlined the issue of network security and technical characteristics of IPv6 IPSec and mechanisms to study the existing IPSec on the impact of network security system, especially the firewall of the new challenges.(2) on the firewall and the achievement of the basic principles of technology, including firewall history, classification, function, and the traditional network firewall, and distributed firewall architectures, working principles were compared.(3) In order to overcome the shortcomings of traditional firewall, and retain its advantages, the paper completed a firewall IPv6 distributed under the design and implementation of the system is the realization of the basic modules. Distributed in accordance with the essential characteristics of a firewall - "strategies focus on developing decentralized implementation of a decentralized focus on preservation of the log", design and management of the central domain manager to manage networks and the development of security policies and security policies distributed to the entire network The host firewall and network firewall implementation, to solve the efficiency of the traditional firewall bottleneck, can not withstand internal attacks and distributed attacks, and other issues. |