This paper evaluates the performance of Internet Protocol Security (IPSec) based Multiprotocol Label Switching (MPLS) virtual private network (VPN) in a small to medium sized organization. The demand for security in d...This paper evaluates the performance of Internet Protocol Security (IPSec) based Multiprotocol Label Switching (MPLS) virtual private network (VPN) in a small to medium sized organization. The demand for security in data networks has been increasing owing to the high cyber attacks and potential risks associated with networks spread over distant geographical locations. The MPLS networks ride on the public network backbone that is porous and highly susceptible to attacks and so the need for reliable security mechanisms to be part of the deployment plan. The evaluation criteria concentrated on Voice over Internet Protocol (VoIP) and Video conferencing with keen interest in jitter, end to end delivery and general data flow. This study used both structured questionnaire and observation methods. The structured questionnaire was administered to a group of 70 VPN users in a company. This provided the study with precise responses. The observation method was used in data simulations using OPNET Version 14.5 Simulation software. The results show that the IPSec features increase the size of data packets by approximately 9.98% translating into approximately 90.02% effectiveness. The tests showed that the performance metrics are all well within the recommended standards. The IPSec Based MPLS Virtual private network is more stable and secure than one without IPSec.展开更多
In conventional shared risk link group(SRLG)-diverse path selection(CSPS)algorithm in survivable GMPLS networks,SRLG is taken into account when selecting the backup paths,while the primary path selection method is the...In conventional shared risk link group(SRLG)-diverse path selection(CSPS)algorithm in survivable GMPLS networks,SRLG is taken into account when selecting the backup paths,while the primary path selection method is the sarne as the algorithms without SRLG constraint.A problem of CSPS algorithm is that,after a primary path is selected,the success probability to select an SRLG-diverse backup path for it is low.If SRLG is taken into account when computing the primary path,then the probability to successfully select an SRLG-diverse backup path will be much increased.Based on this idea,an active SRLG-diverse path selection(ASPS)algorithm is proposed.To actively avoid selecting those SRLG links,when computing the primary path,a link that share risk with more links is assigned a larger link cost.To improve the resource utilization ratio,it is permitted that the bandwidth resources are shared among backup paths.What is more,differentiated reliability(DiR)requirements of different customers are considered in ASPS algorithm.The simulation results show that,compared with CSPS algorithm,ASPS algorithm not only increases successful protection probability but also improves resource utilization ratio.展开更多
传统的IP网络没有提供对业务的服务质量的明确支持,只是对数据流的“尽力”传输,因此在新型网络中如何满足QoS(Quality of Service)成为网络研究的热点问题。本文在分析IP QoS协议两种模型(IntServ和D iffServ)和MPLS技术的基础上提出...传统的IP网络没有提供对业务的服务质量的明确支持,只是对数据流的“尽力”传输,因此在新型网络中如何满足QoS(Quality of Service)成为网络研究的热点问题。本文在分析IP QoS协议两种模型(IntServ和D iffServ)和MPLS技术的基础上提出一种切实可行的混合模型———结合MPLS技术和D iffServ模型的HAMD模型,并给出模型的部分功能实现。使用HAMD模型的网络能够在支持多业务类型的QoS需求的同时快速转发业务。并对网络服务能力也具有良好的扩展性。展开更多
摘要This paper evaluates the performance of Internet Protocol Security (IPSec) based Multiprotocol Label Switching (MPLS) virtual private network (VPN) in a small to medium sized organization. The demand for security in data networks has been increasing owing to the high cyber attacks and potential risks associated with networks spread over distant geographical locations. The MPLS networks ride on the public network backbone that is porous and highly susceptible to attacks and so the need for reliable security mechanisms to be part of the deployment plan. The evaluation criteria concentrated on Voice over Internet Protocol (VoIP) and Video conferencing with keen interest in jitter, end to end delivery and general data flow. This study used both structured questionnaire and observation methods. The structured questionnaire was administered to a group of 70 VPN users in a company. This provided the study with precise responses. The observation method was used in data simulations using OPNET Version 14.5 Simulation software. The results show that the IPSec features increase the size of data packets by approximately 9.98% translating into approximately 90.02% effectiveness. The tests showed that the performance metrics are all well within the recommended standards. The IPSec Based MPLS Virtual private network is more stable and secure than one without IPSec.
基金supported by the National Natural Science Foundation of China(60673142)Applied Basic ResearchProject of Sichuan Province(2006J13-067).
摘要In conventional shared risk link group(SRLG)-diverse path selection(CSPS)algorithm in survivable GMPLS networks,SRLG is taken into account when selecting the backup paths,while the primary path selection method is the sarne as the algorithms without SRLG constraint.A problem of CSPS algorithm is that,after a primary path is selected,the success probability to select an SRLG-diverse backup path for it is low.If SRLG is taken into account when computing the primary path,then the probability to successfully select an SRLG-diverse backup path will be much increased.Based on this idea,an active SRLG-diverse path selection(ASPS)algorithm is proposed.To actively avoid selecting those SRLG links,when computing the primary path,a link that share risk with more links is assigned a larger link cost.To improve the resource utilization ratio,it is permitted that the bandwidth resources are shared among backup paths.What is more,differentiated reliability(DiR)requirements of different customers are considered in ASPS algorithm.The simulation results show that,compared with CSPS algorithm,ASPS algorithm not only increases successful protection probability but also improves resource utilization ratio.