ForCES-Based Firewall with Stateful Packet Inspection

Ligang Dong,Feng Luo,Weiming Wang,Ke Chen
DOI: https://doi.org/10.4028/www.scientific.net/amr.216.440
2011-01-01
Advanced Materials Research
Abstract:In order to meet the extensibility and flexibility requirement of next generation network, ForCES working group of IETF proposes an architecture with the separation of Forwarding Element and Control Element. A firewall with ForCES architecture will have enough flexibility on security function extensibility. This paper not only designs the ForCES architecture of status package inspection firewall and related LFB (Logic Functional Block), but also implements a prototype system and carries out tests and analysis. The experiment result testifies the feasibility of ForCES specification and provides the important technical parameter for the ForCES security application.
What problem does this paper attempt to address?