检索规则说明:AND代表“并且”;OR代表“或者”;NOT代表“不包含”;(注意必须大写,运算符两边需空一格)
检 索 范 例 :范例一: (K=图书馆学 OR K=情报学) AND A=范并思 范例二:J=计算机应用与软件 AND (U=C++ OR U=Basic) NOT M=Visual
机构地区:[1]杭州职业技术学院 [2]苏州大学网络中心
出 处:《微计算机信息》2009年第9期96-98,共3页Control & Automation
摘 要:为了解决防火墙对IPv6协议的兼容及对内部网络之间安全的保障问题,本文设计实现了基于Intel Xscale IXP425处理器的嵌入式IPv6防火墙。该防火墙可以通过WEB远程加以管理,对IPv6网络包和IPv4网络包均可以进行良好的过滤。防火墙能够判断出网络包的协议类型,分别加以处理,实行动态包过滤,并可以解决IPv6分片攻击问题。防火墙硬件系统基于IXP425处理器,该处理器具有良好的网络特性,拥有分布式处理架构,并行方式执行其指令流。处理器的高速性保证了嵌入式IPv6防火墙处理网络数据包的高效性。防火墙软件系统基于Linux的Netfilter框架,该框架对网络包的处理体系十分成熟,从而保证了嵌入式IPv6防火墙运行时的稳定性和准确性。In order to solve the problem of the firewall's compatibility to IPv6 protocol and the security among the internal nets, the paper designs and implements the embedded IPv6 firewaU based on Intel XScale IXP425 network processor .This firewall can be managed by visting WEB page from remote machine and can filter both Ipv6 packet and IPv4 packet. It can identify the protocol of the net packet and process it in respective ways with the main method of Dynamic Packet Filtering.The firewall also solves the problem of IPv6 fragmentation. The hardware system of the firewall is based on IXP425 network processor with good network characteristic, whose distributed processing framework and parallel implementation of its order flows ensure the embedded IPv6 firewall processes the data packet with high speed. The software system of the firewall is based on the Netfilter framework of the Linux with a so- phisticated system to process the network packet.The framework support the embedded IPv6 firewall run with high stability and veracity.
分 类 号:TP393.08[自动化与计算机技术—计算机应用技术]
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在载入数据...
正在链接到云南高校图书馆文献保障联盟下载...
云南高校图书馆联盟文献共享服务平台 版权所有©
您的IP:216.73.216.13