SlideShare una empresa de Scribd logo
1 de 30
Enterprise IPv6 Deployment Experiences
                 - and -
    Deployment to U.S. Government

        Norwegian IPv6 Conference
                   22Nov, 2011
                Stavanger, Norway



                 Ron Broersma
              DREN Chief Engineer
         SPAWAR Network Security Manager
             Federal IPv6 Task Force
              ron@spawar.navy.mil
DREN/SPAWAR Progress




22-Nov-2011    Source: http://www.mrp.net/IPv6_Survey.html   2
The major issues for us
• Lack of IPv6/IPv4 feature parity
     – taking too long to get there
• Vendors not eating own dogfood
     – but starting to turn around
• Rogue RAs
     – set router priority to “high” as workaround
• Privacy Addresses (RFC4941)
     – no good solution yet
• MacOSX 10.6
     – but starting to get much better (10.6.8, 10.7)
• Network Management over IPv6
• Operational Complexity
22-Nov-2011                                             3
Lack of “feature parity”
• “feature parity” between IPv4 and IPv6 is
  something we expect in all products.
     – If the device supports a capability in IPv4, we
       want it to support that same capability in IPv6.
• Nobody delivers feature parity today.
     – Some vendors are working to fix this.
• Until we achieve feature parity...
     – IPv6 is something less than IPv4
     – You may need to re-engineer your network to
       accommodate missing features.

22-Nov-2011                                               4
Privacy Addresses (RFC 4941)
• Incompatible with many Enterprise environments
   – Need address stability for many reasons
      •Logging, Forensics, DNS stability, ACLs, etc.
• Enabled by default in Windows
   – Breaks plug-n-play because we have to visit every Windows
     machine to disable this feature.
• Just added in Mac OS X “Lion”.
• Now default in latest openSuSE (12.1)
• Ubuntuthinking about making it default.


[Privacy addresses] are horrible and I hope nobody really uses them, but they're better than NAT.
… Owen DeLong, Hurricane Electric



22-Nov-2011                                                                                    5
Living with Privacy addresses
    • Where your clients support DHCPv6, use that to
      assign addresses
         – No DHCPv6 client support in Windows XP, Mac OSX before 10.7
           (Lion), etc.
    • If all your Windows systems are in Active Directory,
      use GPO to disable privacy addresses
    • Options for other systems:
         – configure system to disable privacy addresses
              • registry setting in Windows (see below)
         – configure addresses statically on the hosts
         – keep a historical record of all MAC address to IPv6 address
           mappings for every host, for correlation in IDS and forensics tools

netsh interface ipv6 set privacy state=disabled store=persistent
netsh interface ipv6 set global randomizeidentifiers=disabled store=persistent
    22-Nov-2011                                                                  6
Rogue Router Advertisements
                              See RFC 6104
• Router Advertisements (RAs) inform hosts of the default
  router/gateway
• Windows systems with Internet Connection Sharing (ICS)
  enabled, and IPv6 enabled, will announce itself as the
  default router using RAs (“Rogue RAs”).
   – VERY common problem
• Hosts then start sending all their default traffic to the
  Windows system
• Workaround: set router preference to “high” (RFC 4191)
   – Doesn’t work on JunOS
• Long term: “RA Guard” (RFC 6105) or SeND (RFC 3971)

  22-Nov-2011                                            7
Network Management
• Can you do all your network management over
  IPv6?
    • Not yet, but very soon
    • Most products cannot be managed over IPv6-only
• Goal: IPv6-only on management LAN by January
  2011
    • already removed all IPv4 configuration from all layer-2
      switches
    • changed vendors in some cases
    • eliminated old hardware that will never support IPv6
    • awaiting software updates to resolve last remaining
      issues


22-Nov-2011                                                     8
Management over IPv6 in
                                     some products
        • Previously (June)…
            SSH       DNS   Syslog    SNMP   NTP   RADIUS   Unified MIB    Flow export    TFTP   CDP
            HTTPS                                           RFC4293                       FTP    LLDP
Cisco

Brocade                                1                                         2          3         4

Juniper                                                                          5



        • Now…
             SSH      DNS    Syslog   SNMP   NTP   RADIUS    Unified MIB    Flow export   TFTP   CDP
             HTTPS                                           RFC4293                      FTP    LLDP
 Cisco6

 Brocade                                1                                         2          3        4

 Juniper

 ALU            5                                                                 7




        22-Nov-2011                                                                               9
Operational Complexity
  • Added complexity increases security risk
  • dual-stack can be more complex than IPv4
    alone
  • example: firewalls
       – are all your policies equivalent?
       – how do you keep them in sync?
       – twice as much work?



This may incentivize us to shut down IPv4 sooner than later

  22-Nov-2011                                           11
World IPv6 day
• For DREN and SPAWAR, nothing new to turn
  on for the day
     – every day is IPv6 day for us
• What does it look like from an enterprise
  perspective, where ALL clients (users) are
  dual-stack?




22-Nov-2011                                    12
Percentage of Internet
                       traffic over IPv6
•   1% (2009, before Google whitelisting)
•   2.5% (Google whitelisted)
•   10% (late Jan 2010, Youtube added)
•   World IPv6 day… (peak at 68%)




22-Nov-2011                                 13
After IPv6 day
• Percentages across a day (5 min averages):




22-Nov-2011                                    14
After IPv6 day
• Past week (hourly averages):




• Month (daily averages):




22-Nov-2011                              15
Many enterprises have not
                   started their IPv6 deployment
• Reasons:
     –   Lack of incentives and resources
     –   Other higher priorities (improving security)
     –   It all seems overwhelming, and don't know where to start.
     –   No “business case”
• My answer:
     – If you haven't started, you're late and at risk
     – It doesn't take additional resources if you do it right.
     – For U.S. Federal agencies, there is a new mandate.
     – Don't waste time on developing a business case.
         • Its a matter of business continuity.
     – “Don't be afraid to break some glass”

22-Nov-2011                                                          16
IPv6 Deployment to
 U.S. Government
US Federal Agencies
• Earlier mandates didn’t work
• New mandate to IPv6-enable public facing
  services by Sept 2012
• Transition managers assigned in each agency
• Lots of planning, with little or no operational
  experience
• Addressing plans have problems
• Almost no progress on actually IPv6-enabling
  anything
• Major Carriers are not ready
    – even though they claim otherwise in public
• World IPv6 Day – missed opportunities


22-Nov-2011                                         18
US GovtDeployment Status

  http://usgv6-deploymon.antd.nist.gov

  (or just search for “USG IPv6 Status”)




22-Nov-2011                                19
Something is missing:
                       IPv6 Operational Experience
• Lots of planning is underway
     – transition planning
     – address planning
• Much of this planning is done by individuals who
  have never touched an IPv6 packet
• Too much energy is being wasted on plans that are
  flawed, because they are not based on operational
  experience
• It is more important to turn on IPv6 now and start
  moving some IPv6 traffic, than it is to have a
  complete plan


22-Nov-2011                                            20
Some Lessons Learned
• Gain operational IPv6 experience before putting too
  much effort into enterprise-wide planning
• Addressing Plans
     – everyone makes the same mistakes
• Go native (dual stack)
• Start from outside, and work in
     – focus now on public facing services
• There will be challenges (surprises) along the way
• You can automate the DNS updates
• It doesn’t require significant resources, if you start
  early and leverage tech refresh

22-Nov-2011                                                21
Addressing Plans
• Without sufficient operational experience with IPv6
  deployment, you WILL get it wrong at first.
     – usually takes the 3rd time to get it right
• Planners are hindered by IPv4-thinking
     – being conservative with address space
     – thinking “hosts” instead of “subnets”




22-Nov-2011                                             22
Addressing Plans
• Common mistakes
     – Doing other than /64 for subnets
          • Didn’t read RFC 4291 nor 5375
     – Thinking that the addressing plan has to be
       perfect the first time
          • because you can’t afford to re-address
     – Choosing allocations for sites based on size of site
          • because /48 for all sites is too wasteful
     – Justification “upwards”, instead of pre-allocation
       “downwards”
     – Host-centric allocation instead of subnet-centric

22-Nov-2011                                                 23
Making the paradigm shift
• You may be un-qualified to develop an IPv6
  addressing plan if you think:
     – /64 for subnets is wasteful
     – /64 for point-to-point links is wasteful
     – /48 for small sites is wasteful




22-Nov-2011                                       24
Once again…

   When doing an address plan, a major driver in IPv4
   was efficiency and conservation

   In IPv6, efficiency and conservation is NOT a major
   driver, but instead it is all about better alignment
   with network topology, accommodation of security
   architecture, and operational simplicity through
   standardization




22-Nov-2011                                               25
Addressing Plans
• After operational experience, you realize:
     – you never have to “grow” subnets, so you don’t need to
       accommodate that situation
     – if you don’t use /64’s for subnets, you can’t do SLAAC, DHCPv6,
       Multicast with Embedded-RP, etc.
     – there is a huge opportunity to align addressing with security
       topology, to simplify ACLs
     – you can better align subneting and aggregation with existing
       topology
     – it is a bad idea to embed IPv4 addresses in IPv6
     – nibble (4 bit) boundaries align better with PTR records
     – every interface has multiple IPv6 addresses
     – internal aggregation is not as important as you initially thought
     – you can do a lot of pre-allocation


22-Nov-2011                                                                26
Feedback received after I
                   presented the above
• From one of the Federal Agency Engineers:
     – “using /64 everywhere including point-to-point
       links is crazy”
     – “RFCs aren’t rules... There will be new RFCs”
     – “wait with deploying IPv6 until these problems are
       worked out”
     – “If everybody in the world did what the presenter
       did, then we will indeed run out of IPv6
       addresses”
     – “I hope all agencies don’t follow his aggressive
       recommendations like sheep”

22-Nov-2011                                             27
Other common mistakes
• Working from inside out
• Thinking that “native IPv6” means that you
  have to disable IPv4
• Too much use of translators
• Missed opportunities




22-Nov-2011                                    28
Final Thoughts, Summary
• Only use providers and suppliers that have a
  good IPv6 story
• IPv6 is ready for deployment to the Enterprise
• Most important to IPv6-enable the public
  Internet now
• Large bureaucracies have major challenges
  ahead
   – we need to help, and it may also require standards
     cast into strong policy


22-Nov-2011                                           29
END
Any Questions?
  Contact me at:
 ron@spawar.navy.mil
Benefits of IPv6 today
                                    (examples)
• Addressing
     –   can better map subnets to reality
     –   can align with security topology, simplifying ACLs
     –   sparse addressing (harder to scan/map)
     –   never have to worry about “growing” a subnet to hold new
         machines
     –   auto-configuration, plug-n-play
     –   universal subnet size, no surprises, no operator confusion,
         no bitmath
     –   shorter addresses in some cases
     –   at home: multiple subnets rather than single IP that you
         have to NAT
• Multicast is simpler
     – embedded RP
     – no MSDP

22-Nov-2011                                                            31

Más contenido relacionado

La actualidad más candente

Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501
IPv6no
 
Geir Making the leap to ipv6 final
Geir Making the leap to ipv6 finalGeir Making the leap to ipv6 final
Geir Making the leap to ipv6 final
IPv6no
 

La actualidad más candente (20)

implementing IPv6 in an ISP network, case study and lessons learned - Amos Ro...
implementing IPv6 in an ISP network, case study and lessons learned - Amos Ro...implementing IPv6 in an ISP network, case study and lessons learned - Amos Ro...
implementing IPv6 in an ISP network, case study and lessons learned - Amos Ro...
 
PLNOG 9: Ron Broersma - Enterprise IPv6 Deployment
PLNOG 9: Ron Broersma - Enterprise IPv6 Deployment PLNOG 9: Ron Broersma - Enterprise IPv6 Deployment
PLNOG 9: Ron Broersma - Enterprise IPv6 Deployment
 
IPv6 Deployment In Enterprise Networks
IPv6 Deployment In Enterprise NetworksIPv6 Deployment In Enterprise Networks
IPv6 Deployment In Enterprise Networks
 
Sipforum SIP & IPv6 discussion slides
Sipforum SIP & IPv6 discussion slidesSipforum SIP & IPv6 discussion slides
Sipforum SIP & IPv6 discussion slides
 
IPv6 Adressvergabe und Adressierung
IPv6 Adressvergabe und AdressierungIPv6 Adressvergabe und Adressierung
IPv6 Adressvergabe und Adressierung
 
Sip & IPv6 - time for action!
Sip & IPv6 - time for action!Sip & IPv6 - time for action!
Sip & IPv6 - time for action!
 
Presd1 09
Presd1 09Presd1 09
Presd1 09
 
Content over IPv6: no excuses
Content over IPv6: no excusesContent over IPv6: no excuses
Content over IPv6: no excuses
 
IPv6 at CSCS
IPv6 at CSCSIPv6 at CSCS
IPv6 at CSCS
 
IPv6 translation methods
IPv6 translation methodsIPv6 translation methods
IPv6 translation methods
 
COLO: COarse-grain LOck-stepping Virtual Machines for Non-stop Service
COLO: COarse-grain LOck-stepping Virtual Machines for Non-stop ServiceCOLO: COarse-grain LOck-stepping Virtual Machines for Non-stop Service
COLO: COarse-grain LOck-stepping Virtual Machines for Non-stop Service
 
Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501
 
Life Without IPv4: Tore Anderson, IPv6 guru, Redpill Linpro
Life Without IPv4: Tore Anderson, IPv6 guru, Redpill LinproLife Without IPv4: Tore Anderson, IPv6 guru, Redpill Linpro
Life Without IPv4: Tore Anderson, IPv6 guru, Redpill Linpro
 
2015 update: SIP and IPv6 issues - staying Happy in SIP
2015 update: SIP and IPv6 issues - staying Happy in SIP2015 update: SIP and IPv6 issues - staying Happy in SIP
2015 update: SIP and IPv6 issues - staying Happy in SIP
 
Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible) Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
Yes, IPv6 is Real! How To Make Your Apps Work (And Be As Fast As Possible)
 
Successfully Deploying IPv6
Successfully Deploying IPv6Successfully Deploying IPv6
Successfully Deploying IPv6
 
IPV6 Network Simulation Projects Research Guidance
IPV6 Network Simulation Projects Research GuidanceIPV6 Network Simulation Projects Research Guidance
IPV6 Network Simulation Projects Research Guidance
 
12.00 - Dr. Tim Chown - University of Southampton
12.00 - Dr. Tim Chown - University of Southampton12.00 - Dr. Tim Chown - University of Southampton
12.00 - Dr. Tim Chown - University of Southampton
 
Geir Making the leap to ipv6 final
Geir Making the leap to ipv6 finalGeir Making the leap to ipv6 final
Geir Making the leap to ipv6 final
 
SIP and DNS - federation, failover, load balancing and more
SIP and DNS - federation, failover, load balancing and moreSIP and DNS - federation, failover, load balancing and more
SIP and DNS - federation, failover, load balancing and more
 

Destacado

Destacado (13)

Michael De Leo Global IPv6 Summit México 2009
Michael De Leo Global IPv6 Summit México 2009Michael De Leo Global IPv6 Summit México 2009
Michael De Leo Global IPv6 Summit México 2009
 
Hands-on Experience with IPv6 Routing and Services
Hands-on Experience with IPv6 Routing and ServicesHands-on Experience with IPv6 Routing and Services
Hands-on Experience with IPv6 Routing and Services
 
IPv6 Best Practice
IPv6 Best PracticeIPv6 Best Practice
IPv6 Best Practice
 
IPv6 at LinkedIn
IPv6 at LinkedInIPv6 at LinkedIn
IPv6 at LinkedIn
 
Enterprise IPv6 Deployment
Enterprise IPv6 Deployment Enterprise IPv6 Deployment
Enterprise IPv6 Deployment
 
IPv6 Transition Strategies
IPv6 Transition StrategiesIPv6 Transition Strategies
IPv6 Transition Strategies
 
IPv6 experience from a large enterprise - Networkshop44
IPv6 experience from a large enterprise - Networkshop44IPv6 experience from a large enterprise - Networkshop44
IPv6 experience from a large enterprise - Networkshop44
 
Ipv6 deployment at the university of warwick - networkshop44
Ipv6 deployment at the university of warwick - networkshop44Ipv6 deployment at the university of warwick - networkshop44
Ipv6 deployment at the university of warwick - networkshop44
 
Internet Protocol version 6
Internet Protocol version 6Internet Protocol version 6
Internet Protocol version 6
 
IPV6 ADDRESS
IPV6 ADDRESSIPV6 ADDRESS
IPV6 ADDRESS
 
IPv6 Readiness Measurement BoF Report
IPv6 Readiness Measurement BoF ReportIPv6 Readiness Measurement BoF Report
IPv6 Readiness Measurement BoF Report
 
Akamai IPv6 Measurement
Akamai IPv6 MeasurementAkamai IPv6 Measurement
Akamai IPv6 Measurement
 
IPv4 to IPv6
IPv4 to IPv6IPv4 to IPv6
IPv4 to IPv6
 

Similar a Ron Broersma dren-stavanger-22 nov2011

Addressing plans
Addressing plansAddressing plans
Addressing plans
enes373
 

Similar a Ron Broersma dren-stavanger-22 nov2011 (20)

ION San Diego - US Federal IPv6 Deployments
ION San Diego - US Federal IPv6 DeploymentsION San Diego - US Federal IPv6 Deployments
ION San Diego - US Federal IPv6 Deployments
 
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
 
IPv6 Security - Workshop mit Live Demo
IPv6 Security - Workshop mit Live DemoIPv6 Security - Workshop mit Live Demo
IPv6 Security - Workshop mit Live Demo
 
Rapid IPv6 Deployment for ISP Networks
Rapid IPv6 Deployment for ISP NetworksRapid IPv6 Deployment for ISP Networks
Rapid IPv6 Deployment for ISP Networks
 
ARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities ReportARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities Report
 
Tech 2 Tech IPv6 presentation
Tech 2 Tech IPv6 presentationTech 2 Tech IPv6 presentation
Tech 2 Tech IPv6 presentation
 
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
 
Successes and Challenges of IPv6 Transition at APNIC
Successes and Challenges of IPv6 Transition at APNICSuccesses and Challenges of IPv6 Transition at APNIC
Successes and Challenges of IPv6 Transition at APNIC
 
Addressing plans
Addressing plansAddressing plans
Addressing plans
 
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration Engineering
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration EngineeringCAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration Engineering
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration Engineering
 
IPv6 Security Panel (U of Penn)
IPv6 Security Panel (U of Penn)IPv6 Security Panel (U of Penn)
IPv6 Security Panel (U of Penn)
 
RIPE 71 and IETF 94 reports webinar
RIPE 71 and IETF 94 reports webinarRIPE 71 and IETF 94 reports webinar
RIPE 71 and IETF 94 reports webinar
 
My sql tutorial-oscon-2012
My sql tutorial-oscon-2012My sql tutorial-oscon-2012
My sql tutorial-oscon-2012
 
【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering community
【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering community【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering community
【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering community
 
Yeti DNS Project
Yeti DNS ProjectYeti DNS Project
Yeti DNS Project
 
IPv6 Security
IPv6 SecurityIPv6 Security
IPv6 Security
 
Taking Splunk to the Next Level - Architecture Breakout Session
Taking Splunk to the Next Level - Architecture Breakout SessionTaking Splunk to the Next Level - Architecture Breakout Session
Taking Splunk to the Next Level - Architecture Breakout Session
 
Ceph Day Amsterdam 2015 - Ceph over IPv6
Ceph Day Amsterdam 2015 - Ceph over IPv6 Ceph Day Amsterdam 2015 - Ceph over IPv6
Ceph Day Amsterdam 2015 - Ceph over IPv6
 
12 steps for IPv6 Deployment in Governments and Enterprises
12 steps for IPv6 Deployment in Governments and Enterprises12 steps for IPv6 Deployment in Governments and Enterprises
12 steps for IPv6 Deployment in Governments and Enterprises
 
DOE Magellan OpenStack user story
DOE Magellan OpenStack user storyDOE Magellan OpenStack user story
DOE Magellan OpenStack user story
 

Más de IPv6no

I pv6 forum_certification_conor_20120424
I pv6 forum_certification_conor_20120424I pv6 forum_certification_conor_20120424
I pv6 forum_certification_conor_20120424
IPv6no
 
Steinar ipv6forum 20111121v2
Steinar ipv6forum 20111121v2Steinar ipv6forum 20111121v2
Steinar ipv6forum 20111121v2
IPv6no
 
Uwe Germany ipv6-strategy-public
Uwe Germany ipv6-strategy-publicUwe Germany ipv6-strategy-public
Uwe Germany ipv6-strategy-public
IPv6no
 
Ole - Ipv4onlifesupport
Ole - Ipv4onlifesupportOle - Ipv4onlifesupport
Ole - Ipv4onlifesupport
IPv6no
 
Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501
IPv6no
 
Tore K IPv6 and Altibox
Tore K IPv6 and AltiboxTore K IPv6 and Altibox
Tore K IPv6 and Altibox
IPv6no
 
Nathalie - Stavanger
Nathalie - StavangerNathalie - Stavanger
Nathalie - Stavanger
IPv6no
 
11-Sigurd_Thunem-IPv6_through_moderniation
11-Sigurd_Thunem-IPv6_through_moderniation11-Sigurd_Thunem-IPv6_through_moderniation
11-Sigurd_Thunem-IPv6_through_moderniation
IPv6no
 
17-Pete_Vickers-IPv6-in-the-Mobile-Net
17-Pete_Vickers-IPv6-in-the-Mobile-Net17-Pete_Vickers-IPv6-in-the-Mobile-Net
17-Pete_Vickers-IPv6-in-the-Mobile-Net
IPv6no
 

Más de IPv6no (18)

I pv6 forum_certification_conor_20120424
I pv6 forum_certification_conor_20120424I pv6 forum_certification_conor_20120424
I pv6 forum_certification_conor_20120424
 
Steinar ipv6forum 20111121v2
Steinar ipv6forum 20111121v2Steinar ipv6forum 20111121v2
Steinar ipv6forum 20111121v2
 
Uwe Germany ipv6-strategy-public
Uwe Germany ipv6-strategy-publicUwe Germany ipv6-strategy-public
Uwe Germany ipv6-strategy-public
 
Ole - Ipv4onlifesupport
Ole - Ipv4onlifesupportOle - Ipv4onlifesupport
Ole - Ipv4onlifesupport
 
Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501
 
Tore K IPv6 and Altibox
Tore K IPv6 and AltiboxTore K IPv6 and Altibox
Tore K IPv6 and Altibox
 
Nathalie - Stavanger
Nathalie - StavangerNathalie - Stavanger
Nathalie - Stavanger
 
11-Sigurd_Thunem-IPv6_through_moderniation
11-Sigurd_Thunem-IPv6_through_moderniation11-Sigurd_Thunem-IPv6_through_moderniation
11-Sigurd_Thunem-IPv6_through_moderniation
 
50 billion connected wireless devices... IPv6, anyone?: Fredrik Garneij, Syst...
50 billion connected wireless devices... IPv6, anyone?: Fredrik Garneij, Syst...50 billion connected wireless devices... IPv6, anyone?: Fredrik Garneij, Syst...
50 billion connected wireless devices... IPv6, anyone?: Fredrik Garneij, Syst...
 
IPv6 Seen From Statoil: Knut Sebastian Tungland, Chief Engineer Information T...
IPv6 Seen From Statoil: Knut Sebastian Tungland, Chief Engineer Information T...IPv6 Seen From Statoil: Knut Sebastian Tungland, Chief Engineer Information T...
IPv6 Seen From Statoil: Knut Sebastian Tungland, Chief Engineer Information T...
 
17-Pete_Vickers-IPv6-in-the-Mobile-Net
17-Pete_Vickers-IPv6-in-the-Mobile-Net17-Pete_Vickers-IPv6-in-the-Mobile-Net
17-Pete_Vickers-IPv6-in-the-Mobile-Net
 
IPv6, DLD og NAT: Steinar Haug, IPv6 guru, Ventelo
IPv6, DLD og NAT: Steinar Haug, IPv6 guru, VenteloIPv6, DLD og NAT: Steinar Haug, IPv6 guru, Ventelo
IPv6, DLD og NAT: Steinar Haug, IPv6 guru, Ventelo
 
Mobile Broadband and IPv6 in Slovenia: Jan Zorz, Co-Founder Go6 Institute og ...
Mobile Broadband and IPv6 in Slovenia: Jan Zorz, Co-Founder Go6 Institute og ...Mobile Broadband and IPv6 in Slovenia: Jan Zorz, Co-Founder Go6 Institute og ...
Mobile Broadband and IPv6 in Slovenia: Jan Zorz, Co-Founder Go6 Institute og ...
 
IPv6 - The Time Is Now: Latif Ladid, President, IPv6 forum
IPv6 - The Time Is Now: Latif Ladid, President, IPv6 forumIPv6 - The Time Is Now: Latif Ladid, President, IPv6 forum
IPv6 - The Time Is Now: Latif Ladid, President, IPv6 forum
 
Future internet research and IPv6: Till Christopher Lech, Seniorrådgiver, Nor...
Future internet research and IPv6: Till Christopher Lech, Seniorrådgiver, Nor...Future internet research and IPv6: Till Christopher Lech, Seniorrådgiver, Nor...
Future internet research and IPv6: Till Christopher Lech, Seniorrådgiver, Nor...
 
IPv6 Statlig og offentlig fokus - hvorfor nå?: Patrik Fältström, Distinguishe...
IPv6 Statlig og offentlig fokus - hvorfor nå?: Patrik Fältström, Distinguishe...IPv6 Statlig og offentlig fokus - hvorfor nå?: Patrik Fältström, Distinguishe...
IPv6 Statlig og offentlig fokus - hvorfor nå?: Patrik Fältström, Distinguishe...
 
Fra IPv4 til IPv6 bakgrunn og historie: Hans Petter Holen, IT Direktør, Visma...
Fra IPv4 til IPv6 bakgrunn og historie: Hans Petter Holen, IT Direktør, Visma...Fra IPv4 til IPv6 bakgrunn og historie: Hans Petter Holen, IT Direktør, Visma...
Fra IPv4 til IPv6 bakgrunn og historie: Hans Petter Holen, IT Direktør, Visma...
 
IPv6 through modernization: Sigurd Thunem, Direktør Arkitektur og Strategi, T...
IPv6 through modernization: Sigurd Thunem, Direktør Arkitektur og Strategi, T...IPv6 through modernization: Sigurd Thunem, Direktør Arkitektur og Strategi, T...
IPv6 through modernization: Sigurd Thunem, Direktør Arkitektur og Strategi, T...
 

Último

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Último (20)

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 

Ron Broersma dren-stavanger-22 nov2011

  • 1. Enterprise IPv6 Deployment Experiences - and - Deployment to U.S. Government Norwegian IPv6 Conference 22Nov, 2011 Stavanger, Norway Ron Broersma DREN Chief Engineer SPAWAR Network Security Manager Federal IPv6 Task Force ron@spawar.navy.mil
  • 2. DREN/SPAWAR Progress 22-Nov-2011 Source: http://www.mrp.net/IPv6_Survey.html 2
  • 3. The major issues for us • Lack of IPv6/IPv4 feature parity – taking too long to get there • Vendors not eating own dogfood – but starting to turn around • Rogue RAs – set router priority to “high” as workaround • Privacy Addresses (RFC4941) – no good solution yet • MacOSX 10.6 – but starting to get much better (10.6.8, 10.7) • Network Management over IPv6 • Operational Complexity 22-Nov-2011 3
  • 4. Lack of “feature parity” • “feature parity” between IPv4 and IPv6 is something we expect in all products. – If the device supports a capability in IPv4, we want it to support that same capability in IPv6. • Nobody delivers feature parity today. – Some vendors are working to fix this. • Until we achieve feature parity... – IPv6 is something less than IPv4 – You may need to re-engineer your network to accommodate missing features. 22-Nov-2011 4
  • 5. Privacy Addresses (RFC 4941) • Incompatible with many Enterprise environments – Need address stability for many reasons •Logging, Forensics, DNS stability, ACLs, etc. • Enabled by default in Windows – Breaks plug-n-play because we have to visit every Windows machine to disable this feature. • Just added in Mac OS X “Lion”. • Now default in latest openSuSE (12.1) • Ubuntuthinking about making it default. [Privacy addresses] are horrible and I hope nobody really uses them, but they're better than NAT. … Owen DeLong, Hurricane Electric 22-Nov-2011 5
  • 6. Living with Privacy addresses • Where your clients support DHCPv6, use that to assign addresses – No DHCPv6 client support in Windows XP, Mac OSX before 10.7 (Lion), etc. • If all your Windows systems are in Active Directory, use GPO to disable privacy addresses • Options for other systems: – configure system to disable privacy addresses • registry setting in Windows (see below) – configure addresses statically on the hosts – keep a historical record of all MAC address to IPv6 address mappings for every host, for correlation in IDS and forensics tools netsh interface ipv6 set privacy state=disabled store=persistent netsh interface ipv6 set global randomizeidentifiers=disabled store=persistent 22-Nov-2011 6
  • 7. Rogue Router Advertisements See RFC 6104 • Router Advertisements (RAs) inform hosts of the default router/gateway • Windows systems with Internet Connection Sharing (ICS) enabled, and IPv6 enabled, will announce itself as the default router using RAs (“Rogue RAs”). – VERY common problem • Hosts then start sending all their default traffic to the Windows system • Workaround: set router preference to “high” (RFC 4191) – Doesn’t work on JunOS • Long term: “RA Guard” (RFC 6105) or SeND (RFC 3971) 22-Nov-2011 7
  • 8. Network Management • Can you do all your network management over IPv6? • Not yet, but very soon • Most products cannot be managed over IPv6-only • Goal: IPv6-only on management LAN by January 2011 • already removed all IPv4 configuration from all layer-2 switches • changed vendors in some cases • eliminated old hardware that will never support IPv6 • awaiting software updates to resolve last remaining issues 22-Nov-2011 8
  • 9. Management over IPv6 in some products • Previously (June)… SSH DNS Syslog SNMP NTP RADIUS Unified MIB Flow export TFTP CDP HTTPS RFC4293 FTP LLDP Cisco Brocade 1 2 3 4 Juniper 5 • Now… SSH DNS Syslog SNMP NTP RADIUS Unified MIB Flow export TFTP CDP HTTPS RFC4293 FTP LLDP Cisco6 Brocade 1 2 3 4 Juniper ALU 5 7 22-Nov-2011 9
  • 10. Operational Complexity • Added complexity increases security risk • dual-stack can be more complex than IPv4 alone • example: firewalls – are all your policies equivalent? – how do you keep them in sync? – twice as much work? This may incentivize us to shut down IPv4 sooner than later 22-Nov-2011 11
  • 11. World IPv6 day • For DREN and SPAWAR, nothing new to turn on for the day – every day is IPv6 day for us • What does it look like from an enterprise perspective, where ALL clients (users) are dual-stack? 22-Nov-2011 12
  • 12. Percentage of Internet traffic over IPv6 • 1% (2009, before Google whitelisting) • 2.5% (Google whitelisted) • 10% (late Jan 2010, Youtube added) • World IPv6 day… (peak at 68%) 22-Nov-2011 13
  • 13. After IPv6 day • Percentages across a day (5 min averages): 22-Nov-2011 14
  • 14. After IPv6 day • Past week (hourly averages): • Month (daily averages): 22-Nov-2011 15
  • 15. Many enterprises have not started their IPv6 deployment • Reasons: – Lack of incentives and resources – Other higher priorities (improving security) – It all seems overwhelming, and don't know where to start. – No “business case” • My answer: – If you haven't started, you're late and at risk – It doesn't take additional resources if you do it right. – For U.S. Federal agencies, there is a new mandate. – Don't waste time on developing a business case. • Its a matter of business continuity. – “Don't be afraid to break some glass” 22-Nov-2011 16
  • 16. IPv6 Deployment to U.S. Government
  • 17. US Federal Agencies • Earlier mandates didn’t work • New mandate to IPv6-enable public facing services by Sept 2012 • Transition managers assigned in each agency • Lots of planning, with little or no operational experience • Addressing plans have problems • Almost no progress on actually IPv6-enabling anything • Major Carriers are not ready – even though they claim otherwise in public • World IPv6 Day – missed opportunities 22-Nov-2011 18
  • 18. US GovtDeployment Status http://usgv6-deploymon.antd.nist.gov (or just search for “USG IPv6 Status”) 22-Nov-2011 19
  • 19. Something is missing: IPv6 Operational Experience • Lots of planning is underway – transition planning – address planning • Much of this planning is done by individuals who have never touched an IPv6 packet • Too much energy is being wasted on plans that are flawed, because they are not based on operational experience • It is more important to turn on IPv6 now and start moving some IPv6 traffic, than it is to have a complete plan 22-Nov-2011 20
  • 20. Some Lessons Learned • Gain operational IPv6 experience before putting too much effort into enterprise-wide planning • Addressing Plans – everyone makes the same mistakes • Go native (dual stack) • Start from outside, and work in – focus now on public facing services • There will be challenges (surprises) along the way • You can automate the DNS updates • It doesn’t require significant resources, if you start early and leverage tech refresh 22-Nov-2011 21
  • 21. Addressing Plans • Without sufficient operational experience with IPv6 deployment, you WILL get it wrong at first. – usually takes the 3rd time to get it right • Planners are hindered by IPv4-thinking – being conservative with address space – thinking “hosts” instead of “subnets” 22-Nov-2011 22
  • 22. Addressing Plans • Common mistakes – Doing other than /64 for subnets • Didn’t read RFC 4291 nor 5375 – Thinking that the addressing plan has to be perfect the first time • because you can’t afford to re-address – Choosing allocations for sites based on size of site • because /48 for all sites is too wasteful – Justification “upwards”, instead of pre-allocation “downwards” – Host-centric allocation instead of subnet-centric 22-Nov-2011 23
  • 23. Making the paradigm shift • You may be un-qualified to develop an IPv6 addressing plan if you think: – /64 for subnets is wasteful – /64 for point-to-point links is wasteful – /48 for small sites is wasteful 22-Nov-2011 24
  • 24. Once again… When doing an address plan, a major driver in IPv4 was efficiency and conservation In IPv6, efficiency and conservation is NOT a major driver, but instead it is all about better alignment with network topology, accommodation of security architecture, and operational simplicity through standardization 22-Nov-2011 25
  • 25. Addressing Plans • After operational experience, you realize: – you never have to “grow” subnets, so you don’t need to accommodate that situation – if you don’t use /64’s for subnets, you can’t do SLAAC, DHCPv6, Multicast with Embedded-RP, etc. – there is a huge opportunity to align addressing with security topology, to simplify ACLs – you can better align subneting and aggregation with existing topology – it is a bad idea to embed IPv4 addresses in IPv6 – nibble (4 bit) boundaries align better with PTR records – every interface has multiple IPv6 addresses – internal aggregation is not as important as you initially thought – you can do a lot of pre-allocation 22-Nov-2011 26
  • 26. Feedback received after I presented the above • From one of the Federal Agency Engineers: – “using /64 everywhere including point-to-point links is crazy” – “RFCs aren’t rules... There will be new RFCs” – “wait with deploying IPv6 until these problems are worked out” – “If everybody in the world did what the presenter did, then we will indeed run out of IPv6 addresses” – “I hope all agencies don’t follow his aggressive recommendations like sheep” 22-Nov-2011 27
  • 27. Other common mistakes • Working from inside out • Thinking that “native IPv6” means that you have to disable IPv4 • Too much use of translators • Missed opportunities 22-Nov-2011 28
  • 28. Final Thoughts, Summary • Only use providers and suppliers that have a good IPv6 story • IPv6 is ready for deployment to the Enterprise • Most important to IPv6-enable the public Internet now • Large bureaucracies have major challenges ahead – we need to help, and it may also require standards cast into strong policy 22-Nov-2011 29
  • 29. END Any Questions? Contact me at: ron@spawar.navy.mil
  • 30. Benefits of IPv6 today (examples) • Addressing – can better map subnets to reality – can align with security topology, simplifying ACLs – sparse addressing (harder to scan/map) – never have to worry about “growing” a subnet to hold new machines – auto-configuration, plug-n-play – universal subnet size, no surprises, no operator confusion, no bitmath – shorter addresses in some cases – at home: multiple subnets rather than single IP that you have to NAT • Multicast is simpler – embedded RP – no MSDP 22-Nov-2011 31