Publication No 36560

Author(s)

Kiesel, S.*; Scharf, M.*

Title

Modeling and performance evaluation of transport protocols for firewall control

Methods

Performance Evaluation

Keywords

FIREWALL; SCTP; BLOCKING; SIMCO

Abstract

Firewalls are a crucial building block for securing IP networks. The usage of out-ofband signaling protocols such as SIP for IP telephony and multimedia applications requires a dynamic control of these firewalls and imposes several challenges. Recently, several firewall control architectures and protocols have been developed. The main focus of this paper is the Simple Middlebox Configuration Protocol (SIMCO), which is a new transactionbased firewall control protocol. Due to the impact on call setup delays, firewall signaling requires small end-to-end delays and thus mandates a careful choice of the transport protocol. Therefore, this paper studies SCTP, TCP and UDP-based transport for SIMCO and compares different configurations that allow to optimize the performance. We present an analytical model to quantify the impact of head-of-line blocking in SCTP and TCP and verify it with measurements. Both the model and measurements reveal that SCTP can significantly reduce the SIMCO response times by leveraging transmission over multiple parallel streams. While already a few SCTP streams can almost completely avoid headof- line blocking, our results show that TCP- and UDP-based transport may suffer from significantly larger delays.

Year

2007

Reference entry

Kiesel, S.; Scharf, M.
Modeling and performance evaluation of transport protocols for firewall control
Computer Networks (ComNet) 2007, Vol. 51, No. 11, August 2007, pp. 3232-3251

BibTex file

Download  [BIBTEX]

Full Text

Download  [PDF]

Authors marked with an asterisk (*) were IKR staff members at the time the publication has been written.