2026/6/20
Mehdi Khazaei

Mehdi Khazaei

Academic rank: Assistant Professor
ORCID:
Education: PhD.
H-Index:
Faculty: Faculty of Information Technology
ScholarId:
E-mail: m.khazaei [at] kut.ac.ir
ScopusId:
Phone: 08338305041
ResearchGate:

Research

Title
A Lightweight Distributed Firewall Architecture Using SSH and UFW
Type
JournalPaper
Keywords
Distributed Firewall, Secure Shell, Uncomplicated Firewall, IPsec
Year
2025
Journal Majlesi Journal of Telecommunication Devices (MJTD)
DOI
Researchers Mehdi Khazaei ، ُSoroush Nekouzadeh

Abstract

The modern networks demand rapid, scalable, and efficient enforcement of security policies at distributed endpoints. This study presents a lightweight distributed firewall framework leveraging Secure Shell (SSH) and Uncomplicated Firewall (UFW) to address these requirements. In the centralized deployment, a core server transmits encrypted security rules to distributed hosts via SSH, with each node applying policies locally using UFW. In the decentralized mode, nodes exchange firewall rules directly through secure SSH channels. The proposed architecture is benchmarked against conventional IPsec-based systems, assessing rule propagation latency, bandwidth consumption, computational efficiency, scalability, and robustness under network stress. Experimental evaluations across heterogeneous environments demonstrate that the SSH-UFW model propagates rules up to 60% faster than IPsec on average. Moreover, the framework exhibits lower resource utilization and enhanced operational stability under degraded network conditions. These findings suggest that the SSH-based distributed firewall offers a secure, efficient, and scalable alternative to IPsec for real-world deployment.