Author Login Editor-in-Chief Peer Review Editor Work Office Work

Computer Engineering ›› 2007, Vol. 33 ›› Issue (10): 172-174. doi: 10.3969/j.issn.1000-3428.2007.10.062

• Security Technology • Previous Articles     Next Articles

Optimized Design and Research of Firewall Based on Network Processor

SHEN Jian, ZHOU Xingshe, ZHANG Fan, YU Zhiyong   

  1. (College of Computer Science, Northwestern Polytechnical University, Xi’an 710072)
  • Received:1900-01-01 Revised:1900-01-01 Online:2007-05-20 Published:2007-05-20

基于网络处理器的防火墙优化设计与研究

沈 健,周兴社,张 凡,於志勇   

  1. (西北工业大学计算机科学学院,西安 710072)

Abstract: This paper proposes the design scheme of state packet inspection firewall based on network processor, and describes the optimized design of key technologies for IXP2400’s hardware structure, including the storage structure and item searching of the access control list and the status session table. The proposed approach will enhance the performance of firewall observably.

Key words: Network processor, Firewall, Access control list(ACL), Status session table(SST)

摘要:

提出了基于网络处理器的状态检测型防火墙设计方案,并针对IXP2400的硬件结构,对访问控制列表和状态会话表的存储结构及表项查找等关键技术进行了优化,发挥了IXP2400内部各硬件单元的优点,系统达到线速处理的能力,使其性能得到了较大的提交。

关键词: 网络处理器, 防火墙, 访问控制列表, 状态会话表

CLC Number: