{"id":12060,"date":"2025-08-08T02:16:19","date_gmt":"2025-08-07T17:16:19","guid":{"rendered":"https:\/\/aireviewirush.com\/?p=12060"},"modified":"2025-08-08T02:16:19","modified_gmt":"2025-08-07T17:16:19","slug":"ike-throttling-for-cloud-based-vpn-resiliency","status":"publish","type":"post","link":"https:\/\/aireviewirush.com\/?p=12060","title":{"rendered":"IKE Throttling for Cloud-based VPN Resiliency"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><em>Further Put up Contributors: Maxime Peim, <a href=\"https:\/\/blogs.cisco.com\/author\/bganne\" target=\"_blank\" rel=\"noopener\">Benoit Ganne<\/a><\/em><\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_53 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title \" >Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\" role=\"button\"><label for=\"item-6a711acb729cf\" ><span class=\"\"><span style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input aria-label=\"Toggle\" aria-label=\"item-6a711acb729cf\"  type=\"checkbox\" id=\"item-6a711acb729cf\"><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/aireviewirush.com\/?p=12060\/#Cloud-VPN_IKEv2_endpoints_exposition_to_DoS_assaults\" title=\"Cloud-VPN &amp; IKEv2 endpoints exposition to DoS assaults\">Cloud-VPN &amp; IKEv2 endpoints exposition to DoS assaults<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/aireviewirush.com\/?p=12060\/#Implementing_a_network-layer_throttling_mechanism\" title=\"Implementing a network-layer throttling mechanism\">Implementing a network-layer throttling mechanism<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/aireviewirush.com\/?p=12060\/#Minimizing_the_affect_on_respectable_customers\" title=\"Minimizing the affect on respectable customers\">Minimizing the affect on respectable customers<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/aireviewirush.com\/?p=12060\/#Offering_observability_on_high-rate_initiators_with_a_probabilistic_strategy\" title=\"Offering observability on high-rate initiators with a probabilistic strategy\">Offering observability on high-rate initiators with a probabilistic strategy<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/aireviewirush.com\/?p=12060\/#Closing_Notes\" title=\"Closing Notes\">Closing Notes<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-ae7e5f047883aba2eccaff52b2617f80\" id=\"h-cloud-vpn-amp-ikev2-endpoints-exposition-to-dos-attacks\" style=\"font-style:normal;font-weight:400\"><span class=\"ez-toc-section\" id=\"Cloud-VPN_IKEv2_endpoints_exposition_to_DoS_assaults\"><\/span>Cloud-VPN &amp; IKEv2 endpoints exposition to DoS assaults<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Cloud-based VPN options generally expose IKEv2 (Web Key Change v2) endpoints to the general public Web to assist scalable, on-demand tunnel institution for patrons. Whereas this allows flexibility and broad accessibility, it additionally considerably will increase the assault floor. These publicly reachable endpoints develop into enticing targets for Denial-of-Service (DoS) assaults, whereby adversaries can flood the important thing alternate servers with a excessive quantity of IKE site visitors.<\/p>\n<p>Past the computational and reminiscence overhead concerned in dealing with massive numbers of session initiations, such assaults can impose extreme stress on the underlying system by excessive packet I\/O charges, even earlier than reaching the applying layer. The mixed impact of I\/O saturation and protocol-level processing can result in useful resource exhaustion, thereby stopping respectable customers from establishing new tunnels or sustaining present ones \u2014 in the end undermining the provision and reliability of the VPN service.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img fetchpriority=\"high\" decoding=\"async\" width=\"2575\" height=\"1467\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/wp-content\/uploads\/ciscoblogs\/1\/2025\/08\/Ike-throttling-1.webp\" alt=\"IKE flooding on a cloud-based VPN\" class=\"lazy lazy-hidden wp-image-476443\" style=\"width:790px\"\/><noscript><img fetchpriority=\"high\" decoding=\"async\" width=\"2575\" height=\"1467\" src=\"https:\/\/blogs.cisco.com\/wp-content\/uploads\/ciscoblogs\/1\/2025\/08\/Ike-throttling-1.webp\" alt=\"IKE flooding on a cloud-based VPN\" class=\"wp-image-476443\" style=\"width:790px\"\/><\/noscript><figcaption class=\"wp-element-caption\"><em>Fig. <em>1<\/em>:\u00a0 IKE Flooding on Cloud-based VPN<\/em><\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-b8a9bb989c65a27037ac18306b20bcb1\" id=\"h-implementing-a-network-layer-throttling-mechanism\" style=\"font-style:normal;font-weight:400\"><span class=\"ez-toc-section\" id=\"Implementing_a_network-layer_throttling_mechanism\"><\/span>Implementing a network-layer throttling mechanism<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>To boost the resilience of our infrastructure towards IKE-targeted DoS assaults, we carried out a generalized throttling mechanism on the community layer to restrict the speed of IKE session initiations per supply IP, with out impacting IKE site visitors related to established tunnels. This strategy reduces the processing burden on IKE servers by proactively filtering extreme site visitors earlier than it reaches the IKE server. In parallel, we deployed a monitoring system to determine supply IPs exhibiting patterns in keeping with IKE flooding habits, enabling speedy response to rising threats. This network-level mitigation is designed to function in tandem with complementary safety on the software layer, offering a layered protection technique towards each volumetric and protocol-specific assault vectors.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"2437\" height=\"1460\" data-lazy-type=\"image\" src=\"https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2025\/07\/Ike-throttling-2.webp\" alt=\"Protecting Cloud-based VPNs using IKE Throttling\" class=\"lazy lazy-hidden wp-image-475995\" style=\"width:790px;height:auto\"\/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"2437\" height=\"1460\" src=\"https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2025\/07\/Ike-throttling-2.webp\" alt=\"Protecting Cloud-based VPNs using IKE Throttling\" class=\"wp-image-475995\" style=\"width:790px;height:auto\"\/><\/noscript><figcaption class=\"wp-element-caption\"><em>Fig. <em>2<\/em>:\u00a0 Defending Cloud-based VPNs utilizing IKE Throttling<\/em><\/figcaption><\/figure>\n<\/div>\n<p>The implementation was completed in our data-plane framework (primarily based on <a href=\"https:\/\/fd.io\/technology\/\" target=\"_blank\" rel=\"noreferrer noopener\">FD.io\/VPP \u2013 Vector Packet processor<\/a>) by introducing a brand new node within the packet-processing path for IKE packets.<\/p>\n<p>This practice node leverages the generic throttling mechanism accessible in VPP, with a balanced strategy between memory-efficiency and accuracy: Throttling choices are taken by inspecting the supply IP addresses of incoming IKEv2 packets, processing them right into a fixed-size hash desk, and verifying if a collision has occurred with previously-seen IPs over the present throttling time interval.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"2330\" height=\"1272\" data-lazy-type=\"image\" src=\"https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2025\/07\/Ike-throttling-3.webp\" alt=\"IKE Throttling in the VPP node graph \" class=\"lazy lazy-hidden wp-image-475997\" style=\"width:826px;height:auto\"\/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"2330\" height=\"1272\" src=\"https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2025\/07\/Ike-throttling-3.webp\" alt=\"IKE Throttling in the VPP node graph \" class=\"wp-image-475997\" style=\"width:826px;height:auto\"\/><\/noscript><figcaption class=\"wp-element-caption\"><em>Fig. 3: IKE Throttling within the VPP node graph<\/em><\/figcaption><\/figure>\n<\/div>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"2810\" height=\"1222\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/wp-content\/uploads\/ciscoblogs\/1\/2025\/08\/Ike-throttling-4.webp\" alt=\"IKE throttling - VPP node algorithm\" class=\"lazy lazy-hidden wp-image-476447\" style=\"width:746px;height:auto\"\/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"2810\" height=\"1222\" src=\"https:\/\/blogs.cisco.com\/wp-content\/uploads\/ciscoblogs\/1\/2025\/08\/Ike-throttling-4.webp\" alt=\"IKE throttling - VPP node algorithm\" class=\"wp-image-476447\" style=\"width:746px;height:auto\"\/><\/noscript><figcaption class=\"wp-element-caption\"><em><em>Fig. 4:\u00a0 IKE Throttling \u2013 VPP node Algorithm<\/em><\/em><\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-b62caf6e64760607cc8a96cee0062260\" id=\"h-minimizing-the-impact-on-legitimate-users\" style=\"font-style:normal;font-weight:400\"><span class=\"ez-toc-section\" id=\"Minimizing_the_affect_on_respectable_customers\"><\/span>Minimizing the affect on respectable customers<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Occasional false positives or unintended over-throttling could happen when distinct supply IP addresses collide inside the similar hash bucket throughout a given throttling interval. This case can come up because of hash collisions within the throttling knowledge construction used for price limiting. Nonetheless, <a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc7296\" target=\"_blank\" rel=\"noreferrer noopener\">the sensible affect is minimal within the context of IKEv2<\/a>, because the protocol is inherently resilient to transient failures by its built-in retransmission mechanisms. Moreover, the throttling logic incorporates periodic re-randomization of the hash desk seed on the finish of every interval. This seed regeneration ensures that the chance of repeated collisions between the identical set of supply IPs throughout consecutive intervals stays statistically low, additional decreasing the chance of systematic throttling anomalies.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"2755\" height=\"1180\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/wp-content\/uploads\/ciscoblogs\/1\/2025\/08\/Ike-throttling-5.webp\" alt=\"IKE throttling, IKE throttling reset mechanism\" class=\"lazy lazy-hidden wp-image-476448\" style=\"width:736px;height:auto\"\/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"2755\" height=\"1180\" src=\"https:\/\/blogs.cisco.com\/wp-content\/uploads\/ciscoblogs\/1\/2025\/08\/Ike-throttling-5.webp\" alt=\"IKE throttling, IKE throttling reset mechanism\" class=\"wp-image-476448\" style=\"width:736px;height:auto\"\/><\/noscript><figcaption class=\"wp-element-caption\"><em>Fig. <em>5<\/em>:\u00a0 IKE Throttling \u2013 IKE Throttling Reset Mechanism<\/em><\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-020bd0ec3afe0f741c2a3b3e75c4cc7d\" id=\"h-providing-observability-on-high-rate-initiators-with-a-probabilistic-approach\" style=\"font-style:normal;font-weight:400\"><span class=\"ez-toc-section\" id=\"Offering_observability_on_high-rate_initiators_with_a_probabilistic_strategy\"><\/span>Offering observability on high-rate initiators with a probabilistic strategy<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>To enhance the IKE throttling mechanism, we carried out an observability mechanism that retains metadata on throttled supply IPs. This gives essential visibility into high-rate initiators and helps downstream mitigation of workflows. It employs a <a href=\"https:\/\/danluu.com\/2choices-eviction\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Least Incessantly Used (LFU) 2-Random<\/strong> eviction coverage<\/a>, particularly chosen for its stability between accuracy and computational effectivity underneath high-load or adversarial situations similar to DoS assaults.<\/p>\n<p>Somewhat than sustaining a completely ordered frequency checklist, which might be pricey in a high-throughput knowledge aircraft, LFU 2-Random approximates LFU habits by randomly sampling two entries from the cache upon eviction and eradicating the one with the decrease entry frequency. This probabilistic strategy ensures minimal reminiscence and processing overhead, in addition to quicker adaptation to shifts in DoS site visitors patterns, guaranteeing that attackers with traditionally high-frequency do not stay within the cache after being inactive for a sure time period, which might affect observability on newer lively attackers (see Determine-6). The info collected is subsequently leveraged to set off further responses throughout IKE flooding situations, similar to dynamically blacklisting malicious IPs and figuring out respectable customers with potential misconfigurations that generate extreme IKE site visitors.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1500\" height=\"743\" data-lazy-type=\"image\" src=\"https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2025\/07\/Ike-throttling-6.webp\" alt=\"Conducting consecutive DoS attack phases, and comparing each phase\u2019s attacker cache presence over time\" class=\"lazy lazy-hidden wp-image-476080\" style=\"width:728px;height:auto\"\/><noscript><img loading=\"lazy\" decoding=\"async\" width=\"1500\" height=\"743\" src=\"https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2025\/07\/Ike-throttling-6.webp\" alt=\"Conducting consecutive DoS attack phases, and comparing each phase\u2019s attacker cache presence over time\" class=\"wp-image-476080\" style=\"width:728px;height:auto\"\/><\/noscript><figcaption class=\"wp-element-caption\"><em>Fig. 6: LFU vs LFU 2-Random \u2013 Conducting consecutive DoS assault phases, and evaluating every section\u2019s attacker cache presence over time<\/em><\/figcaption><\/figure>\n<\/div>\n<h2 class=\"wp-block-heading has-cisco-green-color has-text-color has-link-color wp-elements-61beb39943819d7916ededfb778008e5\" id=\"h-closing-notes\" style=\"font-style:normal;font-weight:400\"><span class=\"ez-toc-section\" id=\"Closing_Notes\"><\/span>Closing Notes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>We encourage related Cloud-based VPN providers and\/or providers exposing internet-facing IKEv2 server endpoints to proactively examine related mitigation mechanisms which might match their structure. This is able to improve programs resiliency to IKE flood assaults at a low computational value, in addition to presents essential visibility into lively high-rate initiators to take additional actions.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<p class=\"has-text-align-center\"><em>We\u2019d love to listen to what you suppose! Ask a query and keep linked with Cisco Safety on social media.<\/em><\/p>\n<p class=\"has-text-align-center\"><strong>Cisco Safety Social Media<\/strong><\/p>\n<p class=\"has-text-align-center\"><a href=\"https:\/\/www.linkedin.com\/showcase\/cisco-secure\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a><br \/><a href=\"https:\/\/www.facebook.com\/ciscosecure\/\" target=\"_blank\" rel=\"noreferrer noopener\">Fb<\/a><br \/><a href=\"https:\/\/www.instagram.com\/Ciscosecurity\/\" target=\"_blank\" rel=\"noreferrer noopener\">Instagram<\/a><br \/><a href=\"https:\/\/twitter.com\/CiscoSecure\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a><\/p>\n<p>Share:<\/p>\n<p>\n  \t<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script async defer src=\"https:\/\/platform.instagram.com\/en_US\/embeds.js\"><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Further Put up Contributors: Maxime Peim, Benoit Ganne Cloud-VPN &amp; IKEv2 endpoints exposition to DoS assaults Cloud-based VPN options generally expose IKEv2 (Web Key Change v2) endpoints to the general public Web to assist scalable, on-demand tunnel institution for patrons. Whereas this allows flexibility and broad accessibility, it additionally considerably will increase the assault floor. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":12062,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22],"tags":[],"class_list":["post-12060","post","type-post","status-publish","format-standard","has-post-thumbnail","category-iot"],"_links":{"self":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts\/12060","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=12060"}],"version-history":[{"count":1,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts\/12060\/revisions"}],"predecessor-version":[{"id":12061,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/posts\/12060\/revisions\/12061"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=\/wp\/v2\/media\/12062"}],"wp:attachment":[{"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=12060"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=12060"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aireviewirush.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=12060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}