作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (13): 134-136. doi: 10.3969/j.issn.1000-3428.2010.13.047

• 安全技术 • 上一篇    下一篇

基于协商处理的集群防火墙负载均衡算法

彭智朝,谢 东,陈代武   

  1. (湖南人文科技学院计算机科学技术系,娄底 417000)
  • 出版日期:2010-07-05 发布日期:2010-07-05
  • 作者简介:彭智朝(1976-),男,讲师、硕士,主研方向:计算机网络安全;谢 东,讲师、博士;陈代武,副教授、硕士
  • 基金资助:
    湖南省自然科学基金资助项目(07JJ3119);湖南省教育科学“十一五”规划课题基金资助项目(XJK08XCJ010)

Cluster Firewall Load-balancing Algorithm Based on Negotiation Treatment

PENG Zhi-chao, XIE Dong, CHEN Dai-wu   

  1. (Department of Computer Science and Technology, Hunan University of Humanities, Science and Technology, Loudi 417000)
  • Online:2010-07-05 Published:2010-07-05

摘要:

通过分析集群防火墙系统结构和数据包协商处理过程,提出一种基于协商处理的集群防火墙系统负载均衡算法。使用基于权值的Hash算法实现并行过滤。当某一防火墙重载时将任务转移给轻载的伙伴节点,出故障时采用备份防火墙进行快速切换。该算法能实现防火墙节点负载均衡,并且防火墙个数越多,吞吐量越大,时延越低,从而获得了高性能、高可靠性和高可用性。

关键词: 集群防火墙系统, 负载均衡, 协商处理, Hash算法

Abstract: This paper analyzes the structure of the cluster firewall system and data packets negotiation treatment, and proposes a Cluster Firewall System(CFS) load-balancing algorithm based on negotiation treatment. The algorithm achieves parallel filter data based on the weighted Hash algorithm. When a firewall overloads, it transfers some assignments to the light-load partners nodes. When a firewall is failure, the backup firewall fast replaces the failure firewall. The algorithm can achieve a firewall node’s load-balancing, the more firewall number, the more higher throughput, the lower latency. And high performance, high reliability and high availability are received.

Key words: Cluster Firewall System(CFS), load-balancing, negotiation treatment, Hash algorithm

中图分类号: