Transition To IPv6 October 2011

Size: px
Start display at page:

Download "Transition To IPv6 October 2011"

Transcription

1 Transition To IPv6 October 2011 Fred Bovy ccie # Fred Bovy Transition to IPv6 1 1st Generation: The IPv6 Pioneers Tunnels for Experimental testing or Enterprises The Experimental 6BONE network was created from overlay IPv6 in Tunnels over the Internet. Dual-Stack Overlay IPv6 in Tunnels Manual 6in4 and automatic 6to4 And more automatic tunnels Again mostly introduced with Windows: TEREDO to bypass NAT devices and ISATAP to use networks as a NBMA network for IPv6. NAT and Private Addresses (RFC1918) In parallel to make the most of the remaining addresses, NAT44 and private addresses (RFC1918) were introduced 2011 Fred Bovy fred@fredbovy.com. Transition to IPv6 2 2nd Generation: SPs transition 1st Phase, the 2000s SPs with MPLS/ Backbone: 6PE and 6VPE Most SPs were running /MPLS First Phase of the transition, deploy 6PE/6VPE SPs with Backbone: 6RD FREE a french SP deployed IPv6 in 5 Weeks from a 6to4 stack! Carrier Grade NAT or Large Scale NAT (Testing) DS-Lite = in IPv6 Tunnel + CGN SPs who deployed IPv6 choose DS-Lite to support the existing customers They deploy it as soon as they migrated from 6PE/6VPE to Native IPv6 Some of them planned to replace DS-Lite with A+P when it will be available Other protocols are designed, some of themare tested: CGN, NAT444, NAT464, divi, divi-pd Network Address Translation Protocols (NAT) NAT-PT First attempt to translate IPv6 to protocols. Deprecated! NAT64/DNS Fred Bovy fred@fredbovy.com. Transition to IPv6 3

2 3rd Generation: SPs going Stateless, the 2010s Stateful Carrier Grade NAT issues Because of the Stateful CGN known issues, a lot of work is being done to develop and test some Stateless protocols to share the remaining addresses without stateful NAT, CGN. A+P Architecture and Stateless NAT solutions Testing To share the remaining addresses using the Source Ports Without any Stateful NAT in the SP backbone. Users or CPE have some IP addresses and Source Ports assigned Not a new solution, FT ORANGE planned A+P in 2009 while they were choosing DS-Lite in the first place First proposal for A+P at the IETF Taipei 2011 is based on Stateless NAT464 aka divi, divi-pd and 4RD 2011 Fred Bovy fred@fredbovy.com. Transition to IPv6 4 TransitionTools - Deployment Time BONE Deployed 6PE 6VPE IPv6 in Tunnels 6RD IETF Taipei 82 Nov 2011 DS-Lite NAT64 in IPv6 Tunnels divi-pd NAT464 NAT444 DS-Lite divi-pd divi A+P Testing Standardization Dual-Stack 6in4 NAT-PT 6to4 6VPE NAT64 divi-pd NAT444 DS-Lite A+P 2011 Fred Bovy fred@fredbovy.com. Transition to IPv6 5 6RD 6PE Network Address Translation n NAT44 and private addresses in the 90s n IPv6 to translations NAT-PT NAT-PT is NAT64 + NAT46 + DNS ALG NAT-PT was replaced by NAT64 and DNS64 n Carrier Grade NAT or Large Scale NAT NAT444 or double NAT NAT464, divi, divi-pd DS-Lite = in IPv6 Tunnels + NAT44 (LSN) Frédéric Bovy Fred Bovy fred@fredbovy.com. Transition to IPv6 6

3 Dual Stack and Tunneling This was introduced at the very beginning of IPv6 in 1996 All clients are now configured by default as dual-stack nodes It is still the best approach for a smooth transition Tunnels are manually, statically configured It may be obvious but for dual-stack you still need addresses! IPv6 Hosts Tunneling IPv6 Packet IPv6 Hdr Hdr Dual Stack Router IPv6 IPv6 Host IPv6 IPv6 Dual Stack Router IPv6 Host 2011 Fred Bovy fred@fredbovy.com. Transition to IPv6 7 Automatic Tunnels for Enterprises: 6to4 Tunnel destination address is embedded in the IPv6 address! 2002:C044:1::/48 prefix comes from :C046:1::/48 prefix comes from Fred Bovy fred@fredbovy.com. Transition to IPv6 8 SPs MPLS Enabled: 6PE and 6VPE In the very early 2000s, 6PE was introduced to help the SPs with an MPLS/ Background to provide an IPv6 Service No Backbone Routers Upgrade needed! 2011 Fred Bovy fred@fredbovy.com. Transition to IPv6 9

4 6RD Automatic Tunnel for SPs Free, a french SP customized a 6to4 stack to allow a custom prefix instead of 2002::/16 Free deployed 6RD in 5 weeks in 2007 and immediately started an IPv6 service over the backbone, user configurable 4RD is in IPv Fred Bovy fred@fredbovy.com. Transition to IPv6 10 Dual Stack Lite or DS-Lite Once the SP have migrated their backbone to IPv6, DS-Lite is used to support RFC1918 Customers in IPv6 Tunnels + NAT44 (LSN at the SP) LSN inside mapping uses Source IPv6 + Source + Port LSN allows to share the remaining addresses efficienciently But LSN must keep a lot of states and is a Single Point of failure shared by Many Customers LSN 2011 Fred Bovy fred@fredbovy.com. Transition to IPv6 11 DS-Lite: Help transition to IPv Fred Bovy fred@fredbovy.com. Transition to IPv6 12

5 Connecting IPv6-only with -only: AFT64 Residential Access Aggregation Edge Core IP/MPLS NAT64 DNS64 Public Internet Datacenter IPv6 ONLY connectivity ONLY New IPv6 clients must have access to content AFT64 technology is only applicable in case where there are IPv6 only end-points that need to talk to only end-points (AFT64 for going from IPv6 to ) AFT64:= stateful v6 to v4 translation or stateless translation, ALG still required Key components includes NAT64 and DNS64 Assumption: Network infrastructure and services have fully transitioned to IPv6 and has been phased out 2011 Fred Bovy fred@fredbovy.com. Transition to IPv6 13 Protocol Translation: NAT64, DNS64 Client requests the IPv6 Address DNS64 translates the request to an Address NAT64 Web Server IPv6 h2.exemple.com? DNS64 h2.exemple.com? DNS AAAA 64:ff9b::c0:201 A: Fred Bovy fred@fredbovy.com. Transition to IPv6 14 NAT64 and DNS64 The session is initialized by IPv6 client Traffic route the 64:ff9b::/96 prefix to the NAT64 Router Web Server NAT64 then convert headers in both directions NAT64 SYN IPv6 SYN 64:ff9b::c0:201 SYN+ACK h2.exemple.com? DNS64 SYN+ACK h2.exemple.com? DNS A: AAAA 64:ff9b::c0:201 Frédéric Bovy Fred Bovy fred@fredbovy.com. Transition to IPv6 15

6 NAT444: A second level of NAT44 Solution to share the remaining addresses among multiple customers 2011 Fred Bovy fred@fredbovy.com. Transition to IPv6 16 NAT444: LSN Scalability Issue n How many streams LSN will be able to manage? n LSN is a Single Point of failure Frédéric Bovy Fred Bovy fred@fredbovy.com. Transition to IPv6 17 NAT444: Overlapping Private Address! Frédéric Bovy Fred Bovy fred@fredbovy.com. Transition to IPv6 18

7 NAT444: 2 customers behind same LSN Frédéric Bovy Fred Bovy fred@fredbovy.com. Transition to IPv6 19 NAT444 Network Design Issues Overlapping Addresses If one of the customers network uses the same private network number than the NAT CPE to LSN link we have a sever duplicate network issue!!! Two Customers behind the same LSN want to communicate Packets with a private source address may be dropped by customer policy (Firewall, ACL, host policy). So LSN must be used also for local traffic Plus all the LSN Based solutions: Scalability Behind each CPE NAT there can be many devices. Each device may generate many application streams. How mansy stream will be supported by LSN? We have not enough experience to say??? Single Point of Failure The LSN device keeps many states. If it reboot, many users will have to restart their Frédéric Bovy 20 applications Fred Bovy fred@fredbovy.com. Transition to IPv6 20 DS-Lite: Connect the users Another solution to share the remaining addresses among multiple customers 2011 Fred Bovy fred@fredbovy.com. Transition to IPv6 21

8 Stateful NAT464 or Stateless divi, divi-pd divi is the stateless version to share addresses among multiple users using source ports Stateless means NO NAT or LSN! Frédéric Bovy Fred Bovy Transition to IPv6 22 Address+Port (A+P) Experimental RFC6346 Use some bits of the source port to share an address without Stateful NAT, CGN or LSN. Can be implemented on hosts or CPEs which may have to do some translation for the non upgraded hosts Requires signaling to request which ports are granted Packets must be encapsulated/decapsulated to get sent into tunnels using the ports which are allocated for the host or the CPE The first proposal at the IETF in 2011 relies on Stateless NAT464 aka divi, divi-pd and 4RD and does not require signaling France Telecom-Orange has a software implementation: Frédéric Bovy Fred Bovy fred@fredbovy.com. Transition to IPv6 23 divi, divi-pd or Stateless NAT464 A+P proposal at the IETF actually relies on divi-pd and 4RD. divi-pd is Stateless NAT464 and permit to translate IPv6 addresses to Address+Source Port It is then possible to share an address among many users or CPEs. Without requiring any Stateful NAT with all the known problems associated A very interesting test in large SP domains : " For port configuration, since there are TCP/UDP ports for each IP address, and in fact one can use hundreds only for normal applications, so one address can be shared by multiple customers. In our experiment, we selected ratio to be 128. That is to say, one address is shared by 128 users, and there are 512 available ports per user." Frédéric Bovy Fred Bovy fred@fredbovy.com. Transition to IPv6 24

9 Security with to Transition to IPv Fred Bovy Transition to IPv6 25 Threats on Transition protocols n Dual-Stack scanning can be used to discover the node and IPv6 must be at the same security level n Tunnel Tunnels are an easy target for many possible attacks Packet Injection Automatic Tunnels are the most dangerous Automatic Servers can be the target of DoS attacks Manual Tunnel should use IPSec! n Stateful Translation Stateful NAT can be the target of DoS attacks DoS Attacks by address pool depletion DoS Attack by creating a lot of states or request which consumes CPU Frédéric Bovy Fred Bovy fred@fredbovy.com. Transition to IPv6 26 Dual Stack Issues Dual Stack Nodes may be very well protected and poorly IPv6 protected Dual Stack Nodes can be discovered thanks to an scan! And then attacked using IPv6 tools! Frédéric Bovy Fred Bovy fred@fredbovy.com. Transition to IPv6 27

10 Inability to inspect Tunneled Packet Firewall cannot inspect the IPv6 paquet encapsulated in Header IPv6 Header IPv6 Payload Frédéric Bovy Fred Bovy Transition to IPv6 28 Attacks on Tunnels Traffic tunneled cannot be inspected Access-List and paquet inspection cannot inspect the IPv6 paquet which is encapsulated in paquets Solution is to implement multiple Firewall which inspect paquets before they get encapsulated Other solution is when the Tunnel end point is on a Firewall, traffic can be inspected Easy to inject paquets coming from a known Tunnel If an attacker has the knowledge of manual tunnel configuration, it can sends paquet «originiated» from a known tunnel head-end With automatic tunnels it is even easier as paquet can be originated from any address in the network IPSec is the protection Frédéric Bovy Fred Bovy fred@fredbovy.com. Transition to IPv6 29 Attack by Paquet injection in a manual tunnel Frédéric Bovy Fred Bovy fred@fredbovy.com. Transition to IPv6 30

11 Attacks on Stateful NAT64 Stateful NAT can be the target of DoS attacks The attacker sends many IPv6 paquets with different source addresses to the same target. Each paquet consumes an address and a state which must be managed. When there is no more address available, there is no more access to hosts 2011 Fred Bovy fred@fredbovy.com. Transition to IPv6 31 Thank You! fred@fredbovy.com 2011 Fred Bovy fred@fredbovy.com. Transition to IPv6 32

IPv6 Transition Mechanisms

IPv6 Transition Mechanisms IPv6 Transition Mechanisms Petr Grygárek rek 1 IPv6 and IPv4 Coexistence Expected to co-exist together for many years Some IPv4 devices may exist forever Slow(?) transition of (part of?) networks to IPv6

More information

6RD. IPv6 Rapid Deployment. Version Fred Bovy. Chysalis6 6RD 1-1

6RD. IPv6 Rapid Deployment. Version Fred Bovy. Chysalis6 6RD 1-1 6RD IPv6 Rapid Deployment Version 1.0 2012 Fred Bovy. Chysalis6 6RD 1-1 About the Author Fred Bovy 15 years experience in IPv6 IPv6 Forum Certified Gold Engineer IPv6 Forum Certified Gold Trainer 7 years

More information

IPv6 Transition Mechanisms

IPv6 Transition Mechanisms IPv6 Transition Mechanisms Petr Grygárek rek 1 IPv6 and IPv4 Coexistence Expected to co-exist together for many years Some IPv4 devices may exist forever Slow(?) transition of (part of?) networks to IPv6

More information

IPv6 Transitioning. An overview of what s around. Marco Hogewoning Trainer, RIPE NCC

IPv6 Transitioning. An overview of what s around. Marco Hogewoning Trainer, RIPE NCC IPv6 Transitioning An overview of what s around Marco Hogewoning Trainer, RIPE NCC There Was a Plan The original idea was to have IPv6 deployed before we were out of IPv4 addresses By now the whole of

More information

IPv6 Transition Technology

IPv6 Transition Technology www.huawei.com Transition Technology HUAWEI TECHNOLOGIES CO., LTD. Address exhaustion has occurred The address exhaustion has arrived. 4.3 billion addresses are not enough to address the humans and their

More information

IPv6 Transition Strategies

IPv6 Transition Strategies IPv6 Transition Strategies Philip Smith MENOG 14 Dubai 1 st April 2014 Last updated 5 th March 2014 1 Presentation Slides p Will be available on n http://thyme.apnic.net/ftp/seminars/

More information

IPv6 Transition Strategies

IPv6 Transition Strategies IPv6 Transition Strategies Philip Smith APNIC 36 Xi an 20 th -30 th August 2013 Last updated 25 July 2013 1 Presentation Slides p Will be available on n http://thyme.apnic.net/ftp/seminars/apnic36-

More information

BIG-IP CGNAT: Implementations. Version 13.0

BIG-IP CGNAT: Implementations. Version 13.0 BIG-IP CGNAT: Implementations Version 13.0 Table of Contents Table of Contents Deploying a Carrier Grade NAT... 9 Overview: The carrier-grade NAT (CGNAT) module... 9 About ALG Profiles...10 About CGNAT

More information

NAT444+v6 Softwire. Shin Miyakawa, Ph.D. NTT Communications Corporation

NAT444+v6 Softwire. Shin Miyakawa, Ph.D. NTT Communications Corporation NAT444+v6 Softwire Shin Miyakawa, Ph.D. NTT Communications Corporation miyakawa@nttv6.jp NAT444 + Softwire This is not IDEAL solution, we know There are several (maybe serious) problems However so, this

More information

IPv6 Rapid Deployment (6rd) in broadband networks. Allen Huotari Technical Leader June 14, 2010 NANOG49 San Francisco, CA

IPv6 Rapid Deployment (6rd) in broadband networks. Allen Huotari Technical Leader June 14, 2010 NANOG49 San Francisco, CA Rapid Deployment () in broadband networks Allen Huotari Technical Leader ahuotari@cisco.com June 14, 2010 NANOG49 San Francisco, CA 1 Why IP Tunneling? IPv4 Tunnel Tunnel IPv4 IPv4 Retains end-end IP semantics

More information

Unit 5 - IPv4/ IPv6 Transition Mechanism(8hr) BCT IV/ II Elective - Networking with IPv6

Unit 5 - IPv4/ IPv6 Transition Mechanism(8hr) BCT IV/ II Elective - Networking with IPv6 5.1 Tunneling 5.1.1 Automatic Tunneling 5.1.2 Configured Tunneling 5.2 Dual Stack 5.3 Translation 5.4 Migration Strategies for Telcos and ISPs Introduction - Transition - the process or a period of changing

More information

Cisco IOS IPv6. Cisco IOS IPv6 IPv6 IPv6 service provider IPv6. IPv6. data link IPv6 Cisco IOS IPv6. IPv6

Cisco IOS IPv6. Cisco IOS IPv6 IPv6 IPv6 service provider IPv6. IPv6. data link IPv6 Cisco IOS IPv6. IPv6 IP6FD v6 Fundamentals, Design, and Deployment v3.0 Cisco IOS IPv6 Cisco IOS IPv6 IPv6 IPv6 service provider IPv6 IP IPv6 IPv6 data link IPv6 Cisco IOS IPv6 IPv6 IPv6 DHCP DNS DHCP DNS IPv6 IPv4 IPv6 multicast

More information

Host-based Translation Problem Statement.

Host-based Translation Problem Statement. Host-based Translation Problem Statement chengang@chinamobile.com Why we need host based translation Two IP families need talk each other, otherwise there are totally separated two worlds; There exists

More information

Dual-Stack lite. Alain Durand. May 28th, 2009

Dual-Stack lite. Alain Durand. May 28th, 2009 Dual-Stack lite Alain Durand May 28th, 2009 Part I: Dealing with reality A dual-prong strategy IPv4 reality check: completion of allocation is real Today Uncertainty IPv6 reality check: the IPv4 long tail

More information

Federal Agencies and the Transition to IPv6

Federal Agencies and the Transition to IPv6 Federal Agencies and the Transition to IPv6 Introduction Because of the federal mandate to transition from IPv4 to IPv6, IT departments must include IPv6 as a core element of their current and future IT

More information

IPv6 Transition Planning

IPv6 Transition Planning IPv6 Transition Planning ITU/APNIC/MOIC IPv6 Workshop 19 th 21 st June 2017 Thimphu These materials are licensed under the Creative Commons Attribution-NonCommercial 4.0 International license (http://creativecommons.org/licenses/by-nc/4.0/)

More information

BIG-IP CGNAT: Implementations. Version 12.1

BIG-IP CGNAT: Implementations. Version 12.1 BIG-IP CGNAT: Implementations Version 12.1 Table of Contents Table of Contents Deploying a Carrier Grade NAT... 7 Overview: The carrier-grade NAT (CGNAT) module... 7 About ALG Profiles...8 About CGNAT

More information

Securing the Transition Mechanisms

Securing the Transition Mechanisms Securing the Transition Mechanisms ITU/APNIC/MICT IPv6 Security Workshop 23 rd 27 th May 2016 Bangkok Last updated 30 th January 2016 1 Where did we leave off? p We ve just covered the current strategies

More information

An IPv4 End of Life Plan A Shared Vision for IPv6

An IPv4 End of Life Plan A Shared Vision for IPv6 An IPv4 End of Life Plan A Shared Vision for IPv6 from IETF IntArea with Mark Townsley (tunnels) & Dan Wing (nats) NANOG / San Diego 2012.02.06 Randy Bush 1 Why Has the Transition to IPv6

More information

CCNA Questions/Answers IPv6. Select the valid IPv6 address from given ones. (Choose two) A. FE63::0043::11:21 B :2:11.1 C.

CCNA Questions/Answers IPv6. Select the valid IPv6 address from given ones. (Choose two) A. FE63::0043::11:21 B :2:11.1 C. Select the valid IPv6 address from given ones. (Choose two) A. FE63::0043::11:21 B. 191.2.1.2:2:11.1 C. 2001::98 D. 2002:c0a8:101::42 E. :2001:: F. 2002.cb0a:3cdd:1::1 Answer: C, D. 2013 1 Which method

More information

IPv4 exhaustion and the way forward. Guillermo Cicileo

IPv4 exhaustion and the way forward. Guillermo Cicileo IPv4 exhaustion and the way forward Guillermo Cicileo HOW ARE INTERNET ADDRESSES ASSIGNED? Allocation of Internet number resources IANA IANA (Internet Assigned Numbers Authority) actualmente bajo la responsabilidad

More information

IPv6 Evolution and Migration Solution

IPv6 Evolution and Migration Solution IPv6 Evolution and Migration Solution www.huawei.com HUAWEI TECHNOLOGIES CO., LTD. Contents Industry s Viewpoints to IPv6 Development IPv6 Migration Solution and Huawei IPv6 Solution Highlights The World

More information

IPv6 Implementation Best Practices For Service Providers

IPv6 Implementation Best Practices For Service Providers IPv6 Implementation Best Practices For Service Providers Brandon Ross Chief Network Architect and CEO 2013 Utilities Telecom Council Network Utility Force www.netuf.net @NetUF RFC 6540 - IPv6 Support Required

More information

Practical IPv6 for Windows Administrators

Practical IPv6 for Windows Administrators Practical IPv6 for Windows Administrators Edward Horley Apress" Contents J Forward About the Author About the Technical Reviewers Acknowledgments Introduction xvii xix xxi xxiii xxv Chapter 1: IPv6 the

More information

What's the big deal about IPv6? A plain-english guidebook for non-technical managers

What's the big deal about IPv6? A plain-english guidebook for non-technical managers What's the big deal about IPv6? A plain-english guidebook for non-technical managers Why should I care about IPv6? 2. We're all going to IPv6 Your network administrators will tell you that IPv6 is the

More information

Tunnels. Jean Yves Le Boudec 2015

Tunnels. Jean Yves Le Boudec 2015 Tunnels Jean Yves Le Boudec 2015 1. Tunnels Definition: a tunnel, also called encapsulation occurs whenever a communication layer carries packets of a layer that is not the one above e.g.: IP packet in

More information

IPv6. Internet Technologies and Applications

IPv6. Internet Technologies and Applications IPv6 Internet Technologies and Applications Contents Summary of IPv6 core features Auto-configuration IPv4-IPv6 transition techniques IPv6 networks today ITS 413 - IPv6 2 Motivation Current version of

More information

IPv4/v6 Considerations Ralph Droms Cisco Systems

IPv4/v6 Considerations Ralph Droms Cisco Systems Title IPv4/v6 Considerations Ralph Droms Cisco Systems Agenda Motivation for IPv6 Review of IPv6 Impact of differences Tools and techniques Why IPv6? More addresses More addresses More addresses Security,

More information

IPv6 Bootcamp Course (5 Days)

IPv6 Bootcamp Course (5 Days) IPv6 Bootcamp Course (5 Days) Course Description: This intermediate - advanced, hands-on course covers pertinent topics needed for IPv6 migration and deployment strategies. IPv6 novices can expect to gain

More information

Deploying IPv6 Services

Deploying IPv6 Services Deploying IPv6 Services gogo6.com gogonet.gogo6.com January 2010 gogo6 2010 1 Company Overview IPv6 products, community and services Hardware and software for network operators to go v6 Social network

More information

Post IPv4 completion. Making IPv6 deployable incrementally by making it. Alain Durand

Post IPv4 completion. Making IPv6 deployable incrementally by making it. Alain Durand Post IPv4 completion Making IPv6 deployable incrementally by making it backward compatible with IPv4. Alain Durand The tmust support continued, un interrupted growth regardless of IPv4 address availability

More information

IPv6 migration strategies for mobile networks

IPv6 migration strategies for mobile networks migration strategies for mobile s White paper To cope with the increasing demand for IP addresses, most mobile operators (MNOs) have deployed Carrier Grade Network Address Translation (CG-NAT). Introducing

More information

COE IPv6 Roadmap Planning. ZyXEL

COE IPv6 Roadmap Planning. ZyXEL COE IPv6 Roadmap Planning ZyXEL COE Product Offering with IPv6 Dual Stack Lite / Translation & Dual Stack, IPv6 Core Phase I Chassis MSAN FW Rel. 3.96.1 MSC1000G, MSC1024G, MSC1224G, ALC12xxG- 5x, VLC13xxG-5x

More information

Tunnels. Jean Yves Le Boudec 2015

Tunnels. Jean Yves Le Boudec 2015 Tunnels Jean Yves Le Boudec 2015 1. Tunnels Definition: a tunnel, also called encapsulation occurs whenever a communication layer carries packets of a layer that is not the one above e.g.: IP packet in

More information

Security Concerns With Tunneling draft-ietf-v6ops-tunnel-security-concerns-00

Security Concerns With Tunneling draft-ietf-v6ops-tunnel-security-concerns-00 Security Concerns With Tunneling draft-ietf-v6ops-tunnel-security-concerns-00 Dave Thaler Suresh Krishnan Jim Hoagland IETF 72 1 Status Formerly draft-ietf-v6ops-teredo-securityconcerns-02.txt Most points

More information

IPv6 adoption for operators

IPv6 adoption for operators adoption for operators 29 th Feb 2012 Ramesh Chandra Head IP & Transport Engineering India & South East Asia Coverage Drivers for New service opportunities Present IPv4 Eco system Design consideration

More information

IPv4 and IPv6 Transition & Coexistence

IPv4 and IPv6 Transition & Coexistence IPv4 and IPv6 Transition & Coexistence Copy Rights This slide set is the ownership of the 6DEPLOY project via its partners The Powerpoint version of this material may be reused and modified only with written

More information

Mapping of Address and Port (MAP) an ISPs Perspective. E. Jordan Gottlieb Principal Engineer Charter Communications

Mapping of Address and Port (MAP) an ISPs Perspective. E. Jordan Gottlieb Principal Engineer Charter Communications Mapping of Address and Port () an ISPs Perspective E. Jordan Gottlieb Principal Engineer Charter Communications jordan.gottlieb@charter.com Agenda What is? Benefits of in Action Algorithms in Action Deployment

More information

Implementing IP Addressing Services

Implementing IP Addressing Services Implementing IP Addressing Services Accessing the WAN Chapter 7 Version 4.0 2006 Cisco Systems, Inc. All rights reserved. Cisco Public 1 Objectives Configure DHCP in an enterprise branch network Configure

More information

Transitioning to IPv6

Transitioning to IPv6 Transitioning to IPv6 麟瑞科技區域銷售事業處副處長張晃崚 CCIE #13673 2007 Cisco Systems, Inc. All rights reserved. ICND2 v1.0 7-1 IPv4 and IPv6 Currently, there are approximately 1.3 billion usable IPv4 addresses available.

More information

Implementing IP Addressing Services. Accessing the WAN Chapter 7

Implementing IP Addressing Services. Accessing the WAN Chapter 7 Implementing IP Addressing Services Accessing the WAN Chapter 7 ITE I Chapter 6 2006 Cisco Systems, Inc. All rights reserved. Cisco Public 1 Objectives Configure DHCP in an enterprise branch network Configure

More information

Deploy CGN to Retain IPv4 Addressing While Transitioning to IPv6

Deploy CGN to Retain IPv4 Addressing While Transitioning to IPv6 White Paper Deploy CGN to Retain Addressing While Transitioning to IPv6 The IANA ran out of addresses to allocate in February 2011, and the Regional Internet Registries (RIR) will have assigned most of

More information

Introduction to Network Address Translation

Introduction to Network Address Translation Introduction to Network Address Translation Campus Network Design & Operations Workshop These materials are licensed under the Creative Commons Attribution-NonCommercial 4.0 International license (http://creativecommons.org/licenses/by-nc/4.0/)

More information

IPv6 Technical Challenges

IPv6 Technical Challenges IPv6 Technical Challenges Peter Palúch, CCIE #23527, CCIP University of Zilina, Slovakia Academy Salute, April 15 th 16 th, Bucharest IPv6 technical challenges What challenges do I meet if I decide to

More information

IPv6 in Campus Networks

IPv6 in Campus Networks IPv6 in Campus Networks Dave Twinam Manager, Technical Marketing Engineering Internet Systems Business Unit dtwinam@cisco.com Cisco Twinam IPv6 Summit 2003 Cisco Systems, Inc. All rights reserved. 1 IPv6

More information

Yasuo Kashimura Senior Manager, Japan, APAC IPCC Alcatel-lucent

Yasuo Kashimura Senior Manager, Japan, APAC IPCC Alcatel-lucent Yasuo Kashimura Senior Manager, Japan, APAC IPCC Alcatel-lucent Agenda 1. 1. Current status of / internet 2. 2. continuity 3. 3. continuity over network 4. 4. rapid deployment 5. 6. Wider deployment 6.

More information

Qwest IPv6. Engineering & Certification 1/31/2011. Government Services

Qwest IPv6. Engineering & Certification 1/31/2011. Government Services Qwest IPv6 Engineering & Certification 1/31/2011 Agenda Qwest IPv6 history IPv4 Depletion & Carrier Timeline IPv6 Service objectives Qwest IP Networks => IPv6 Networks? IPv6 Implementation: Public port

More information

A Border Gateway Protocol 3 (BGP-3) DNS Extensions to Support IP version 6. Path MTU Discovery for IP version 6

A Border Gateway Protocol 3 (BGP-3) DNS Extensions to Support IP version 6. Path MTU Discovery for IP version 6 IPv6 Standards and RFC 1195 Use of OSI IS-IS for Routing in TCP/IP and Dual Environments RFC 1267 A Border Gateway Protocol 3 (BGP-3) RFC 1305 Network Time Protocol (Version 3) Specification, Implementation

More information

IPv6 Enablement for Enterprises. Waliur Rahman Managing Principal, Global Solutions April, 2011

IPv6 Enablement for Enterprises. Waliur Rahman Managing Principal, Global Solutions April, 2011 IPv6 Enablement for Enterprises Waliur Rahman Managing Principal, Global Solutions April, 2011 PROPRIETARY STATEMENT This document and any attached materials are the sole property of Verizon and are not

More information

Tunnels. Jean Yves Le Boudec 2014

Tunnels. Jean Yves Le Boudec 2014 Tunnels Jean Yves Le Boudec 2014 2 Menu Today: lecture Tunnels, 6to4 Link State Routing Tomorrow 11:15 12:15 Last clicker test How TOR works (presentation of best research exercise award) No lab Lab 3

More information

IPv6 implementation in a multi-vendor network.

IPv6 implementation in a multi-vendor network. IPv6 implementation in a multi-vendor network. Roque Gagliano www.antel.com.uy Agenda motivation. first experience. backbone deployment. addressing. routing. multi-vendor environment. conclusion / next

More information

MUM Lagos Nigeria Nov 28th IPv6 Demonstration By Mani Raissdana

MUM Lagos Nigeria Nov 28th IPv6 Demonstration By Mani Raissdana MUM Lagos Nigeria Nov 28th IPv6 Demonstration By Mani Raissdana Mani Raissdana MikroTik Certified Trainer CTO & Co-Founder of Being in IT technology business roughly around 14 years Support & instruct

More information

IPV6 SIMPLE SECURITY CAPABILITIES.

IPV6 SIMPLE SECURITY CAPABILITIES. IPV6 SIMPLE SECURITY CAPABILITIES. 50 issues from RFC 6092 edited by J. Woodyatt, Apple Presentation by Olle E. Johansson, Edvina AB. ABSTRACT The RFC which this presentation is based upon is focused on

More information

Transition Strategies from IPv4 to IPv6: The case of GRNET

Transition Strategies from IPv4 to IPv6: The case of GRNET Transition Strategies from IPv4 to IPv6: The case of GRNET C. Bouras 1,2, P. Ganos 1, A. Karaliotas 1,2 1 Research Academic Computer Technology Institute, Patras, Greece 2 Department of Computer Engineering

More information

Network Configuration Example

Network Configuration Example Network Configuration Example Configuring Stateful NAT64 for Handling IPv4 Address Depletion Release NCE0030 Modified: 2017-01-23 Juniper Networks, Inc. 1133 Innovation Way Sunnyvale, California 94089

More information

Journey to IPv6: A Real-World deployment for Mobiles

Journey to IPv6: A Real-World deployment for Mobiles Journey to IPv6: A Real-World deployment for Mobiles ISP Workshops Last updated 1 st March 2017 Telstra Unrestricted Acknowledgements p We would like to acknowledge Jeff Schmidt @ Telstra for permitting

More information

The case for IPv6-only data centres...and how to pull it off in today's IPv4-dominated world

The case for IPv6-only data centres...and how to pull it off in today's IPv4-dominated world The case for IPv6-only data centres...and how to pull it off in today's IPv4-dominated world Tore Anderson Redpill Linpro AS PLNOG10, Warszawa, February 2013 Our traditional DC layout VLAN cust. 1 ~150

More information

Patrick Grossetete Cisco Systems Cisco IOS IPv6 Product Manager 2003, Cisco Systems, Inc. All rights reserved.

Patrick Grossetete Cisco Systems Cisco IOS IPv6 Product Manager 2003, Cisco Systems, Inc. All rights reserved. Patrick Grossetete Cisco Systems Product Manager pgrosset@cisco.com 1 IPv6 Business Model Integration of IPv6 brings benefits but it has also a cost ROI not yet - easy to evaluate Additional business models

More information

Case Study A Service Provider s Road to IPv6

Case Study A Service Provider s Road to IPv6 Case Study A Service Provider s Road to IPv6 September 2010 Menog Amir Tabdili UnisonIP Consulting amir@unisonip.com The Scenario Residential Network L3 MPLS VPN Network Public Network The Scenario What

More information

Executive Summary...1 Chapter 1: Introduction...1

Executive Summary...1 Chapter 1: Introduction...1 Table of Contents Executive Summary...1 Chapter 1: Introduction...1 SSA Organization... 1 IRM Strategic Plan Purpose... 3 IRM Strategic Plan Objectives... 4 Relationship to Other Strategic Planning Documents...

More information

CONCEPTION ON TRANSITION METHODS: DEPLOYING NETWORKS FROM IPV4 TO IPV6

CONCEPTION ON TRANSITION METHODS: DEPLOYING NETWORKS FROM IPV4 TO IPV6 CONCEPTION ON TRANSITION METHODS: DEPLOYING NETWORKS FROM IPV4 TO IPV6 1 MS. CHAITA JANI, 2 PROF.MEGHA MEHTA 1 M.E.[C.E] Student, Department Of Computer Engineering, Noble Group Of Institutions, Junagadh,Gujarat

More information

Comcast IPv6 Trials NANOG50 John Jason Brzozowski

Comcast IPv6 Trials NANOG50 John Jason Brzozowski Comcast IPv6 Trials NANOG50 John Jason Brzozowski October 2010 Overview Background Goals and Objectives Trials Observations 2 Background Comcast IPv6 program started over 5 years ago Incrementally planned

More information

Journey to IPv6 A Real-World deployment for Mobiles

Journey to IPv6 A Real-World deployment for Mobiles Journey to IPv6 A Real-World deployment for Mobiles APRICOT 2017 February 2017 Telstra Unrestricted Copyright Telstra Introduction Instructional Slide Jeff Schmidt- Technology Team Manager, Telstra Wireless

More information

Juniper Networks Certified Professional Security Bootcamp, AJSEC and JIPS (JNCIP-SEC BC)

Juniper Networks Certified Professional Security Bootcamp, AJSEC and JIPS (JNCIP-SEC BC) Juniper Networks Certified Professional Security Bootcamp, AJSEC and JIPS (JNCIP-SEC BC) This course combines both Advanced Junos Security (AJSEC) and Junos Intrusion Prevention Systems (JIPS) into five

More information

Migration to IPv6 using DNS64/NAT64. Stephan Lagerholm

Migration to IPv6 using DNS64/NAT64. Stephan Lagerholm Migration to IPv6 using DNS64/NAT64 Stephan Lagerholm Agenda / About me DNS Architect at Secure64 Software Corp. Director and founder of the TXv6TF Personal blog at IPv4depletion.com 1 IPv4 depletion Global

More information

The trend of IPv4 over IPv6 techniques, use cases and experience

The trend of IPv4 over IPv6 techniques, use cases and experience APRICOT 2013 @ Singapore The trend of IPv4 over IPv6 techniques, use cases and experience Japan Internet Exchange Co., Ltd. Masataka MAWATARI Copyright 2013 Japan Internet Exchange

More information

"Charting the Course... IPv6 Bootcamp Course. Course Summary

Charting the Course... IPv6 Bootcamp Course. Course Summary Course Summary Description This intermediate - advanced, hands-on course covers pertinent topics needed for IPv6 migration and deployment strategies. IPv6 novices can expect to gain a thorough understanding

More information

Carrier Grade NAT - Observations and Recommendations. Chris Grundemann North American IPv6 Summit 11 April 2012

Carrier Grade NAT - Observations and Recommendations. Chris Grundemann North American IPv6 Summit 11 April 2012 Carrier Grade NAT - Observations and Recommendations Chris Grundemann North American IPv6 Summit 11 April 2012 Agenda CGN Technology CGN Challenges CGN Architectures Conclusions 2 Cable Television Laboratories,

More information

IPv6 implementation aspects in the operator s environment. Grzegorz Kornacki F5 Field Systems Engineer

IPv6 implementation aspects in the operator s environment. Grzegorz Kornacki F5 Field Systems Engineer IPv6 implementation aspects in the operator s environment Grzegorz Kornacki F5 Field Systems Engineer Exposing applications & services to IP v6 Exposing applications / services to IP v6 Facebook has already

More information

Intended status: Standards Track Expires: April 26, 2012 Y. Ma Beijing University of Posts and Telecommunications October 24, 2011

Intended status: Standards Track Expires: April 26, 2012 Y. Ma Beijing University of Posts and Telecommunications October 24, 2011 softwire Internet-Draft Intended status: Standards Track Expires: April 26, 2012 Z. Li China Mobile Q. Zhao X. Huang Y. Ma Beijing University of Posts and Telecommunications October 24, 2011 DS-Lite Intra-Domain

More information

Securizarea Calculatoarelor și a Rețelelor 32. Tehnologia MPLS VPN

Securizarea Calculatoarelor și a Rețelelor 32. Tehnologia MPLS VPN Platformă de e-learning și curriculă e-content pentru învățământul superior tehnic Securizarea Calculatoarelor și a Rețelelor 32. Tehnologia MPLS VPN MPLS VPN 5-ian-2010 What this lecture is about: IP

More information

IPv6 migration challenges and Security

IPv6 migration challenges and Security IPv6 migration challenges and Security ITU Regional Workshop for the CIS countries Recommendations on transition from IPv4 to IPv6 in the CIS region, 16-18 April 2014 Tashkent, Republic of Uzbekistan Desire.karyabwite@itu.int

More information

IPv6 in 2G and 3G Networks. John Loughney. North American IPv6 Forum 2004

IPv6 in 2G and 3G Networks. John Loughney. North American IPv6 Forum 2004 IPv6 in 2G and 3G Networks John Loughney North American IPv6 Forum 2004 Introduction Relevant IPv6 Status in the IETF Relevant IPv6 Status in 3GPP Relevant IPv6 Status in 3GPP2 Conclusion What IPv6 Brings

More information

IPv6 tutorial. RedIRIS Miguel Angel Sotos

IPv6 tutorial. RedIRIS Miguel Angel Sotos IPv6 tutorial RedIRIS Miguel Angel Sotos miguel.sotos@rediris.es Agenda History Why IPv6 IPv6 addresses Autoconfiguration DNS Transition mechanisms Security in IPv6 IPv6 in Windows and Linux IPv6 now 2

More information

Why, When & How? Asela Galappattige Sri Lanka Telecom PLC

Why, When & How? Asela Galappattige Sri Lanka Telecom PLC Why, When & How? Asela Galappattige Sri Lanka Telecom PLC LkNOG Conference, Colombo Sri Lanka, 20 th Oct 2017 Precursor World has run out of IPv4 addresses IPv6 is the new Network Address Scheme for the

More information

IPv6 Transition Solutions for 3GPP Networks

IPv6 Transition Solutions for 3GPP Networks v6 Transition Solutions for 3GPP Networks draft-wiljakka-3gpp-ipv6-transition-00.txt Juha Wiljakka, Nokia on behalf of the 3GPP ngtrans design team 54 th IETF Meeting, Yokohama, Japan 17.07.02 1 3gpp_trans/

More information

IPv4 on-life support (or) The vision of way forward and tradeoffs in transition to IPv6 mechanisms space

IPv4 on-life support (or) The vision of way forward and tradeoffs in transition to IPv6 mechanisms space IPv4 on-life support (or) The vision of way forward and tradeoffs in transition to IPv6 mechanisms space Presenter: Jan Žorž Go6 Institute Slides put together by Ole Trøan, Cisco With help from: Randy

More information

Implementing NAT-PT for IPv6

Implementing NAT-PT for IPv6 Implementing NAT-PT for IPv6 Last Updated: August 1, 2012 Network Address Translation--Protocol Translation (NAT-PT) is an IPv6 to IPv4 translation mechanism, as defined in RFC 2765 and RFC 2766, allowing

More information

ARCHITECTING THE NETWORK FOR THE MOBILE IPV6 TRANSITION. Gary Hauser Sr. Marketing Mgr. Mobility Sector Member 3GPP RAN3 WG

ARCHITECTING THE NETWORK FOR THE MOBILE IPV6 TRANSITION. Gary Hauser Sr. Marketing Mgr. Mobility Sector Member 3GPP RAN3 WG ARCHITECTING THE NETWORK FOR THE MOBILE IPV6 TRANSITION Gary Hauser Sr. Marketing Mgr. Mobility Sector Member 3GPP RAN3 WG ghauser@juniper.net AGENDA! The State of Standards IPv6 & Transition in Mobile!

More information

Akamai's V6 Rollout Plan and Experience from a CDN Point of View. Christian Kaufmann Director Network Architecture Akamai Technologies, Inc.

Akamai's V6 Rollout Plan and Experience from a CDN Point of View. Christian Kaufmann Director Network Architecture Akamai Technologies, Inc. Akamai's V6 Rollout Plan and Experience from a CDN Point of View Christian Kaufmann Director Network Architecture Akamai Technologies, Inc. Agenda About Akamai General IPv6 transition technologies Challenges

More information

IP/ICMP Translation Algorithm (IIT) Xing Li, Congxiao Bao, Fred Baker

IP/ICMP Translation Algorithm (IIT) Xing Li, Congxiao Bao, Fred Baker IP/ICMP Translation Algorithm (IIT) Xing Li, Congxiao Bao, Fred Baker 2008-11-17 Abstract This document specifies an update to the Stateless IP/ICMP Translation Algorithm described in RFC 2765. The algorithm

More information

Benchmarking Methodology for IPv6 Transition Technologies

Benchmarking Methodology for IPv6 Transition Technologies iplab Benchmarking Methodology for IPv6 Transition Technologies draft-ietf-bmwg-ipv6-tran-tech-benchmarking-00 Marius Georgescu Nara Institute of Science and Technology Internet Engineering Laboratory

More information

Network Address Translation

Network Address Translation Network Address Translation All you want to know about (C) Herbert Haas 2005/03/11 Reasons for NAT Mitigate Internet address depletion Save global addresses (and money) Conserve internal address plan TCP

More information

Radware ADC. IPV6 RFCs and Compliance

Radware ADC. IPV6 RFCs and Compliance Radware ADC IPV6 s and Compliance Knowledgebase Team February 2016 Scope: This document lists most of the s that relevant to IPv6. Legend: Yes supported N/A not applicable No Currently not supported Relevance:

More information

Internet Engineering Task Force (IETF) Request for Comments: 7040 Category: Informational. O. Vautrin Juniper Networks Y. Lee Comcast November 2013

Internet Engineering Task Force (IETF) Request for Comments: 7040 Category: Informational. O. Vautrin Juniper Networks Y. Lee Comcast November 2013 Internet Engineering Task Force (IETF) Request for Comments: 7040 Category: Informational ISSN: 2070-1721 Y. Cui J. Wu P. Wu Tsinghua University O. Vautrin Juniper Networks Y. Lee Comcast November 2013

More information

Customer IPv6 Delivery

Customer IPv6 Delivery Customer IPv6 Delivery The Nextgen Experience Chris Chaundy, Nextgen Networks October 2011 Agenda Nextgen Network s strategy Just get a prefix and turn it on!?!? Scope of the project Hardware considerations

More information

IPv4/IPv6 Smooth Migration (IVI) Xing Li etc

IPv4/IPv6 Smooth Migration (IVI) Xing Li etc IPv4/IPv6 Smooth Migration (IVI) Xing Li etc. 2008-08-16 Abstract This presentation will introduce the concept and practice of prefix-specific and bi-direction explicit address mapping (IVI) for IPv4/IPv6

More information

Insights on IPv6 Security

Insights on IPv6 Security Insights on IPv6 Security Bilal Al Sabbagh, MSc, CISSP, CCSP Senior Information & Network Security Consultant - NXme Information Security Researcher Stockholm University 10/9/10 NXme FZ-LLC 1 NIXU Middle

More information

Migration Technologies. Dual Stack and Tunneling Using GRE, 6to4, and 6in4.

Migration Technologies. Dual Stack and Tunneling Using GRE, 6to4, and 6in4. Migration Technologies. Dual Stack and Tunneling Using GRE, 6to4, and 6in4. 1 By Gaza IPv6 Project Team Eng. Mohammed Abu-Jamous Why Not Dual Stack? Dual Stack is very important in our migration plane.

More information

CHAPTER 2 LITERATURE SURVEY

CHAPTER 2 LITERATURE SURVEY 23 CHAPTER 2 LITERATURE SURVEY The current version of the Internet Protocol IPv4 was first developed in the 1970s (Tanenbaum 2002), and the main protocol standard RFC 791 that governs IPv4 functionality

More information

The STRIDE towards IPv6: A Threat Model for IPv6 Transition Technologies

The STRIDE towards IPv6: A Threat Model for IPv6 Transition Technologies iplab The STRIDE towards IPv6: A Threat Model for IPv6 Transition Technologies draft-georgescu-opsec-ipv6-trans-tech-threat-model-01 Marius Georgescu Nara Institute of Science and Technology Internet Engineering

More information

2610:f8:ffff:2010:04:13:0085:1

2610:f8:ffff:2010:04:13:0085:1 2610:f8:ffff:2010:04:13:0085:1 Qwest IPv6 Implementation Experience Shawn Carroll 2610:f8:ffff:2010:04:13:0085:55 Previous Qwest Implementation Work Obtained 6bone Pseudo Next Level Aggregator (pnla) from

More information

IPv6 over IPv4 GRE Tunnels

IPv6 over IPv4 GRE Tunnels GRE tunnels are links between two points, with a separate tunnel for each link. The tunnels are not tied to a specific passenger or transport protocol, but in this case carry IPv6 as the passenger protocol

More information

Network Configuration Example

Network Configuration Example Network Configuration Example Configuring Dual-Stack Lite for IPv6 Access Release NCE0025 Modified: 2016-10-12 Juniper Networks, Inc. 1133 Innovation Way Sunnyvale, California 94089 USA 408-745-2000 www.juniper.net

More information

The Netwok 15 Layer IPv4 and IPv6 Part 3

The Netwok 15 Layer IPv4 and IPv6 Part 3 1 ÉCOLE POLYTECHNIQUE FÉDÉRALE DE LAUSANNE The Netwok 15 Layer IPv4 and IPv6 Part 3 Jean Yves Le Boudec 2015 Contents 1. Fragmentation 2. Interworking h4 h6 with NATs 3. Proxy ARP Textbook Chapter 5: The

More information

Tutorial: IPv6 Technology Overview Part II

Tutorial: IPv6 Technology Overview Part II Tutorial: IPv6 Technology Overview Part II Speaker: Byju Pularikkal, Cisco Systems, Inc Date: 11 th November 2011 1 Structure of IPv6 Protocol IPv4 and IPv6 Header Comparison IPv6 Extension Headers IPv6

More information

MAP-E as IPv4 over IPv6 Technology

MAP-E as IPv4 over IPv6 Technology APRICOT 2015 MAP-E as IPv4 over Technology - with some operational experiences - Mar.4.2015 Japan Network Enabler Corporation 日本ネットワークイネイブラー株式会社 (JPNE) (JPNE) 中川あきら Akira Nakagawa 240b::1 Agenda 1. Why

More information

Insights on IPv6 Security

Insights on IPv6 Security Insights on IPv6 Security Bilal Al Sabbagh, MSc, CISSP, CISA, CCSP Senior Information & Network Security Consultant NXme FZ-LLC Information Security Researcher, PhD Candidate Stockholm University bilal@nxme.net

More information

Configuring Network Address Translation

Configuring Network Address Translation Finding Feature Information, on page 1 Network Address Translation (NAT), on page 2 Benefits of Configuring NAT, on page 2 How NAT Works, on page 2 Uses of NAT, on page 3 NAT Inside and Outside Addresses,

More information

IPv6 Deployment at the University of Pennsylvania

IPv6 Deployment at the University of Pennsylvania IPv6 Deployment at the University of Pennsylvania Jorj Bauer and Shumon Huque University of Pennsylvania Educause Mid-Atlantic Regional Conference, Philadelphia, PA January 8 th, 2009 Outline Why you should

More information