gogo6 IPv6 Video Series. Event, presentation and speaker details below:
EVENT
gogoNET LIVE! 3: Enterprise wide Migration. http://gogonetlive.com
November 12 – 14, 2012 at San Jose State University, California
Agenda: http://gogonetlive.com/4105/gogonetlive3-agenda.asp
PRESENTATION
Overcoming Challenges of Deploying IPv6 in the live Enterprise Work Environment
Abstract: http://www.gogo6.com/profiles/blogs/my-panel-discussion-at-gogonet-live-3
Presentation video: http://www.gogo6.com/video/challenges-of-deploying-ipv6-in-the-live-enterprise-by-tina-tsou
Interview video: http://www.gogo6.com/video/interview-with-tina-tsou-at-gogonet-live-3-ipv6-conference
SPEAKER
Tina Tsou - Head of IPv6 Research, Huawei
Bio/Profile: http://www.gogo6.com/profile/TinaTSOU
MORE
Learn more about IPv6 on the gogoNET social network
http://www.gogo6.com
Get free IPv6 connectivity with Freenet6
http://www.gogo6.com/Freenet6
Subscribe to the gogo6 IPv6 Channel on YouTube
http://www.youtube.com/subscription_center?add_user=gogo6videos
Follow gogo6 on Twitter
http://twitter.com/gogo6inc
Like gogo6 on Facebook
http://www.facebook.com/pages/IPv6-products-community-and-services-gogo6/161626696777
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Overcoming Challenges of Deploying IPv6 in the live Enterprise Work Environment by Tina Tsou at gogoNET LIVE! 3 IPv6 Conference
1. Overcoming challenges of deploying IPv6
in the live Enterprise work environment
Tina Tsou (Speaker), Kenneth Durazzo, Wendell Rios www.huawei.com
Huawei Technologies
HUAWEI TECHNOLOGIES CO., LTD.
2. Agenda
It’s Only IP…Right?
Making the case
Defining success
Testing 360
Planning the Transition
Deployment Details
UCC
Applications / Network
Platforms
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential
4. It’s Only IP… Right?
Should be easy, no?
But what about…
Security policy and devices
Operating systems, Hypervisors
Servers, PCs and smart-devices
Network platforms
Services and Applications
VPN
Application Optimization
UCC
Private and Public Cloud Applications
DNS / DHCP / Printing
Monitoring / Troubleshooting tools
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential
5. Making the Case
Business Executives
IPv6 will help us increase IT flexibility for
new applications and communications,
for instance BYOD
CAPex cost should be minimal, OPex
Business Security should stay the same
Executives Operations Security Operations
IPv6 is here on the network, in fact all
new OS’s already support it, if you don’t
embrace it, how will you protect the
IT business?
Application / Server Operations
Many applications and tools already
support IPv6, resulting in minor changes
Application / Business to existing environment and processes
Server Function Business Function Leaders
Operations Leaders
How this will be non-intrusive to their
users and business goals but be an
enabler to their business (eg: BYOD)
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential
6. Defining Success
Business impact definition
What is the scope of deployment?
Entire environment? branch, campus or DC?
Phased deployment?
At the Edge? In the Core?
Timeline for cut-over
User QOE for:
Applications
Network
What is the desired successful
outcome (exit criteria)?
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential
7. Testing 360
Best practices
Set up a lab that mimics your target environment, but not at scale
Perform an inventory of:
Applications
Platforms / Devices
Work with employees to create User-stories / Use-cases for the target
environment
Test, test, test…
Devices / Applications / permutations
Involve security and other operations teams, early and often, even better
if they are part of the testing team
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential
8. Planning the Transition
Create the scope of work
Environment
Platforms
Applications
Users, etc
Get training for all impacted personnel for support of
IPv6 and any new systems put in place to support
the environment
Inventory all impacted devices and configurations.
Include wiring plant and HVAC, etc
Create clear documentation and points of contact for
transition activities
All OPS teams must be deeply involved (Sec / App /
Server / Network)
Socialize the scope of work and get buy-in / signatures
for cut-over dates / times
Go live!
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential
9. IPv6 production office networks
Enable all Explore practical IPv6
employees to deployment and
have IPv6 access transition options
Enable employees Enable product
to innovate and teams to test
collaborate with the new
external partners implementations
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential Page 9
11. IPv6 Network
OSPFv3 Static Routing
CGN @ NE40E
Santa Clara, CA
Content CE
Server Router
IPv6 Network Core IPv6
Network
AR AR
Plano, TX and Santa Clara, CA
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential Page 11
12. CGN and PCP Layout
UPnP DS-Lite NAT44
Private IPv4 Client/IPv4
IPv4 over IPv6 Public IPv4/Internet Client
Web Server
PCP
Port 2 CPE1 Port 3 IPv6 Internet
P2P Client-1
NON-PCP PCP PCP Server
Port 2
P2P Client-2
NATCoord IPv4 Internet
CPE2 CGN
Port 1 Port 3
Web Server (VM) UPnP/PCP Interworking NE40E-X3 Internet
NATCoord Client Huawei HG553 Client
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential Page 12
16. Phase 1 Enterprise Network Transition
Challenges:
• Security and compliance
• Multi zone networks based on use.
• Intranet networks highly secured and regulated by Corporate HQ.
• Nothing goes on the network unless approved by Information Security and IT.
• Too much “red tape.”
• Technology
• Existing infrastructure not ready, no IPv6 support.
• Support
• Minimal to none local resources.
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential Page 16
17. Phase 1 Enterprise Network Transition – cont.
Strategy:
• Security and compliance
• Solution or Proof of Concept implementation that does not break the rules.
• Technology
• Solution that utilizes existing network – no change in IT infrastructure.
• Support
• Get local Regional IT buy in.
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential Page 17
18. Phase 1 Enterprise Network Transition – cont.
Solution and scope:
• Deploy IPv6 stub network with dual nic Linux host runing NAT64/DNS64 service.
• IPv6 only host able to access IPv4 rfc1918 resources, i.e. Sharepoint portal, Proxy web server,
and etc; by utilizing NAT64 and DNS64 gateway.
Technology and resources:
• Allocate IPv4 rfc1918 network prefix for IPv4 dynamic mapping pool.
• Allocate IPv6 network prefixes:
• 2001:db8:1:ffff::/96 for NAT64/DNS64 service.
• Redhat Linux host with dual network adapters running NAT64/DNS64 service.
• Tayga stateless NAT64 open source application was installed and tested.
• TOTD DNS64 open source application was installed and tested.
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential Page 18
19. Phase 1 Enterprise Network Transition – cont.
cont.
• IPv6 NAT64 prefix (well-known or network-specific) is dedicated to mapped IPv4 addresses.
• NAT64 and DNS64 processes use the same prefix.
• Default gateway and DNS server of IPv6 host is the NAT64/DNS64 gateway.
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential Page 19
20. Phase 1 Enterprise Network Transition – cont.
Results:
• IPv6 host able to ping and telnet to network devices in IPv4 domain using NAT64 IPv6 prefix.
• IPv6 host able to access resources in IPv4 only domain using Fully Qualified Domain Names.
• IPv6 host able to use web proxy in IPv4 only domain to access Internet websites.
• Web proxy FQDN was hard set in host browser settings.
• IPv6 host able to browse and utilize Sharepoint portal/collaboration tool.
Next Steps:
• Explore and incorporate additional IPv6 technologies.
• DHCPv6
• Deploy architecture to larger scope – Phase 2.
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential Page 20
21. eSpace UC
PSTN/PLMN
Analog IP Phone UC Server Soft
Fax PC Client / Soft Phone PSTN Gateway U2990 (CALL Control) Console
HEADQUARTERS
SBC Firewall SVN
IP
E1/ATO
POTS
IPV4/IPV6
WiFi/3G
E1/T1 PSTN/PLMN ATO PSTN/PLMN
IAD U1980 EGW
SSL VPN
Analog Analog Internet PC Client
Fax Fax SBC
Proxy Soft Phone
IP Phone IP Phone
PC Client PC Client WiFi WiFi
BRANCH A BRANCH B PUBLIC NETWORK
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential Page 21
28. Huawei: IPv6 Deployment used by IEEE meeting
IEEE HOT INTERCONNECT CONFERENCE, Aug 22-24, hosted by Huawei at
Huawei campus on Santa Clara, CA, USA
IPv4/IPv6 Internet
IPv4/IPv6 Firewall
(support NAT
for IPv4)
IPv4 IPS/IDS
IPv4 AC
IPv4/IPv6
Core&Aggregation (Active)
(Gateway,iStack) IPv4 AC
(Standby)
Access Layer
IPv4 AP
IPv4/IPv6 STA
HUAWEI TECHNOLOGIES CO., LTD. Huawei Confidential Page 28