|
A plethora of different connection-aware and content-aware
appliances - such as VPN concentrators, content switches,
and load balancers - is being deployed in private networks
and in data centers to satisfy the security and content
switching needs of enterprises. In response, manufacturers
are combining the capabilities of this equipment into
integrated devices such as IPsec-capable security routers,
integrated security gateways, and all-in-one Data Center
devices.
Validation of these devices can be complex. Although
they may include IPsec, it is no longer adequate to
test IPsec capabilities in isolation. Because the devices
perform filtering or switching based on layer 4 to 7
information, it is unacceptable to merely test using
instrumented layer 2 or 3 packets. The layer 4-7 capabilities
must be tested together with IPsec to fully stress the
device in a realistic manner.
This paper discusses IPsec test issues and shows you
how to measure the latest security devices using a mix
of real application traffic over IPsec tunnels. You
will learn how to accurately gauge performance
from the perspective of the end user's experience.
|