Font Size: a A A

IPv6 Firewall Study Based On Flow Filtering Technology

Posted on:2012-09-29Degree:MasterType:Thesis
Country:ChinaCandidate:W WangFull Text:PDF
GTID:2218330374453567Subject:Computer application technology
Abstract/Summary:PDF Full Text Request
With the rapid development and wide application of internet, the network security is more and more serious. For the next generation network-IPv6 network, network security problem can't be ignored. Based on the platform of Linux, in allusion to implementing and application of IPv6 and security problems of period IPv6, the thesis designs and implements an IPv6 firewall system based on flow filtering technology. It has not only packet filtering firewall's efficiency, but also application proxy firewall's security. On the thesis, flow filtering technology is a main filtering technology, packet filtering technology is a secondary filtering technology. As the latest firewall technology, flow filtering technology integrates advantages of state inspection packet filtering technology and application proxy technology and overcome weakness of traditional firewalls. Moreover, flow filtering technology can provide more security and more efficient protective effect for application layer.The thesis focuses on solving the existing number of IPv6 firewall security risks exist, the thesis analyzes firewall primary technology in detail, packet filtering technology,application proxy technology,state inspection technology and flow filtering technology. I choose flow filtering technology, which is the main technology on my thesis; I choose flow packet filtering technology, which is the secondary technology on my theses. The messages are divided into two categories:the key packets and non-key packets. The key messages have block application data, the other are non-critical messages. While my thesis uses flow filtering module to filter the key packets, uses packet filtering module to filter Non-key packets. So it can improve the efficiency of the firewall. The thesis designs and realizes the each module about the filter, and designs an IPv6 firewall on Flow filtering technology, which chooses screened subnet system structure. The section of the firewall can be applied to research institutions, universities, manufactures and carriers'IPv6 test networks.Finally, the thesis tests filtering function of system by ping6; tests the throughput and delay of system by NetIQ Chariot tool; tests capacity of flow control by RRDtool and Cron software. The thesis analyzes its performance and discusses extend usage by test results.
Keywords/Search Tags:Network Security, IPv6, Firewall, Flow Filtering Technology
PDF Full Text Request
Related items