Font Size: a A A

Based On The Design And Research Of The The Ipv6 Hardware Firewall

Posted on:2007-04-05Degree:MasterType:Thesis
Country:ChinaCandidate:K HeFull Text:PDF
GTID:2208360185456025Subject:Software engineering
Abstract/Summary:PDF Full Text Request
As the rapid development of internet, the number of network nodes is increasing drastically. In order to solve the problem of insufficient IP addresses and meanwhile enhance internet data transfer security, the current IPv4 will inevitably be replaced by IPv6. Furthermore, the internet bandwidth keeps on growing, followed by more and more new network techniques. Increasing emphasis is paid on the long development cycle and upgrade difficulty of the earliest technologies such as ASIC. Because of all these, a new technology called Network Processor (NP) is presented. To adapt the high speed modern networks the NP is hardware optimized especially for the network data processing. Meanwhile, it is programmable and thus can be upgraded quickly to apply new network technology and applicatoins.This thesis is mainly about the design of the firewall which is based on Intel NP and IPv6. Intel IXA(Internet Exchange Architecture) is studied and based on it the whole design of IPv6 firewall is finished. This paper can be divided into four parts.The first part (the 2nd chapter) introduces background technology of the firewall, including firewall, IPv6 and NP.The second part (the 3rd chapter) begins to introduce the design of the system. It describes the system architecture including hardware structure, software structure, the flow chart, and task scheduling on microengines.The third part (the 4th and the 5th chapter) particularly describes what the author did in the project. The fourth chapter is about the Data Plane. The main control code of the Data Plane which can support both IPv4 and IPv6 has been implemented. Then it describes the software framework of the firewall system in Data Plane. The fifth chapter is about the dynamic packet filter's design and implementation. Dynamic packet filtering technique greatly enhances packet filter's efficiency and security.The fourth part (the 6th chapter) is the conclusion of the paper. It describes the characteristics and the disadvantages of the system, gives improvement suggestions, and raised issues which need to be further studied.
Keywords/Search Tags:NP, IPv6, Firewall, IXP2400, IXA
PDF Full Text Request
Related items