Articles

INVESTIGATION OF IPsec IKEv2 IMPLEMENTATION BASED ON vESR

Download PDF Article on eLIBRARY.RU

Abstract

The article presents an experimental study of the IPsec IKEv2 protocol implementation on the virtual extended routing switch platform, vESR, in the context of NFV/SDN-based virtualized network deployment. The relevance of the study is determined by the need to provide secure tunneling between distributed network nodes under the limited computing resources of a virtual infrastructure. The main research problem is the influence of cryptographic algorithm selection and the number of simultaneously established tunnels on throughput, CPU utilization, and the stability of the vESR control plane. During the study, a test environment was deployed, including a vESR virtual router, a peer node with IPsec IKEv2 support, and a network traffic generator. Load testing was used to evaluate performance under different cryptographic profiles, including AES-128, AES-256, GCM, and CBC modes. The behavior of the system was also analyzed when the number of simultaneous IPsec tunnels was increased. The obtained results demonstrated a significant trade-off between cryptographic strength and performance: stronger algorithms increase CPU load and reduce scalability margins. It was found that the control plane load grows nonlinearly as the number of tunnels increases, which limits stable system operation. Based on the experimental data, practical recommendations are proposed for selecting an optimal IPsec IKEv2 configuration on the vESR platform in order to balance security requirements, functionality, and efficient resource utilization.

Online viewer

References

  1. Uymin, A. G. The use of domestic Eltex and EcoRouter network equipment in the frame-work of specialty 09.02.06 "Network and system administration". Issues of import sub-stitution and training of qualified personnel in network equipment / A. G. Uymin, I. M. Tolmachev // Automation and informatization of the fuel and energy complex. – 2025. – № 11(628). – Pp. 58-62. – EDN DMHQJU.
  2. Kaufman, C. Internet Key Exchange Protocol Version 2 (IKEv2) [Electronic resource] : RFC 7296 / C. Kaufman, P. Hoffman, Y. Nir [et al.]. – IETF, 2014. – URL: https://datatracker.ietf.org/doc/html/rfc7296 (date of request: 12.12.2025).
  3. Nir, Y. IPsec Cluster Problem Statement [Electronic resource] : RFC 6027 / Y. Nir. – IETF, 2010. – URL: https://datatracker.ietf.org/doc/html/rfc6027 (date of request: 12.12.2025).
  4. Sheffer, Y. Additional EAP Methods for IKEv2 [Electronic resource] : RFC 5106 / Y. Shef-fer, S. Fluhrer. – IETF, 2008. – URL: https://datatracker.ietf.org/doc/html/rfc5106 (date of request: 12.12.2025).
  5. Kent, S., & Seo, K. (2005). Security architecture for the Internet Protocol (RFC 4301). IETF. https://www.rfc-editor.org/rfc/rfc4301.html
  6. Wouters, P., Migault, D., Mattsson, J., Nir, Y., & Kivinen, T. (2017). Cryptographic algo-rithm implementation requirements and usage guidance for ESP and AH (RFC 8221). IETF. https://www.rfc-editor.org/rfc/rfc8221.html
  7. Barker, E., Dang, Q., Frankel, S., Scarfone, K., & Wouters, P. (2020). Guide to IPsec VPNs (NIST SP 800-77 Rev. 1). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-77r1

License

Copyright (c) 2025 V. S. Skoromnikov , A. P. Andryukhina (Authors)

Keywords