Methodology for Benchmarking IPsec Gateways

Adam Tisovsky 1,* Ivan Baronak 1

1. Department of Telecommunications, Slovak University of Technology, Bratislava, Slovakia

* Corresponding author.


Received: 5 Jan. 2012 / Revised: 11 Apr. 2012 / Accepted: 3 Jun. 2012 / Published: 8 Aug. 2012

Index Terms

IPsec, benchmarking, throughput, offered load, forwarding rate, CPU utilization


The paper analyses forwarding performance of IPsec gateway over the rage of offered loads. It focuses on the forwarding rate and packet loss particularly at the gateway's performance peak and at the state of gateway's overload. It explains possible performance degradation when the gateway is overloaded by excessive offered load. The paper further evaluates different approaches for obtaining forwarding performance parameters – a widely used throughput described in RFC 1242, maximum forwarding rate with zero packet loss and us proposed equilibrium throughput. According to our observations equilibrium throughput might be the most universal parameter for benchmarking security gateways as the others may be dependent on the duration of test trials. Employing equilibrium throughput would also greatly shorten the time required for benchmarking. Lastly, the paper presents methodology and a hybrid step/binary search algorithm for obtaining value of equilibrium throughput.

Cite This Paper

Adam Tisovský, Ivan Baroňák, "Methodology for Benchmarking IPsec Gateways", International Journal of Computer Network and Information Security(IJCNIS), vol.4, no.9, pp.1-9, 2012. DOI:10.5815/ijcnis.2012.09.01


