AIPT2 is the second version of the Abilis IP tunnel protocol. This new type of resource offers the possibility to create a tunnel with up to 6 paths, and use them for load balancing and/or for redundancy (former AIPT double path now AIPT2 multipath), as well as for backup purposes by means of dependency setting. It simplifies configurations and improves performances.
The main characteristics of AIPT2 are:
Simplified and more efficient architecture respect to AIPT. It is designed from the ground up for IP VPNs (IP in UDP tunnels).
Simplified configuration.
Strong authentication using passwords and/or ABILIS-ID (same as NPV).
Strong and fast ciphering with AES256 cipher, and use of hardware based AES cryptography when available.
Note | |
---|---|
Hardware based AES increases performances between 3x and 10x. It's presence is visible by means of DEBUG AES LSN:1 command. It is also indicated in the processor characteristics shown with the D CPUID command. Not present: [13:40:55] ABILIS_CPX: Present, Intel: [13:39:16] ABILIS_CPX: Present, VIA: [13:59:35] ABILIS_CPX: |
Embedded multipath redundancy.
Embedded load balancing among paths and multipaths.
Embedded paths backup by means of dependencies rules (client side).
Individual 'per path' speedlimit.
Opportunistic packet reordering for each IPCOS priority.
TCP-MSS-CLAMP feature to optimize TCP flows.
Ciphering and Data compression (data compression requires specific licence) controllable just on one side, the server.
Important | |
---|---|
The tunnel packets, i.e. control and encapsulated payload, that
AIPT2 sends out obey IPACL for all parameters except for
|
In the example below:
Path 1 is disabled;
Paths 4 and 5 are configured as a redundancy multipath, i.e. Packets are duplicated on both path;
Path 6 is activated when either path 2 or 3 goes DOWN;
Load balancing is performed across paths 2, 3, 4/5 as multipath, with path 6 taking place of 2 or 3 or both in case they go DOWN.
Server:
[21:56:35] ABILIS_CPX:d p ip-11
RES:Ip-11 ---------------------------------------------------------------------
- Abilis IP tunnel v.2 (AIPT2) -----------------------------------------
Run DESCR:
OPSTATE:UP LOG:NO STATE-DETECT:NORMAL
IPADD:172.020.011.205 MASK:255.255.255.000 NEIGH:000.000.000.000
REDIS:YES HIDE:NO RP:NONE IPSEC:NO VRRP:NO
NAT:VPN DIFFSERV:NO DDNS:NO
OUTBUF:250 OUTQUEUE:FAIR MTU:1500
OUTSPL:NO
INBUF:0 mru:1500 SRCV:NO
- TRFA section ---------------------------------------------------------
TRFA:NO
- IP Tunnel ------------------------------------------------------------
ROLE:SERVER CR:NO COMP:NO FRAGSIZE:1480 TRY:5 TOUT:5000
LOCKEY:ip11 LOCPORT:4011 C-TOS:0-D DLY-UP:10 THR-DN:30
REMKEY:ip11 C-IPCOS:HIGH DLY-TOUT:3
REMABILIS-ID: RS-BUF:250 D-TOS:COPY BURST:1
NUMPATHS:6 REORDER:NO D-IPCOS:COPY BURST-DLY:100
- IP Tunnel Paths ------------------------------------------------------
x MPx: OUTSPx: OUTx: LOCIPx: REMIPx:
GWx: SPL-OVHx:
--+----+-------+------+---------------+---------------------------------
1 | NOMAX AUTO * *
2 | NOMAX AUTO * *
3 | NOMAX AUTO * *
4 |A NOMAX AUTO * *
5 |A NOMAX AUTO * *
6 | NOMAX AUTO * *
Client:
[21:53:49] ABILIS_CPX:d p ip-11
RES:Ip-11 ---------------------------------------------------------------------
- Abilis IP tunnel v.2 (AIPT2) -----------------------------------------
Run DESCR:
OPSTATE:UP LOG:NO STATE-DETECT:NORMAL
IPADD:172.020.011.206 MASK:255.255.255.000 NEIGH:000.000.000.000
REDIS:YES HIDE:NO RP:NONE IPSEC:NO VRRP:NO
NAT:VPN DIFFSERV:NO DDNS:NO
OUTBUF:250 OUTQUEUE:FAIR MTU:1500
OUTSPL:NO
INBUF:0 mru:1500 SRCV:NO
- TRFA section ---------------------------------------------------------
TRFA:NO
- IP Tunnel ------------------------------------------------------------
ROLE:CLIENT FRAGSIZE:1480 TRY:5 TOUT:5000
LOCKEY:ip11 LOCPORT:4011 C-TOS:0-D DLY-UP:10 THR-DN:30
REMKEY:ip11 REMPORT:4011 C-IPCOS:HIGH DLY-TOUT:3
REMABILIS-ID: RS-BUF:250 D-TOS:0-N BURST:1
NUMPATHS:6 REORDER:AUTO D-IPCOS:COPY BURST-DLY:100
- IP Tunnel Paths ------------------------------------------------------
x MPx: OUTSPx: OUTx: LOCIPx: REMIPx:
DEPx: GWx: SPL-OVHx:
--+----+-------+------+---------------+---------------------------------
1 | NOMAX AUTO OUT-IP #
2 | NOMAX AUTO OUT-IP 172.020.002.205
3 | NOMAX AUTO OUT-IP 172.020.003.205
4 |A NOMAX AUTO OUT-IP 172.020.004.205
5 |A NOMAX AUTO OUT-IP 172.020.005.205
6 | NOMAX AUTO OUT-IP 172.020.006.205
2|3 # AUTO