Case Study: Professional Services Firm Ensures Secure and Successful IPv6 Deployments for Customers with the OptiView XG Network Analysis Tablet

Size: px
Start display at page:

Download "Case Study: Professional Services Firm Ensures Secure and Successful IPv6 Deployments for Customers with the OptiView XG Network Analysis Tablet"

Transcription

1 CASE STUDY Case Study: Professional Services Firm Ensures Secure and Successful IPv6 Deployments for Customers with the OptiView XG Network Analysis Tablet At a Glance: Customer: Nephos6 Industry: Professional Services Location: Raleigh, NC Challenge: Quickly build a network capable of demonstrating multiple key IPv6 technologies in support of customer training and transaction programs. Result: The OptiView XG Network Analysis Tablet reduced deployment time by providing fast and accurate device discovery, identification of tunneling protocols, and easy-touse tools for troubleshooting integration issues. Product: OptiView XG Network Analysis Tablet Click to View 1 of 5

2 Overview IPv6 adoption is accelerating globally. Integrators, long bereft of adequate IPv6 support in IT infrastructure, are demanding feature parity to support nextgeneration network rollouts. In addition to routers, operating systems, and other standard IT infrastructure, network engineers and technicians need IPv6- capable monitoring and analysis tools. NETSCOUT OptiView XG Network Analysis Tablet, already a staple tool in many organizations, is ready. With capabilities for IPv6 network discovery, tunneling protocol identification, router advertisement analysis, and IPv6 services detection, OptiView XG is an invaluable aid in supporting IPv6 deployment, troubleshooting integration issues, and helping identify unintentional IPv6 deployment. The Review In February 2011, the Internet Assigned Numbers Authority (IANA) distributed the last five /8 (historically referred to as Class A ) IPv4 address blocks to the Regional Internet Registries (RIR). This event signaled the beginning of the end for the IPv4-based Internet and heralded the start of the global transition to the next generation Internet protocol, IPv6. Standardized in 1995, IPv6 is designed to enhance the Internet protocol and address the issue of IP resource exhaustion, but had never found significant purchase in the marketplace for a variety of economic and technology reasons. While some technology camps believed Network Address Translation (NAT) would suffice, Internet scalability requirements and the ever increasing complexity of multiple NATted environments make a compelling case for IPv6 adoption now. Despite a lack of widespread interest in IPv6, numerous organizations, including world governments, large IT product companies, major service providers, and some early adopters blazed the trail of IPv6 adoption. The Internet Engineering Task Force (IETF) developed mechanisms to support the co-existence of IPv4 and IPv6 and to mitigate some of the financial burden of migration. IT vendors incorporated support for IPv6 in many of their mainstream products. Emerging from this collective effort of the early adopters are methodologies and best practices for the secure and efficient deployment of IPv6. Nephos6, Inc. is an IPv6 and Cloud Computing Professional Services firm located in Raleigh, NC. The company was founded by a number of industry experts with significant deployment experience in IPv6 (and cloud computing). The company uses a five-stage methodology to manage the IPv6 integration effort for enterprises and service providers. The first four stages involve cultivating a common understanding of the current environment, aligning business and technical drivers, assessing the IT infrastructure and support systems for IPv6 support capability, and developing architectures and plans for deployment. The fifth stage, Implementation, sees the rollout of IPv6, in a controlled but progressive manner. The ultimate goal environment for any IPv6 adoption program is to enabled dual stack (both IPv4 and IPv6 running concurrently on the same device) on all devices throughout the organization. But the path to achieving a dual stack installation is rarely the same from organization to organization. Despite different approaches to the end state, all well-managed deployments embody these approaches: 1. Validate and test designs configurations and architectures are evaluated in isolated labs first and then systematically deployed in the production environment. 2. Manage and troubleshoot deployments nothing ever goes perfectly the first time. Invariably equipment malfunctions, human error, or Murphy s Law interfere during deployments and require systematic troubleshooting to correct. 3. Monitor for unauthorized/rogue IPv6 Devices IPv6 is supported in most modern IT devices and operating systems, enabled by default in some cases. Unintentional deployment is a security issue and needs to be monitored and managed. A critical element of the implementation process is effective tools to support these key activities. Nephos6 uses packet capture software and network analysis tools but wanted to see if the market offered a comprehensive, portable, and remotely accessible tool. Yurie Rich, chief operating officer of Nephos6 recalls, It was interesting. I interacted with NETSCOUT all the way back in 2000 when I started working with IPv6, then again sometime in 2007 or 2008 as their OptiView team was working towards JITC [Joint Interoperability Test Command] IPv6 certification. I guess it was kismet when they reached out to our CEO, Ciprian (Chip) Popoviciu, to see if we d be interested in evaluating the XG. After reviewing the OptiView XG s capabilities on paper, John Spence, vice president of IP Services at Nephos6, developed a series of trials to test OptiView XG s capabilities. John recalls, Chip, Yurie and I spent some time thinking about the commonality of the deployments we d been involved with. No two are the same, but generally you see testing in the lab, a controlled rollout (or prototype or pilot or all of these) into the production environment using one or more transition technologies, then testing and remediation of any problems. That process is continuously evolved until the organization ends up with the optimal target architecture that is operationally sound and dual-stack enabled. The OptiView XG contains a robust discovery capability, the ability to capture IPv6 tunnel traffic and identify the type of transition mechanism being used. It can also identify a number of IPv6 services types a node is offering, and an analysis of router advertisements. Collectively these features provided a valuable tool chest to support Nephos6 common requirements. 2 of 5

3 Leveraging the Network and Device Discovery Feature Figure 1 is a very simplified diagram of a typical enterprise environment. It consists of three disparate campus environments, a data center, and centralized access to the Internet. John developed a lab environment that mirrored this architecture and identified touch points to connect the OptiView XG. Most IPv6 deployments start with a prototype conducted in a lab. The first step was to leverage its discovery capability. Figure 1: Example Enterprise Architecture The lab started as IPv4-only and then IPv6 is enabled on a few devices. The OptiView XG allows both onsubnet device discovery, and through some configuration parameters, discovery of off-subnet devices as well. In IPv6 deployments, most enterprises (and service providers) will likely want a managed IPv6 address space - meaning the use of DHCPv6. Information provided by the Discovery process will verify that nodes are using properly obtained IPv6 address configuration information. The Discovery process also categorizes discovered nodes as a router, server, switch, or end node. Figure 2 is a sample screen capture of the OptiView XG Discovery user interface from the lab on one subnet. Figure 2: OptiView XG Network and Device Discovery Interface 3 of 5

4 The highlighted device is a server on this particular LAN segment. The IPv6 address space is highly diversified. In addition to having a number of address types (unicast, multicast, anycast - like IPv4), there are address scopes (such as link local - identifiable here as fe80::82c:6ff:fe55:1c2b). And, just to make things a bit more interesting, IPv6 addresses can be derived through a number of processes. Here, the upstream router is configured to use address autoconfiguration and send router advertisements to the node, which is properly configuring its IPv6 address based partly on information contained in the RA. The preference in this case is an address configured using the Extended Unique Identifier (EUI-64) process. This is verified by examining the last 64 bits, which have the hex characters FF FE placed in the middle of the MAC address. Combined with the prefix of 2001:db8:ff:70::/64,the interface created 2001:db8:ff:70:82c:6ff:fe55:1c 2b as its IPv6 address The Nephos6 team quickly recognized several benefits of the OptiView s Discovery capability: 1. Validation of on-link device IPv6 configuration recall that one of the common requirements of all IPv6 integration processes is the need to test and validate deployments. The information supplied by the OptiView XG clearly yields solid information to verify IPv6 connectivity, IPv6 address information, and, with further analysis, what specific nodes are doing in terms of open ports and service offerings. 2. Identification of rogue or unintentional IPv6 deployment certainly anytime the discovery process is run and IPv6 devices are present on the link, the OptiView XG will find and report them. 3. Remote access means remote expertise IPv6 skill sets take some time to accrue. It is not uncommon for field personnel, who do much of the heavy lifting in the IPv6 integration process, to be last on the list for IPv6 training. The remote access capability of the OptiView XG means that IPv6 savvy engineers can collaborate with field engineers to not only conduct testing and validation exercises, but also continue the IPv6 knowledge transfer process. Integrating IPv6 Once base configurations are implemented and the environment is operating as predicted, the next step is to expand the deployment to other areas of the network. In the lab example, as shown in Figure 3, IPv6 is deployed in another section of the campus and the two islands are connected with a manually configured tunnel, commonly known as a 6in4 tunnel. At each tunnel end point, the routers are dual stacked - supporting both IPv4 and IPv6 simultaneously. The IPv6-in-IPv4 tunnels are manually configured on each router. The OptiView XG is a very effective IPv6 tunneling identification tool. Figure 4 shows a screen capture of the IPv6 Tunneling Protocol user interface, which is found under the Traffic Analysis tab. In this particular example, John was able to place the OptiView XG discovery interface on a SPAN (monitor) port over which the IPv6 tunneled traffic was passing. Monitoring the traffic on that port, the OptiView XG automatically identifies the tunnel type at 6in4. The capture also identifies the tunnel end points, which is extremely important in the Figure 4: IPv6 Tunneling Protocol Screen Ca detecting and eliminating rogues scenario. With the information provided on this screen, I can identify this traffic as one of my intended deployments. If I don t recognize those endpoints, it is easy to track them down through the DDI (DHCP, DNS, IP Address Management) infrastructure and work with IT to bring those deployments under control commented John. The OptiView XG s IPv6 Discovery capability is not limited to 6in4 tunnels. It supports identification of the most widely utilized tunnels leveraged in industry today (See table below). This is exceptionally important as most modern operating systems have IPv6 enabled by default and the stacks are aggressive about obtaining IPv6 connectivity via established transition mechanisms. As an example, Windows 7 has IPv6 enabled by default and in IPv4-only environment will attempt to establish IPv6 capability via 6to4, ISATAP, and Teredo transition mechanisms. 4 of 5

5 2017 NETSCOUT. Rev: 02/02/2017 9:43 am 5 of 5

IPv6 Feature Facts

IPv6 Feature Facts 12.1.2 IPv6 Feature Facts The current IP addressing standard, version 4, will eventually run out of unique addresses, so a new system is being developed. It is named IP version 6 or IPv6. You should know

More information

IPv6 Enablement for Enterprises. Waliur Rahman Managing Principal, Global Solutions April, 2011

IPv6 Enablement for Enterprises. Waliur Rahman Managing Principal, Global Solutions April, 2011 IPv6 Enablement for Enterprises Waliur Rahman Managing Principal, Global Solutions April, 2011 PROPRIETARY STATEMENT This document and any attached materials are the sole property of Verizon and are not

More information

Transitioning to IPv6

Transitioning to IPv6 Transitioning to IPv6 麟瑞科技區域銷售事業處副處長張晃崚 CCIE #13673 2007 Cisco Systems, Inc. All rights reserved. ICND2 v1.0 7-1 IPv4 and IPv6 Currently, there are approximately 1.3 billion usable IPv4 addresses available.

More information

IPv6 Implementation Best Practices For Service Providers

IPv6 Implementation Best Practices For Service Providers IPv6 Implementation Best Practices For Service Providers Brandon Ross Chief Network Architect and CEO 2013 Utilities Telecom Council Network Utility Force www.netuf.net @NetUF RFC 6540 - IPv6 Support Required

More information

Federal Agencies and the Transition to IPv6

Federal Agencies and the Transition to IPv6 Federal Agencies and the Transition to IPv6 Introduction Because of the federal mandate to transition from IPv4 to IPv6, IT departments must include IPv6 as a core element of their current and future IT

More information

Planning for Information Network

Planning for Information Network Planning for Information Network Lecture 7: Introduction to IPv6 Assistant Teacher Samraa Adnan Al-Asadi 1 IPv6 Features The ability to scale networks for future demands requires a limitless supply of

More information

CSCI-1680 Network Layer:

CSCI-1680 Network Layer: CSCI-1680 Network Layer: Wrapup Rodrigo Fonseca Based partly on lecture notes by Jennifer Rexford, Rob Sherwood, David Mazières, Phil Levis, John JannoA Administrivia Homework 2 is due tomorrow So we can

More information

IPv6 Technical Challenges

IPv6 Technical Challenges IPv6 Technical Challenges Peter Palúch, CCIE #23527, CCIP University of Zilina, Slovakia Academy Salute, April 15 th 16 th, Bucharest IPv6 technical challenges What challenges do I meet if I decide to

More information

IPv6 Addressing. There are three types of IPV6 Addresses. Unicast:Multicast:Anycast

IPv6 Addressing. There are three types of IPV6 Addresses. Unicast:Multicast:Anycast IPv6 Addressing There are three types of IPV6 Addresses. Unicast:Multicast:Anycast Unicast IPv6 addresses A unicast address identifies a single interface within the scope of the type of unicast address.

More information

IPv6 migration challenges and Security

IPv6 migration challenges and Security IPv6 migration challenges and Security ITU Regional Workshop for the CIS countries Recommendations on transition from IPv4 to IPv6 in the CIS region, 16-18 April 2014 Tashkent, Republic of Uzbekistan Desire.karyabwite@itu.int

More information

Expert Reference Series of White Papers. IP Version 6 Address Types

Expert Reference Series of White Papers. IP Version 6 Address Types Expert Reference Series of White Papers IP Version 6 Address Types 1-800-COURSES www.globalknowledge.com IP Version 6 Address Types Joe Rinehart, MBA, CCIE #14256, CCNP/DP/VP Introduction In 1998, the

More information

Results of a Security Assessment of the Internet Protocol version 6 (IPv6)

Results of a Security Assessment of the Internet Protocol version 6 (IPv6) Results of a Security Assessment of the Internet Protocol version 6 (IPv6) Fernando Gont DEEPSEC 2011 Conference Vienna, Austria, November 15-18, 2011 About... I have worked in security assessment of communication

More information

Comcast IPv6 Trials NANOG50 John Jason Brzozowski

Comcast IPv6 Trials NANOG50 John Jason Brzozowski Comcast IPv6 Trials NANOG50 John Jason Brzozowski October 2010 Overview Background Goals and Objectives Trials Observations 2 Background Comcast IPv6 program started over 5 years ago Incrementally planned

More information

CCNA Questions/Answers IPv6. Select the valid IPv6 address from given ones. (Choose two) A. FE63::0043::11:21 B :2:11.1 C.

CCNA Questions/Answers IPv6. Select the valid IPv6 address from given ones. (Choose two) A. FE63::0043::11:21 B :2:11.1 C. Select the valid IPv6 address from given ones. (Choose two) A. FE63::0043::11:21 B. 191.2.1.2:2:11.1 C. 2001::98 D. 2002:c0a8:101::42 E. :2001:: F. 2002.cb0a:3cdd:1::1 Answer: C, D. 2013 1 Which method

More information

Sony Adopts Cisco Solution for Global IPv6 Project

Sony Adopts Cisco Solution for Global IPv6 Project Customer Case Study Sony Adopts Cisco Solution for Global IPv6 Project Sony aims to accelerate global collaboration and business across business units to realize goal of "One Sony." EXECUTIVE SUMMARY Customer

More information

MIGRATION OF INTERNET PROTOCOL V4 TO INTERNET PROTOCOL V6 USING DUAL-STACK TECHNIQUE

MIGRATION OF INTERNET PROTOCOL V4 TO INTERNET PROTOCOL V6 USING DUAL-STACK TECHNIQUE MIGRATION OF INTERNET PROTOCOL V4 TO INTERNET PROTOCOL V6 USING DUAL-STACK TECHNIQUE 1 SHEETAL BORSE, 2 MRUDUL DIXIT 1,2 Department of Electronics and Telecommunication, Cummins College of Engineering

More information

Unit 5 - IPv4/ IPv6 Transition Mechanism(8hr) BCT IV/ II Elective - Networking with IPv6

Unit 5 - IPv4/ IPv6 Transition Mechanism(8hr) BCT IV/ II Elective - Networking with IPv6 5.1 Tunneling 5.1.1 Automatic Tunneling 5.1.2 Configured Tunneling 5.2 Dual Stack 5.3 Translation 5.4 Migration Strategies for Telcos and ISPs Introduction - Transition - the process or a period of changing

More information

How Cisco IT Is Accelerating Adoption of IPv6

How Cisco IT Is Accelerating Adoption of IPv6 Cisco IT Case Study How Cisco IT Is Accelerating Adoption of IPv6 Priority projects are IPv6-based public website and end-to-end reference implementation. Cisco IT Case Study / Borderless Networks / IPv6:

More information

Lecture 7 Overview. IPv6 Source: Chapter 12 of Stevens book Chapter 31 of Comer s book

Lecture 7 Overview. IPv6 Source: Chapter 12 of Stevens book Chapter 31 of Comer s book Last Lecture Lecture 7 Overview Name and address conversions This Lecture IPv6 Source: Chapter 12 of Stevens book Chapter 31 of Comer s book Next Lecture Broadcast and multicast sockets Source: Chapters

More information

OSI Data Link & Network Layer

OSI Data Link & Network Layer OSI Data Link & Network Layer Erkki Kukk 1 Layers with TCP/IP and OSI Model Compare OSI and TCP/IP model 2 Layers with TCP/IP and OSI Model Explain protocol data units (PDU) and encapsulation 3 Addressing

More information

IPv4/v6 Considerations Ralph Droms Cisco Systems

IPv4/v6 Considerations Ralph Droms Cisco Systems Title IPv4/v6 Considerations Ralph Droms Cisco Systems Agenda Motivation for IPv6 Review of IPv6 Impact of differences Tools and techniques Why IPv6? More addresses More addresses More addresses Security,

More information

Internet of Things (IOT) Things that you do not know about IOT

Internet of Things (IOT) Things that you do not know about IOT 1 Internet of Things (IOT) Things that you do not know about IOT Technical Track Inspiring People Connecting Ideas SingTel Group Learning Fiesta 6 Sep 2013, 11.30am 12.30pm Progreso Networks (S) Pte Ltd

More information

Guide to TCP/IP Fourth Edition. Chapter 11: Deploying IPv6

Guide to TCP/IP Fourth Edition. Chapter 11: Deploying IPv6 Guide to TCP/IP Fourth Edition Chapter 11: Deploying IPv6 Objectives Explain IPv6 deployment requirements and considerations Plan an IPv6 deployment, including success criteria, architectural decisions,

More information

ProDeploy Suite. Accelerate enterprise technology adoption with expert deployment designed for you

ProDeploy Suite. Accelerate enterprise technology adoption with expert deployment designed for you Accelerate enterprise technology adoption with expert deployment designed for you 1 Shift resources to innovate and drive better business outcomes The landscape faced by IT managers and business leaders

More information

IP version 6. The not so new next IP version. dr. C. P. J. Koymans. Informatics Institute University of Amsterdam.

IP version 6. The not so new next IP version. dr. C. P. J. Koymans. Informatics Institute University of Amsterdam. IP version 6 The not so new next IP version dr. C. P. J. Koymans Informatics Institute University of Amsterdam February 5, 2008 dr. C. P. J. Koymans (UvA) IP version 6 February 5, 2008 1 / 35 1 Rationale

More information

MUM Lagos Nigeria Nov 28th IPv6 Demonstration By Mani Raissdana

MUM Lagos Nigeria Nov 28th IPv6 Demonstration By Mani Raissdana MUM Lagos Nigeria Nov 28th IPv6 Demonstration By Mani Raissdana Mani Raissdana MikroTik Certified Trainer CTO & Co-Founder of Being in IT technology business roughly around 14 years Support & instruct

More information

Carl Harris Chief Technology Officer Virginia Tech IT

Carl Harris Chief Technology Officer Virginia Tech IT Carl Harris Chief Technology Officer Virginia Tech IT Timeline 1997 6Bone experimentation between VT Department of Electrical Engineering and IT division 1998 VT has Early Field Trial IPv6 firmware running

More information

IPv6 tutorial. RedIRIS Miguel Angel Sotos

IPv6 tutorial. RedIRIS Miguel Angel Sotos IPv6 tutorial RedIRIS Miguel Angel Sotos miguel.sotos@rediris.es Agenda History Why IPv6 IPv6 addresses Autoconfiguration DNS Transition mechanisms Security in IPv6 IPv6 in Windows and Linux IPv6 now 2

More information

Migration to IPv6 from IPv4. Is it necessary?

Migration to IPv6 from IPv4. Is it necessary? Introduction Today Internet plays a big role in every aspect of our lives and IP acted as an important pillar of Internet. Since its inception the Internet has reached almost all corners of globe and it

More information

Accelerate Your Enterprise Private Cloud Initiative

Accelerate Your Enterprise Private Cloud Initiative Cisco Cloud Comprehensive, enterprise cloud enablement services help you realize a secure, agile, and highly automated infrastructure-as-a-service (IaaS) environment for cost-effective, rapid IT service

More information

IPv6 in Campus Networks

IPv6 in Campus Networks IPv6 in Campus Networks Dave Twinam Manager, Technical Marketing Engineering Internet Systems Business Unit dtwinam@cisco.com Cisco Twinam IPv6 Summit 2003 Cisco Systems, Inc. All rights reserved. 1 IPv6

More information

IPv6 Migration Framework Case of Institutions in Ethiopia

IPv6 Migration Framework Case of Institutions in Ethiopia IPv6 Migration Framework Case of Institutions in Ethiopia Kidist Mekonnen Zemen Bank, Addis Ababa, Ethiopia kidistmt@yahoo.com Taye Abdulkadir HiLCoE School of Computer Science and Technology, Addis Ababa,

More information

IPv6 Security (Theory vs Practice) APRICOT 14 Manila, Philippines. Merike Kaeo

IPv6 Security (Theory vs Practice) APRICOT 14 Manila, Philippines. Merike Kaeo IPv6 Security (Theory vs Practice) APRICOT 14 Manila, Philippines Merike Kaeo merike@doubleshotsecurity.com Current IPv6 Deployments Don t break existing IPv4 network Securing IPv6 Can t secure something

More information

IPv6 Next generation IP

IPv6 Next generation IP Seminar Presentation IPv6 Next generation IP N Ranjith Kumar 11/5/2004 IPv6 : Next generation IP 1 Network Problems Communication Problem Identification Problem Identification of Networks Logical Addressing

More information

DHCPv6 OPERATIONAL ISSUES Tom Coffeen 4/7/2016

DHCPv6 OPERATIONAL ISSUES Tom Coffeen 4/7/2016 1 2016 2013 Infoblox Inc. All Inc. Rights All Reserved. Rights Reserved. DHCPv6 OPERATIONAL ISSUES Tom Coffeen 4/7/2016 ABOUT THE PRESENTER Tom Coffeen IPv6 Evangelist Infoblox @ipv6tom tom@ipv6.works

More information

Chapter 7: IP Addressing CCENT Routing and Switching Introduction to Networks v6.0

Chapter 7: IP Addressing CCENT Routing and Switching Introduction to Networks v6.0 Chapter 7: IP Addressing CCENT Routing and Switching Introduction to Networks v6.0 CCNET v6 13 Chapter 7 - Sections & Objectives 7.1 IPv4 Network Addresses Convert between binary and decimal numbering

More information

Next Generation IPv6 Cyber Security Protection Through Assure6i TM Product Line

Next Generation IPv6 Cyber Security Protection Through Assure6i TM Product Line Next Generation IPv6 Cyber Security Protection Through Assure6i TM Product Line Designed to Prevent, Detect, and Block Malicious Attacks on Both IPv4 and IPv6 Networks TM Introduction With the exponential

More information

6421A: Configuring and Troubleshooting a Windows Server 2008 Network Infrastructure

6421A: Configuring and Troubleshooting a Windows Server 2008 Network Infrastructure www.peaksolutions.com 6421A: Configuring and Troubleshooting a Windows Server 2008 Network Infrastructure Course 6421A: Five days; Instructor-Led Introduction This five-day instructor-led course provides

More information

FUNDAMENTALS OF IPV6. June 18, 2014

FUNDAMENTALS OF IPV6. June 18, 2014 FUNDAMENTALS OF IPV6 June 18, 2014 SCTE LIVE LEARNING Monthly Professional Development service Generally Hot Topics or Topics of high interest to the industry Vendor Agnostic No product promotion Free

More information

OSI Data Link & Network Layer

OSI Data Link & Network Layer OSI Data Link & Network Layer Erkki Kukk 1 Layers with TCP/IP and OSI Model Compare OSI and TCP/IP model 2 Layers with TCP/IP and OSI Model Explain protocol data units (PDU) and encapsulation 3 Addressing

More information

Encouraging the deployment of IPv6 in the developing countries

Encouraging the deployment of IPv6 in the developing countries Encouraging the deployment of IPv6 in the developing countries ITU Regional Workshop for the CIS countries Recommendations on transition from IPv4 to IPv6 in the CIS region, 16-18 April 2014 Tashkent,

More information

SECURITY IN AN IPv6 WORLD MYTH & REALITY. RIPE 68 Warsaw May 2014 Chris Grundemann

SECURITY IN AN IPv6 WORLD MYTH & REALITY. RIPE 68 Warsaw May 2014 Chris Grundemann SECURITY IN AN IPv6 WORLD MYTH & REALITY RIPE 68 Warsaw May 2014 Chris Grundemann WHO AM I? DO Director @ Internet Society CO ISOC Founding Chair RMv6TF Board NANOG PC NANOG-BCOP Chair IPv6 Author (Juniper

More information

Executive Summary...1 Chapter 1: Introduction...1

Executive Summary...1 Chapter 1: Introduction...1 Table of Contents Executive Summary...1 Chapter 1: Introduction...1 SSA Organization... 1 IRM Strategic Plan Purpose... 3 IRM Strategic Plan Objectives... 4 Relationship to Other Strategic Planning Documents...

More information

DATA SHEETS. Unpublished. Datasheet: OneTouch AT 10G Network Assistant Performance Testing

DATA SHEETS. Unpublished. Datasheet: OneTouch AT 10G Network Assistant Performance Testing DATA SHEETS Unpublished Datasheet: OneTouch AT 10G Network Assistant Performance Testing Ensure that newly installed or upgraded networks meet SLA objectives and are ready for new high-bandwidth applications

More information

IPv6. Dispelling the Magic

IPv6. Dispelling the Magic IPv6 Dispelling the Magic Board Chairman RIPE NCC 1 Why the Title? 96 more bits. No Magic Gaurab Raj Upadhaya 2 Agenda RIPE NCC Background to IPv6 History of IPv6 Why Deploy Ipv6? Where are we Conclusions

More information

This document is exclusive property of Cisco Systems, Inc. Permission is granted to print and copy this document for non-commercial distribution and

This document is exclusive property of Cisco Systems, Inc. Permission is granted to print and copy this document for non-commercial distribution and This document is exclusive property of Cisco Systems, Inc. Permission is granted to print and copy this document for non-commercial distribution and exclusive use by instructors in the CCNP: Building Scalable

More information

IPv6 Addressing Guide. Revision: H2CY10

IPv6 Addressing Guide. Revision: H2CY10 IPv6 Addressing Guide Revision: H2CY10 Who Should Read This Guide Related Documents Before reading this guide LAN Deployment Guide This document is for the reader who: Wants a general understanding of

More information

Deploy CGN to Retain IPv4 Addressing While Transitioning to IPv6

Deploy CGN to Retain IPv4 Addressing While Transitioning to IPv6 White Paper Deploy CGN to Retain Addressing While Transitioning to IPv6 The IANA ran out of addresses to allocate in February 2011, and the Regional Internet Registries (RIR) will have assigned most of

More information

OSI Data Link & Network Layer

OSI Data Link & Network Layer OSI Data Link & Network Layer Erkki Kukk 1 Layers with TCP/IP and OSI Model Compare OSI and TCP/IP model 2 Layers with TCP/IP and OSI Model Explain protocol data units (PDU) and encapsulation 3 Addressing

More information

IPv6: The Ins and Outs. Chris Buechler

IPv6: The Ins and Outs. Chris Buechler IPv6: The Ins and Outs Chris Buechler cmb@pfsense.org About Me Co-founder and CTO of BSD Perimeter LLC Corporate arm of pfsense project 15 years IT experience Former IT Manager at public accounting firm

More information

VMware Cloud Operations Management Technology Consulting Services

VMware Cloud Operations Management Technology Consulting Services VMware Cloud Operations Management Technology Consulting Services VMware Technology Consulting Services for Cloud Operations Management The biggest hurdle [that CIOs face as they move infrastructure and

More information

Networking for a dynamic infrastructure: getting it right.

Networking for a dynamic infrastructure: getting it right. IBM Global Technology Services Networking for a dynamic infrastructure: getting it right. A guide for realizing the full potential of virtualization June 2009 Executive summary June 2009 Networking for

More information

Performance Comparison of Internet Protocol v4 with Internet Protocol v6

Performance Comparison of Internet Protocol v4 with Internet Protocol v6 Performance Comparison of Internet Protocol v4 with Internet Protocol v6 Mrs. Sheetal Mali Department of Electronics and Telecommunication Parvatibai Genba Sopanrao Moze College of Engineering Wagholi,

More information

Chapter 15 IPv6 Transition Technologies

Chapter 15 IPv6 Transition Technologies Chapter 15 IPv6 Transition Technologies Published: April 18, 2006 Updated: November 06, 2006 Writer: Joe Davies 1 Abstract This chapter describes the mechanisms that aid in the transition of Internet Protocol

More information

Cisco Data Center Network Manager 5.1

Cisco Data Center Network Manager 5.1 Cisco Data Center Network Manager 5.1 Product Overview Modern data centers are becoming increasingly large and complex. New technology architectures such as cloud computing and virtualization are adding

More information

Insights on IPv6 Security

Insights on IPv6 Security Insights on IPv6 Security Bilal Al Sabbagh, MSc, CISSP, CCSP Senior Information & Network Security Consultant - NXme Information Security Researcher Stockholm University 10/9/10 NXme FZ-LLC 1 NIXU Middle

More information

Market Viability of IPv6 Revisited

Market Viability of IPv6 Revisited Market Viability of IPv6 Revisited North American IPv6 Summit John Curran President & CEO, ARIN Market Viability of IPv6 Revisited Quick History of the Internet Protocol The Market Viability Requirement

More information

NORTH CAROLINA NC MRITE. Nominating Category: Enterprise IT Management Initiatives

NORTH CAROLINA NC MRITE. Nominating Category: Enterprise IT Management Initiatives NORTH CAROLINA MANAGING RISK IN THE INFORMATION TECHNOLOGY ENTERPRISE NC MRITE Nominating Category: Nominator: Ann V. Garrett Chief Security and Risk Officer State of North Carolina Office of Information

More information

MIPv6: New Capabilities for Seamless Roaming Among Wired, Wireless, and Cellular Networks

MIPv6: New Capabilities for Seamless Roaming Among Wired, Wireless, and Cellular Networks Page 1 M: New Capabilities for Seamless Roaming Among Wired, Wireless, and Cellular Networks Paul Schmitz Technical Marketing Engineer Geoff Weaver Business Development Manager Copyright 2002. *Third-party

More information

CCNA Routing and Switching Courses. Scope and Sequence. Target Audience. Curriculum Overview. Last updated August 22, 2018

CCNA Routing and Switching Courses. Scope and Sequence. Target Audience. Curriculum Overview. Last updated August 22, 2018 CCNA Routing and Switching Scope and Sequence Last updated August 22, 2018 Target Audience The Cisco CCNA Routing and Switching curriculum is designed for Cisco Networking Academy students who are seeking

More information

Impact of IPv6 to an NGN and Migration Strategies. Gyu Myoung Lee ETRI

Impact of IPv6 to an NGN and Migration Strategies. Gyu Myoung Lee ETRI ITU Workshop on IPv6 Geneva, Switzerland, 4 5 September 2008 Impact of IPv6 to an NGN and Migration Strategies Gyu Myoung Lee ETRI gmlee@etri.re.kr Geneva, Switzerland, 4-5 September 2008 Contents Introduction

More information

Radware ADC. IPV6 RFCs and Compliance

Radware ADC. IPV6 RFCs and Compliance Radware ADC IPV6 s and Compliance Knowledgebase Team February 2016 Scope: This document lists most of the s that relevant to IPv6. Legend: Yes supported N/A not applicable No Currently not supported Relevance:

More information

Avaya Networking IPv6 Using Fabric Connect to ease IPv6 Deployment. Ed Koehler Director DSE Ron Senna SE Avaya Networking Solutions Architecture

Avaya Networking IPv6 Using Fabric Connect to ease IPv6 Deployment. Ed Koehler Director DSE Ron Senna SE Avaya Networking Solutions Architecture Avaya Networking IPv6 Using Fabric Connect to ease IPv6 Deployment Ed Koehler Director DSE Ron Senna SE Avaya Networking Solutions Architecture IAUG Newport RI, November 2013 Agenda IPv6, The fundamentals

More information

Enterprise IPv6, Affecting Positive Change

Enterprise IPv6, Affecting Positive Change Enterprise IPv6, Affecting Positive Change Rich Lewis IPv6 Product Manager, Oracle Global IT TXv6TF, March 2014 I am not an Oracle spokesperson, the views and opinions expressed in this presentation are

More information

This course prepares candidates for the CompTIA Network+ examination (2018 Objectives) N

This course prepares candidates for the CompTIA Network+ examination (2018 Objectives) N CompTIA Network+ (Exam N10-007) Course Description: CompTIA Network+ is the first certification IT professionals specializing in network administration and support should earn. Network+ is aimed at IT

More information

12.1. IPv6 Feature. The Internet Corporation for Assigned Names and Numbers (ICANN) assigns IPv6 addresses based on the following strategy:

12.1. IPv6 Feature. The Internet Corporation for Assigned Names and Numbers (ICANN) assigns IPv6 addresses based on the following strategy: 12.1. IPv6 Feature The current IP addressing standard, version 4, will eventually run out of unique addresses, so a new system is being developed. It is named IP version 6 or IPv6. You should know about

More information

Course 20741B: Networking with Windows Server 2016

Course 20741B: Networking with Windows Server 2016 Course Duration: 5 days Course description Overview: This 5-day classroom-based course provides the fundamental networking skills required to deploy and support Windows Server 2016 in most organizations.

More information

Managing Network Bandwidth to Maximize Performance

Managing Network Bandwidth to Maximize Performance Managing Network Bandwidth to Maximize Performance With increasing bandwidth demands, network professionals are constantly looking to optimize network resources, ensure adequate bandwidth, and deliver

More information

IPv6 Deployment at the University of Pennsylvania

IPv6 Deployment at the University of Pennsylvania IPv6 Deployment at the University of Pennsylvania Jorj Bauer and Shumon Huque University of Pennsylvania Educause Mid-Atlantic Regional Conference, Philadelphia, PA January 8 th, 2009 Outline Why you should

More information

VXLAN Overview: Cisco Nexus 9000 Series Switches

VXLAN Overview: Cisco Nexus 9000 Series Switches White Paper VXLAN Overview: Cisco Nexus 9000 Series Switches What You Will Learn Traditional network segmentation has been provided by VLANs that are standardized under the IEEE 802.1Q group. VLANs provide

More information

10/4/2016. Advanced Windows Services. IPv6. IPv6 header. IPv6. IPv6 Address. Optimizing 0 s

10/4/2016. Advanced Windows Services. IPv6. IPv6 header. IPv6. IPv6 Address. Optimizing 0 s Advanced Windows Services IPv6 IPv6 FSRM, FCI, DAC and RMS PKI IPv6 IP is the foundation of nearly all communication The number of addresses is limited Technologies like NAT help in addition to enhancements

More information

IPv6 Transition Technologies (TechRef)

IPv6 Transition Technologies (TechRef) Tomado de: http://technet.microsoft.com/en-us/library/dd379548.aspx IPv6 Transition Technologies (TechRef) Updated: January 7, 2009 IPv6 Transition Technologies Protocol transitions are not easy, and the

More information

Practical IPv6 for Windows Administrators

Practical IPv6 for Windows Administrators Practical IPv6 for Windows Administrators Edward Horley Apress" Contents J Forward About the Author About the Technical Reviewers Acknowledgments Introduction xvii xix xxi xxiii xxv Chapter 1: IPv6 the

More information

IPv6 Deployment Experiences. John Jason Brzozowski

IPv6 Deployment Experiences. John Jason Brzozowski IPv6 Deployment Experiences John Jason Brzozowski Overview Terminology Scope Core Concepts Goals and Objectives Lessons Learned Challenges IPv6 Data Services Considerations Content and Services 2 Terminology

More information

IPv6 Transition Mechanisms

IPv6 Transition Mechanisms IPv6 Transition Mechanisms Petr Grygárek rek 1 IPv6 and IPv4 Coexistence Expected to co-exist together for many years Some IPv4 devices may exist forever Slow(?) transition of (part of?) networks to IPv6

More information

Cisco Director Class SAN Planning and Design Service

Cisco Director Class SAN Planning and Design Service Cisco Director Class SAN Planning and Design Service Rapidly Plan and Deploy a Cisco Director Class MDS Solution for More Efficient Storage Networking Service Overview Cisco s intelligent storage networking

More information

Predictive Insight, Automation and Expertise Drive Added Value for Managed Services

Predictive Insight, Automation and Expertise Drive Added Value for Managed Services Sponsored by: Cisco Services Author: Leslie Rosenberg December 2017 Predictive Insight, Automation and Expertise Drive Added Value for Managed Services IDC OPINION Competitive business leaders are challenging

More information

Windows 7 on the 2009 A+ Exams

Windows 7 on the 2009 A+ Exams Windows 7 on the 2009 A+ Exams CompTIA s 2009 A+ exams will include Windows 7 beginning January, 2011. The revised A+ 2009 objectives showing additional content on Windows 7 are available at CompTIA's

More information

Insights on IPv6 Security

Insights on IPv6 Security Insights on IPv6 Security Bilal Al Sabbagh, MSc, CISSP, CISA, CCSP Senior Information & Network Security Consultant NXme FZ-LLC Information Security Researcher, PhD Candidate Stockholm University bilal@nxme.net

More information

EMBRACE CHANGE Computacenter s Global Solutions Center helps organizations take the risk out of business transformation and IT innovation

EMBRACE CHANGE Computacenter s Global Solutions Center helps organizations take the risk out of business transformation and IT innovation EMBRACE CHANGE Computacenter s Global Solutions Center helps organizations take the risk out of business transformation and IT innovation SOLUTIONS CENTER SOLUTION SUMMARY From digitalization initiatives

More information

AC : TEACHING A LABORATORY-BASED IPV6 COURSE IN A DISTANCE EDUCATION ENVIRONMENT

AC : TEACHING A LABORATORY-BASED IPV6 COURSE IN A DISTANCE EDUCATION ENVIRONMENT AC 2007-1962: TEACHING A LABORATORY-BASED IPV6 COURSE IN A DISTANCE EDUCATION ENVIRONMENT Philip Lunsford, East Carolina University Phil Lunsford received a B.S. in Electrical Engineering and a M.S. in

More information

IPv6 Deployment Planning

IPv6 Deployment Planning IPv6 Deployment Planning ISP Workshops Last updated 1 st October 2016 1 Introduction p Presentation introduces the high level planning considerations which any network operator needs to be aware of prior

More information

IPv6 support. Chris Mitchell. Program Manager Microsoft Corporation Windows Networking & Communications IPv6

IPv6 support. Chris Mitchell. Program Manager Microsoft Corporation Windows Networking & Communications IPv6 IPv6 support Chris Mitchell Program Manager Microsoft Corporation Windows Networking & Communications IPv6 Introduction New scenarios and IPv6 Microsoft s IPv6 support Migration and roadmap 2 New Engaging

More information

ENTERPRISE. Brief selected topics. Jeff Hartley, SP ADP SE

ENTERPRISE. Brief selected topics. Jeff Hartley, SP ADP SE IPv6 TRANSITION FOR THE ENTERPRISE Brief selected topics Jeff Hartley, SP ADP SE Observations on IPv6 Deployment Trends Where do successful sites commonly deploy first? Upstream Connectivity (Transit/Border/Peering/etc.)

More information

Finding IPv6 Where You Least Expect It Using LiveAction Software to Visualize and Troubleshoot IPv6 on Your Network

Finding IPv6 Where You Least Expect It Using LiveAction Software to Visualize and Troubleshoot IPv6 on Your Network LiveAction Application Note Finding IPv6 Where You Least Expect It Using LiveAction Software to Visualize and Troubleshoot IPv6 on Your Network September 2012 http://www.actionpacked.com Table of Contents

More information

SWITCH Implementing Cisco IP Switched Networks

SWITCH Implementing Cisco IP Switched Networks Hands-On SWITCH Implementing Cisco IP Switched Networks CCNP Course 2 Course Description Revised CCNP Curriculum and Exams Cisco has redesigned the CCNP courses and exams to reflect the evolving job tasks

More information

Internet Protocol, Version 6

Internet Protocol, Version 6 Outline Protocol, Version 6 () Introduction to Header Format Addressing Model ICMPv6 Neighbor Discovery Transition from to vs. Taken from:chun-chuan Yang Basics: TCP/ Protocol Suite Protocol (IP) Features:

More information

World IPv6 Launch and Penn

World IPv6 Launch and Penn World IPv6 Launch and Penn Shumon Huque University of Pennsylvania Megaconference v6 June 6th 2012 1 World IPv6 Launch http://www.worldip6launch.org/ Major Internet service providers (ISPs), home networking

More information

Migration Technologies. Dual Stack and Tunneling Using GRE, 6to4, and 6in4.

Migration Technologies. Dual Stack and Tunneling Using GRE, 6to4, and 6in4. Migration Technologies. Dual Stack and Tunneling Using GRE, 6to4, and 6in4. 1 By Gaza IPv6 Project Team Eng. Mohammed Abu-Jamous Why Not Dual Stack? Dual Stack is very important in our migration plane.

More information

Experience working with Windows Server 2008 or Windows Server Experience working in a Windows Server infrastructure enterprise environment

Experience working with Windows Server 2008 or Windows Server Experience working in a Windows Server infrastructure enterprise environment Networking with Windows Server 2016 va Day(s): 5 Course Code: M20741 Version: A Overview This 5-day classroom-based course provides the fundamental networking skills required to deploy and support Windows

More information

CompTIA Network+ Study Guide Table of Contents

CompTIA Network+ Study Guide Table of Contents CompTIA Network+ Study Guide Table of Contents Course Introduction Table of Contents Getting Started About This Course About CompTIA Certifications Module 1 / Local Area Networks Module 1 / Unit 1 Topologies

More information

Necessity to Migrate to IPv6

Necessity to Migrate to IPv6 Necessity to Migrate to IPv6 1 Rahathullah Khan, 2 Hussain Fouad Sindi 1&2 Department of Information System King Abdul Aziz University, KSA 1 mdrahathkhan26@yahoo.com, 2 u4sindi@gmail.com Abstract This

More information

Security in an IPv6 World Myth & Reality

Security in an IPv6 World Myth & Reality Security in an IPv6 World Myth & Reality DGI Washington D.C. August 2014 Chris Grundemann MYTH: IPv6 Has Security Designed In MYTH: IPv6 Has Security Designed In IPSEC IS NOT NEW IPsec exists for IPv4

More information

IPv6 Bootcamp Course (5 Days)

IPv6 Bootcamp Course (5 Days) IPv6 Bootcamp Course (5 Days) Course Description: This intermediate - advanced, hands-on course covers pertinent topics needed for IPv6 migration and deployment strategies. IPv6 novices can expect to gain

More information

Beyond the IPv4 Internet. Geoff Huston Chief Scientist, APNIC

Beyond the IPv4 Internet. Geoff Huston Chief Scientist, APNIC Beyond the IPv4 Internet Geoff Huston Chief Scientist, APNIC The IETF s ROAD Trip By 1990 it was evident that IPv4 was not going to have a large enough address span for long term deployment And the routing

More information

IPv6- IPv4 Threat Comparison v1.0. Darrin Miller Sean Convery

IPv6- IPv4 Threat Comparison v1.0. Darrin Miller Sean Convery IPv6- IPv4 Threat Comparison v1.0 Darrin Miller dmiller@cisco.com Sean Convery sean@cisco.com Motivations Discussions around IPv6 security have centered on IPsec Though IPsec is mandatory in IPv6, the

More information

IP Addressing Modes for Cisco Collaboration Products

IP Addressing Modes for Cisco Collaboration Products IP Addressing Modes for Cisco Collaboration Products IP Addressing Modes, page 1 Recommended IPv6 Addressing Modes for CSR 12.0 Products, page 3 IPv6 Addressing in Cisco Collaboration Products, page 9

More information

Chapter 10: Review and Preparation for Troubleshooting Complex Enterprise Networks

Chapter 10: Review and Preparation for Troubleshooting Complex Enterprise Networks 0: Review and Preparation for Troubleshooting Complex Enterprise Networks CCNP TSHOOT: Maintaining and Troubleshooting IP Networks Chapter TSHOOT 1v6 0 1 0 Objectives Review key maintenance and troubleshooting

More information

Best practices in IT security co-management

Best practices in IT security co-management Best practices in IT security co-management How to leverage a meaningful security partnership to advance business goals Whitepaper Make Security Possible Table of Contents The rise of co-management...3

More information

IPv6 Rapid Deployment (6rd) in broadband networks. Allen Huotari Technical Leader June 14, 2010 NANOG49 San Francisco, CA

IPv6 Rapid Deployment (6rd) in broadband networks. Allen Huotari Technical Leader June 14, 2010 NANOG49 San Francisco, CA Rapid Deployment () in broadband networks Allen Huotari Technical Leader ahuotari@cisco.com June 14, 2010 NANOG49 San Francisco, CA 1 Why IP Tunneling? IPv4 Tunnel Tunnel IPv4 IPv4 Retains end-end IP semantics

More information