SlideShare ist ein Scribd-Unternehmen logo
1 von 17
Downloaden Sie, um offline zu lesen
IPV6
an introduction to transition planning




                          Eduardo Coelho
                         http://coelho.pro.br
TOPICS (1)

• why    you have to plan before the deployment

• the   framework

• whats    wrong with ipv4?

• dual   stack deployment strategy

• router   advertisements and the plug-and-play philosophy

• choosing   the equipments
TOPICS (2)

• IPv6   addressing

• DNS    settings delivery issues

• legacy   devices

• transition   protocols

• security   concerns

• final   suggestions
WHY YOU HAVE TO PLAN
    BEFORE THE DEPLOYMENT
• acceptplanning as part of IT culture as it should always have
 been (ps: if you`re already there, great!)

• your   planning can act as a decision-making tool

• including   be ready to defend investment choices

• documenting     helps delegate and check compliance

• feel   you are on top of the changing environment
THE FRAMEWORK

•a   simple framework for the changes

 • get    to know (conheça)

 • plan   (planeje)

 • test   (teste)

 • implement        (implemente)
WHAT’S WRONG WITH IPV4


• lack   of enough host addresses

• NAT     issues and lack of end-to-end connectivity

• note: you
          should pay attention to the opportunities that
 comes with ipv6 deploy
DUAL STACK DEPLOYMENT
         PHILOSOPHY

• ipv4   is not compatible with ipv6

• thedeployment of ipv6 is meant to be made world-wide in
 parallel to already functioning ipv4 networks

• while
      the traffic on internet and intranets shift to v6, transition
 protocols will help most equipment to remain connected
THE PLUG-AND-PLAY
               PHILOSOPHY
• plug-and-play   as a principle

• that   makes ipv6 more plug-and-play

• reduced     router processing

• better   connectivity auto-healing

• mobility   is supported

• multicast   gains momentum
CHOOSING THE EQUIPMENTS

• be   ready to update and test all your equipment

• when buying new equipment, consider the updating
 capabilities and the manufacturer update policies

• watch for JITC (Defense Information Systems Agency/Joint
 Interoperability Test Command) compatibility

• watch   for ipv6ready compatibility (an ipv6forum initiative)

• pay   special attention to routers
IPV6 ADDRESSING


• global   unicast

• link   local

• unique    local

• anycast, multicast, reserved   and special
DNS SETTINGS DELIVERY

• llmnr

• stateless   dhcp6 vs dns-ra

• watch   for windows non-compliance to rfc6106

• naming  is now more important than with ipv4, due to human
 difficulty manually handling ipv6 addresses
LEGACY DEVICES


• identify   which devices wont be able to talk ipv4

• identify   which devices wont be able to talk ipv6

• makechoices based on the need for devices which wont
 operate with dual ip stack
TRANSITION PROTOCOLS (1)

• there   a lot of transitional protocols, including some drafts

• be   careful about equipment support

• avoid
      transitional protocols when possible, due to security
 concerns (possible firewall traversal and datagram data
 obfuscation)

• isps   may offer dual stack connectivity or transparent tunneling
TRANSITION PROTOCOLS (2)

• recommended       transitional protocols:

 • initial   transition: 6to4 (auto), teredo (auto, ipv4 nat support)

 • intrasite, initial   transition: isatap

 • final   transition: 4in6 (manual, rfc2473)

• othertunnels: 6in4 (manual, broker based), 6over4 (requires
 ipv4 multicast, hard to comply), nat64 (translation protocol)
SECURITY CONCERNS

• rogue   routers

• rogue   dhcp servers

• sniffing

• spoofing

• tunneling   obfuscation
FINAL SUGGESTIONS

• carefully   choose isp offering

• define network-level addressing plan and enforce
 requirements

• have   a clear plan for naming and dhcp

• consider    deprecating ipv4-only devices

• prefer   dual-stack devices
REFERENCES
Unique Local Address                     Internet powers flip the IPv6 switch
http://en.wikipedia.org/wiki/            (FAQ)                                   Comparison of IPv6 support in
Unique_local_address                     http://news.cnet.com/                   operating systems
                                         8301-1001_3-57445316-92/internet-       http://en.wikipedia.org/wiki/
Unique Local Unicast Addresses           powers-flip-the-ipv6-switch-faq/        Comparison_of_IPv6_support_in_oper
http://tools.ietf.org/html/rfc4193                                               ating_systems
                                         IPv6-capable devices: Make sure they
Deprecating Site Local Addresses         are ready                               Internet Protocol Version 6 Address
http://tools.ietf.org/rfc/rfc3879.txt    http://www.techrepublic.com/blog/       Space
                                         networking/ipv6-capable-devices-        http://www.iana.org/assignments/ipv6-
IPv6 Support in Home Routers             make-sure-they-are-ready/2522           address-space/ipv6-address-space.xml
http://msdn.microsoft.com/en-us/
library/windows/hardware/                IPv6 Ready Logo Program                 Router Advertisement (radvd)
gg463251.aspx                            https://www.ipv6ready.org               configuration
                                                                                 http://wiki.openwrt.org/doc/uci/radvd
Prefix delegation                        IPv6: When do you really need to
http://en.wikipedia.org/wiki/            switch?                                 Does Win7 or W2K8 server support
Prefix_delegation                        http://www.zdnet.com/blog/networking/   RFC 6106?
                                         ipv6-when-do-you-really-need-to-        http://social.technet.microsoft.com/
Requirements for IPv6 Prefix             switch/2444                             Forums/en-US/ipv6/thread/
Delegation                                                                       5757980a-5983-4efc-
http://tools.ietf.org/html/rfc3769       Portal IPv6 NIC.br                      a5f3-27687b90fe41/
                                         http://ipv6.br
IPv6 Prefix Options for DHCP version 6                                           Delivering DNS via IPv6 Router
http://www.ietf.org/rfc/rfc3633.txt      IPv6                                    http://www.itdojo.com/2011/05/02/
                                         http://en.wikipedia.org/wiki/IPv6       delivering-dns-via-ipv6-router-
IP Version 6 Addressing Architecture                                             advertisements/
http://tools.ietf.org/html/rfc4291       IPv6 transition mechanisms
                                         http://en.wikipedia.org/wiki/
                                         IPv6_transition_mechanisms

Weitere ähnliche Inhalte

Was ist angesagt?

PLNOG 18 - Paweł Małachowski - Spy hard czyli regexpem po pakietach
PLNOG 18 - Paweł Małachowski - Spy hard czyli regexpem po pakietachPLNOG 18 - Paweł Małachowski - Spy hard czyli regexpem po pakietach
PLNOG 18 - Paweł Małachowski - Spy hard czyli regexpem po pakietachPROIDEA
 
MAGPI: Advanced Services: IPv6, Multicast, DNSSEC
MAGPI: Advanced Services: IPv6, Multicast, DNSSECMAGPI: Advanced Services: IPv6, Multicast, DNSSEC
MAGPI: Advanced Services: IPv6, Multicast, DNSSECShumon Huque
 
Oracle Sandbox
Oracle SandboxOracle Sandbox
Oracle SandboxDatavail
 
IPv6 strategy for deployment at ETH Switzerland
IPv6 strategy for deployment at ETH SwitzerlandIPv6 strategy for deployment at ETH Switzerland
IPv6 strategy for deployment at ETH SwitzerlandSwiss IPv6 Council
 
OpenStack Icehouse Over IPv6
OpenStack Icehouse Over IPv6OpenStack Icehouse Over IPv6
OpenStack Icehouse Over IPv6Shixiong Shang
 
IPV6 - Threats and Countermeasures / Crash Course
IPV6 - Threats and Countermeasures / Crash CourseIPV6 - Threats and Countermeasures / Crash Course
IPV6 - Threats and Countermeasures / Crash CourseThierry Zoller
 
Henrik Strøm - IPv6 from the attacker's perspective
Henrik Strøm - IPv6 from the attacker's perspectiveHenrik Strøm - IPv6 from the attacker's perspective
Henrik Strøm - IPv6 from the attacker's perspectiveIKT-Norge
 
RIPE 70 Report Webinar
RIPE 70 Report WebinarRIPE 70 Report Webinar
RIPE 70 Report WebinarMen and Mice
 
OpenStack Havana over IPv6
OpenStack Havana over IPv6OpenStack Havana over IPv6
OpenStack Havana over IPv6Shixiong Shang
 
Eric Vyncke - Layer-2 security, ipv6 norway
Eric Vyncke - Layer-2 security, ipv6 norwayEric Vyncke - Layer-2 security, ipv6 norway
Eric Vyncke - Layer-2 security, ipv6 norwayIKT-Norge
 
Addressing DHCP and DNS scalability issues in OpenStack Neutron
Addressing DHCP and DNS scalability issues in OpenStack NeutronAddressing DHCP and DNS scalability issues in OpenStack Neutron
Addressing DHCP and DNS scalability issues in OpenStack NeutronVikram G Hosakote
 
PLNOG15: Practical deployments of Kea, a high performance scalable DHCP - Tom...
PLNOG15: Practical deployments of Kea, a high performance scalable DHCP - Tom...PLNOG15: Practical deployments of Kea, a high performance scalable DHCP - Tom...
PLNOG15: Practical deployments of Kea, a high performance scalable DHCP - Tom...PROIDEA
 
Rapid IPv6 Deployment for ISP Networks
Rapid IPv6 Deployment for ISP NetworksRapid IPv6 Deployment for ISP Networks
Rapid IPv6 Deployment for ISP NetworksSkeeve Stevens
 
Using PerfDHCP tool to scale DHCP in OpenStack Neutron
Using PerfDHCP tool to scale DHCP in OpenStack NeutronUsing PerfDHCP tool to scale DHCP in OpenStack Neutron
Using PerfDHCP tool to scale DHCP in OpenStack NeutronVikram G Hosakote
 
FreeSWITCH on Docker
FreeSWITCH on DockerFreeSWITCH on Docker
FreeSWITCH on Docker建澄 吳
 
OpenStack Neutron IPv6 Lessons
OpenStack Neutron IPv6 LessonsOpenStack Neutron IPv6 Lessons
OpenStack Neutron IPv6 LessonsAkihiro Motoki
 
Badge Poser v3.0 - A DevOps Journey
Badge Poser v3.0 - A DevOps JourneyBadge Poser v3.0 - A DevOps Journey
Badge Poser v3.0 - A DevOps JourneyFabio Cicerchia
 

Was ist angesagt? (20)

PLNOG 18 - Paweł Małachowski - Spy hard czyli regexpem po pakietach
PLNOG 18 - Paweł Małachowski - Spy hard czyli regexpem po pakietachPLNOG 18 - Paweł Małachowski - Spy hard czyli regexpem po pakietach
PLNOG 18 - Paweł Małachowski - Spy hard czyli regexpem po pakietach
 
MAGPI: Advanced Services: IPv6, Multicast, DNSSEC
MAGPI: Advanced Services: IPv6, Multicast, DNSSECMAGPI: Advanced Services: IPv6, Multicast, DNSSEC
MAGPI: Advanced Services: IPv6, Multicast, DNSSEC
 
Oracle Sandbox
Oracle SandboxOracle Sandbox
Oracle Sandbox
 
Ipv6
Ipv6Ipv6
Ipv6
 
IPv6 strategy for deployment at ETH Switzerland
IPv6 strategy for deployment at ETH SwitzerlandIPv6 strategy for deployment at ETH Switzerland
IPv6 strategy for deployment at ETH Switzerland
 
OpenStack Icehouse Over IPv6
OpenStack Icehouse Over IPv6OpenStack Icehouse Over IPv6
OpenStack Icehouse Over IPv6
 
IPV6 - Threats and Countermeasures / Crash Course
IPV6 - Threats and Countermeasures / Crash CourseIPV6 - Threats and Countermeasures / Crash Course
IPV6 - Threats and Countermeasures / Crash Course
 
Henrik Strøm - IPv6 from the attacker's perspective
Henrik Strøm - IPv6 from the attacker's perspectiveHenrik Strøm - IPv6 from the attacker's perspective
Henrik Strøm - IPv6 from the attacker's perspective
 
RIPE 70 Report Webinar
RIPE 70 Report WebinarRIPE 70 Report Webinar
RIPE 70 Report Webinar
 
OpenStack Havana over IPv6
OpenStack Havana over IPv6OpenStack Havana over IPv6
OpenStack Havana over IPv6
 
Eric Vyncke - Layer-2 security, ipv6 norway
Eric Vyncke - Layer-2 security, ipv6 norwayEric Vyncke - Layer-2 security, ipv6 norway
Eric Vyncke - Layer-2 security, ipv6 norway
 
Addressing DHCP and DNS scalability issues in OpenStack Neutron
Addressing DHCP and DNS scalability issues in OpenStack NeutronAddressing DHCP and DNS scalability issues in OpenStack Neutron
Addressing DHCP and DNS scalability issues in OpenStack Neutron
 
pps Matters
pps Matterspps Matters
pps Matters
 
PLNOG15: Practical deployments of Kea, a high performance scalable DHCP - Tom...
PLNOG15: Practical deployments of Kea, a high performance scalable DHCP - Tom...PLNOG15: Practical deployments of Kea, a high performance scalable DHCP - Tom...
PLNOG15: Practical deployments of Kea, a high performance scalable DHCP - Tom...
 
Rapid IPv6 Deployment for ISP Networks
Rapid IPv6 Deployment for ISP NetworksRapid IPv6 Deployment for ISP Networks
Rapid IPv6 Deployment for ISP Networks
 
Using PerfDHCP tool to scale DHCP in OpenStack Neutron
Using PerfDHCP tool to scale DHCP in OpenStack NeutronUsing PerfDHCP tool to scale DHCP in OpenStack Neutron
Using PerfDHCP tool to scale DHCP in OpenStack Neutron
 
FreeSWITCH on Docker
FreeSWITCH on DockerFreeSWITCH on Docker
FreeSWITCH on Docker
 
Multicast in OpenStack
Multicast in OpenStackMulticast in OpenStack
Multicast in OpenStack
 
OpenStack Neutron IPv6 Lessons
OpenStack Neutron IPv6 LessonsOpenStack Neutron IPv6 Lessons
OpenStack Neutron IPv6 Lessons
 
Badge Poser v3.0 - A DevOps Journey
Badge Poser v3.0 - A DevOps JourneyBadge Poser v3.0 - A DevOps Journey
Badge Poser v3.0 - A DevOps Journey
 

Ähnlich wie IPv6 Transition Planning Guide

APNIC Update
APNIC Update APNIC Update
APNIC Update APNIC
 
Microsoft IT's IPv6 Killer App
Microsoft IT's IPv6 Killer AppMicrosoft IT's IPv6 Killer App
Microsoft IT's IPv6 Killer AppOliver Müller
 
ARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities ReportARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities ReportARIN
 
ietf-115-hackathon-srv6-dataplane-visibility.pptx
ietf-115-hackathon-srv6-dataplane-visibility.pptxietf-115-hackathon-srv6-dataplane-visibility.pptx
ietf-115-hackathon-srv6-dataplane-visibility.pptxThomasGraf40
 
Swiss IPv6 Council: Konfusion um die Router Flags
Swiss IPv6 Council: Konfusion um die Router FlagsSwiss IPv6 Council: Konfusion um die Router Flags
Swiss IPv6 Council: Konfusion um die Router FlagsDigicomp Academy AG
 
Update on IPv6 activity in CERNET2
Update on IPv6 activity in CERNET2Update on IPv6 activity in CERNET2
Update on IPv6 activity in CERNET2APNIC
 
Tutorial: IPv6-only transition with demo
Tutorial: IPv6-only transition with demoTutorial: IPv6-only transition with demo
Tutorial: IPv6-only transition with demoAPNIC
 
Getting started with IPv6
Getting started with IPv6Getting started with IPv6
Getting started with IPv6Private
 
ARIN 34 IPv6 IAB/IETF Activities Report
ARIN 34 IPv6 IAB/IETF Activities ReportARIN 34 IPv6 IAB/IETF Activities Report
ARIN 34 IPv6 IAB/IETF Activities ReportARIN
 
IPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-onIPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-onAPNIC
 
AIDevWorldApacheNiFi101
AIDevWorldApacheNiFi101AIDevWorldApacheNiFi101
AIDevWorldApacheNiFi101Timothy Spann
 
Ipv6 tutorial
Ipv6 tutorialIpv6 tutorial
Ipv6 tutorialsaryu2011
 
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn FortinetDigicomp Academy AG
 
Successes and Challenges of IPv6 Transition at APNIC
Successes and Challenges of IPv6 Transition at APNICSuccesses and Challenges of IPv6 Transition at APNIC
Successes and Challenges of IPv6 Transition at APNICAPNIC
 
Successfully Deploying IPv6
Successfully Deploying IPv6Successfully Deploying IPv6
Successfully Deploying IPv6Zivaro Inc
 

Ähnlich wie IPv6 Transition Planning Guide (20)

APNIC Update
APNIC Update APNIC Update
APNIC Update
 
IPv6 on the Interop Network
IPv6 on the Interop NetworkIPv6 on the Interop Network
IPv6 on the Interop Network
 
Microsoft IT's IPv6 Killer App
Microsoft IT's IPv6 Killer AppMicrosoft IT's IPv6 Killer App
Microsoft IT's IPv6 Killer App
 
ARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities ReportARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities Report
 
ietf-115-hackathon-srv6-dataplane-visibility.pptx
ietf-115-hackathon-srv6-dataplane-visibility.pptxietf-115-hackathon-srv6-dataplane-visibility.pptx
ietf-115-hackathon-srv6-dataplane-visibility.pptx
 
Swiss IPv6 Council: Konfusion um die Router Flags
Swiss IPv6 Council: Konfusion um die Router FlagsSwiss IPv6 Council: Konfusion um die Router Flags
Swiss IPv6 Council: Konfusion um die Router Flags
 
Neutron IPv6
Neutron IPv6Neutron IPv6
Neutron IPv6
 
IPv6 training guide - Yuval Shaul
IPv6 training guide - Yuval ShaulIPv6 training guide - Yuval Shaul
IPv6 training guide - Yuval Shaul
 
Update on IPv6 activity in CERNET2
Update on IPv6 activity in CERNET2Update on IPv6 activity in CERNET2
Update on IPv6 activity in CERNET2
 
Tutorial: IPv6-only transition with demo
Tutorial: IPv6-only transition with demoTutorial: IPv6-only transition with demo
Tutorial: IPv6-only transition with demo
 
Getting started with IPv6
Getting started with IPv6Getting started with IPv6
Getting started with IPv6
 
ARIN 34 IPv6 IAB/IETF Activities Report
ARIN 34 IPv6 IAB/IETF Activities ReportARIN 34 IPv6 IAB/IETF Activities Report
ARIN 34 IPv6 IAB/IETF Activities Report
 
IPv6 Can No Longer Be Ignored
IPv6 Can No Longer Be IgnoredIPv6 Can No Longer Be Ignored
IPv6 Can No Longer Be Ignored
 
IPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-onIPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-on
 
AIDevWorldApacheNiFi101
AIDevWorldApacheNiFi101AIDevWorldApacheNiFi101
AIDevWorldApacheNiFi101
 
Ipv6 tutorial
Ipv6 tutorialIpv6 tutorial
Ipv6 tutorial
 
Ipv6 tutorial
Ipv6 tutorialIpv6 tutorial
Ipv6 tutorial
 
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
 
Successes and Challenges of IPv6 Transition at APNIC
Successes and Challenges of IPv6 Transition at APNICSuccesses and Challenges of IPv6 Transition at APNIC
Successes and Challenges of IPv6 Transition at APNIC
 
Successfully Deploying IPv6
Successfully Deploying IPv6Successfully Deploying IPv6
Successfully Deploying IPv6
 

Mehr von Eduardo Coelho

Dual stack IPv4 / IPv6 Security Issues - A simple proof of concept
Dual stack IPv4 / IPv6 Security Issues - A simple proof of conceptDual stack IPv4 / IPv6 Security Issues - A simple proof of concept
Dual stack IPv4 / IPv6 Security Issues - A simple proof of conceptEduardo Coelho
 
2013 09-21 e-learning, moodle and opensource - what do i have to do with it
2013 09-21 e-learning, moodle and opensource - what do i have to do with it 2013 09-21 e-learning, moodle and opensource - what do i have to do with it
2013 09-21 e-learning, moodle and opensource - what do i have to do with it Eduardo Coelho
 
Speaking - cloud computing and the sysop professional - how to get ready
Speaking - cloud computing and the sysop professional - how to get readySpeaking - cloud computing and the sysop professional - how to get ready
Speaking - cloud computing and the sysop professional - how to get readyEduardo Coelho
 
2012 07-05 eduardo coelho - revolução tecnológica - a influencia dos jogos
2012 07-05 eduardo coelho - revolução tecnológica - a influencia dos jogos2012 07-05 eduardo coelho - revolução tecnológica - a influencia dos jogos
2012 07-05 eduardo coelho - revolução tecnológica - a influencia dos jogosEduardo Coelho
 
2012 06-27 imersão academia de redes itcursos
2012 06-27 imersão academia de redes itcursos2012 06-27 imersão academia de redes itcursos
2012 06-27 imersão academia de redes itcursosEduardo Coelho
 
2012 06-05 porque voce precisa ser fera em linux.pdf
2012 06-05 porque voce precisa ser fera em linux.pdf2012 06-05 porque voce precisa ser fera em linux.pdf
2012 06-05 porque voce precisa ser fera em linux.pdfEduardo Coelho
 
2011 11-05 csi - valores pessoais
2011 11-05 csi - valores pessoais2011 11-05 csi - valores pessoais
2011 11-05 csi - valores pessoaisEduardo Coelho
 
2011 09-22 responsabilidade social, o profissional e a empresa.pdf
2011 09-22 responsabilidade social, o profissional e a empresa.pdf2011 09-22 responsabilidade social, o profissional e a empresa.pdf
2011 09-22 responsabilidade social, o profissional e a empresa.pdfEduardo Coelho
 
2011 04-26 estacio fcc - palestra cloud computing para o profissional de ti
2011 04-26 estacio fcc - palestra cloud computing para o profissional de ti2011 04-26 estacio fcc - palestra cloud computing para o profissional de ti
2011 04-26 estacio fcc - palestra cloud computing para o profissional de tiEduardo Coelho
 
2010 10-16 workshop gestão de projetos 2010 - palestra gestão de tempo de g...
2010 10-16 workshop gestão de projetos 2010 - palestra gestão de tempo de g...2010 10-16 workshop gestão de projetos 2010 - palestra gestão de tempo de g...
2010 10-16 workshop gestão de projetos 2010 - palestra gestão de tempo de g...Eduardo Coelho
 
2010 09-22 infra rn security meeting - palestra firewalls opensource
2010 09-22 infra rn security meeting - palestra firewalls opensource2010 09-22 infra rn security meeting - palestra firewalls opensource
2010 09-22 infra rn security meeting - palestra firewalls opensourceEduardo Coelho
 
2010 09-17 farn sistemas de informação 6o periodo - palestra e-commerce
2010 09-17 farn sistemas de informação 6o periodo - palestra e-commerce2010 09-17 farn sistemas de informação 6o periodo - palestra e-commerce
2010 09-17 farn sistemas de informação 6o periodo - palestra e-commerceEduardo Coelho
 

Mehr von Eduardo Coelho (13)

Dual stack IPv4 / IPv6 Security Issues - A simple proof of concept
Dual stack IPv4 / IPv6 Security Issues - A simple proof of conceptDual stack IPv4 / IPv6 Security Issues - A simple proof of concept
Dual stack IPv4 / IPv6 Security Issues - A simple proof of concept
 
2013 09-21 e-learning, moodle and opensource - what do i have to do with it
2013 09-21 e-learning, moodle and opensource - what do i have to do with it 2013 09-21 e-learning, moodle and opensource - what do i have to do with it
2013 09-21 e-learning, moodle and opensource - what do i have to do with it
 
Speaking - cloud computing and the sysop professional - how to get ready
Speaking - cloud computing and the sysop professional - how to get readySpeaking - cloud computing and the sysop professional - how to get ready
Speaking - cloud computing and the sysop professional - how to get ready
 
2012 07-05 eduardo coelho - revolução tecnológica - a influencia dos jogos
2012 07-05 eduardo coelho - revolução tecnológica - a influencia dos jogos2012 07-05 eduardo coelho - revolução tecnológica - a influencia dos jogos
2012 07-05 eduardo coelho - revolução tecnológica - a influencia dos jogos
 
2012 06-27 imersão academia de redes itcursos
2012 06-27 imersão academia de redes itcursos2012 06-27 imersão academia de redes itcursos
2012 06-27 imersão academia de redes itcursos
 
2012 06-05 porque voce precisa ser fera em linux.pdf
2012 06-05 porque voce precisa ser fera em linux.pdf2012 06-05 porque voce precisa ser fera em linux.pdf
2012 06-05 porque voce precisa ser fera em linux.pdf
 
2011 11-05 csi - valores pessoais
2011 11-05 csi - valores pessoais2011 11-05 csi - valores pessoais
2011 11-05 csi - valores pessoais
 
2011 09-22 responsabilidade social, o profissional e a empresa.pdf
2011 09-22 responsabilidade social, o profissional e a empresa.pdf2011 09-22 responsabilidade social, o profissional e a empresa.pdf
2011 09-22 responsabilidade social, o profissional e a empresa.pdf
 
2011 04-26 estacio fcc - palestra cloud computing para o profissional de ti
2011 04-26 estacio fcc - palestra cloud computing para o profissional de ti2011 04-26 estacio fcc - palestra cloud computing para o profissional de ti
2011 04-26 estacio fcc - palestra cloud computing para o profissional de ti
 
2010 10-16 workshop gestão de projetos 2010 - palestra gestão de tempo de g...
2010 10-16 workshop gestão de projetos 2010 - palestra gestão de tempo de g...2010 10-16 workshop gestão de projetos 2010 - palestra gestão de tempo de g...
2010 10-16 workshop gestão de projetos 2010 - palestra gestão de tempo de g...
 
2010 09-22 infra rn security meeting - palestra firewalls opensource
2010 09-22 infra rn security meeting - palestra firewalls opensource2010 09-22 infra rn security meeting - palestra firewalls opensource
2010 09-22 infra rn security meeting - palestra firewalls opensource
 
2010 09-17 farn sistemas de informação 6o periodo - palestra e-commerce
2010 09-17 farn sistemas de informação 6o periodo - palestra e-commerce2010 09-17 farn sistemas de informação 6o periodo - palestra e-commerce
2010 09-17 farn sistemas de informação 6o periodo - palestra e-commerce
 
Firewalls Opensource
Firewalls OpensourceFirewalls Opensource
Firewalls Opensource
 

IPv6 Transition Planning Guide

  • 1. IPV6 an introduction to transition planning Eduardo Coelho http://coelho.pro.br
  • 2. TOPICS (1) • why you have to plan before the deployment • the framework • whats wrong with ipv4? • dual stack deployment strategy • router advertisements and the plug-and-play philosophy • choosing the equipments
  • 3. TOPICS (2) • IPv6 addressing • DNS settings delivery issues • legacy devices • transition protocols • security concerns • final suggestions
  • 4. WHY YOU HAVE TO PLAN BEFORE THE DEPLOYMENT • acceptplanning as part of IT culture as it should always have been (ps: if you`re already there, great!) • your planning can act as a decision-making tool • including be ready to defend investment choices • documenting helps delegate and check compliance • feel you are on top of the changing environment
  • 5. THE FRAMEWORK •a simple framework for the changes • get to know (conheça) • plan (planeje) • test (teste) • implement (implemente)
  • 6. WHAT’S WRONG WITH IPV4 • lack of enough host addresses • NAT issues and lack of end-to-end connectivity • note: you should pay attention to the opportunities that comes with ipv6 deploy
  • 7. DUAL STACK DEPLOYMENT PHILOSOPHY • ipv4 is not compatible with ipv6 • thedeployment of ipv6 is meant to be made world-wide in parallel to already functioning ipv4 networks • while the traffic on internet and intranets shift to v6, transition protocols will help most equipment to remain connected
  • 8. THE PLUG-AND-PLAY PHILOSOPHY • plug-and-play as a principle • that makes ipv6 more plug-and-play • reduced router processing • better connectivity auto-healing • mobility is supported • multicast gains momentum
  • 9. CHOOSING THE EQUIPMENTS • be ready to update and test all your equipment • when buying new equipment, consider the updating capabilities and the manufacturer update policies • watch for JITC (Defense Information Systems Agency/Joint Interoperability Test Command) compatibility • watch for ipv6ready compatibility (an ipv6forum initiative) • pay special attention to routers
  • 10. IPV6 ADDRESSING • global unicast • link local • unique local • anycast, multicast, reserved and special
  • 11. DNS SETTINGS DELIVERY • llmnr • stateless dhcp6 vs dns-ra • watch for windows non-compliance to rfc6106 • naming is now more important than with ipv4, due to human difficulty manually handling ipv6 addresses
  • 12. LEGACY DEVICES • identify which devices wont be able to talk ipv4 • identify which devices wont be able to talk ipv6 • makechoices based on the need for devices which wont operate with dual ip stack
  • 13. TRANSITION PROTOCOLS (1) • there a lot of transitional protocols, including some drafts • be careful about equipment support • avoid transitional protocols when possible, due to security concerns (possible firewall traversal and datagram data obfuscation) • isps may offer dual stack connectivity or transparent tunneling
  • 14. TRANSITION PROTOCOLS (2) • recommended transitional protocols: • initial transition: 6to4 (auto), teredo (auto, ipv4 nat support) • intrasite, initial transition: isatap • final transition: 4in6 (manual, rfc2473) • othertunnels: 6in4 (manual, broker based), 6over4 (requires ipv4 multicast, hard to comply), nat64 (translation protocol)
  • 15. SECURITY CONCERNS • rogue routers • rogue dhcp servers • sniffing • spoofing • tunneling obfuscation
  • 16. FINAL SUGGESTIONS • carefully choose isp offering • define network-level addressing plan and enforce requirements • have a clear plan for naming and dhcp • consider deprecating ipv4-only devices • prefer dual-stack devices
  • 17. REFERENCES Unique Local Address Internet powers flip the IPv6 switch http://en.wikipedia.org/wiki/ (FAQ) Comparison of IPv6 support in Unique_local_address http://news.cnet.com/ operating systems 8301-1001_3-57445316-92/internet- http://en.wikipedia.org/wiki/ Unique Local Unicast Addresses powers-flip-the-ipv6-switch-faq/ Comparison_of_IPv6_support_in_oper http://tools.ietf.org/html/rfc4193 ating_systems IPv6-capable devices: Make sure they Deprecating Site Local Addresses are ready Internet Protocol Version 6 Address http://tools.ietf.org/rfc/rfc3879.txt http://www.techrepublic.com/blog/ Space networking/ipv6-capable-devices- http://www.iana.org/assignments/ipv6- IPv6 Support in Home Routers make-sure-they-are-ready/2522 address-space/ipv6-address-space.xml http://msdn.microsoft.com/en-us/ library/windows/hardware/ IPv6 Ready Logo Program Router Advertisement (radvd) gg463251.aspx https://www.ipv6ready.org configuration http://wiki.openwrt.org/doc/uci/radvd Prefix delegation IPv6: When do you really need to http://en.wikipedia.org/wiki/ switch? Does Win7 or W2K8 server support Prefix_delegation http://www.zdnet.com/blog/networking/ RFC 6106? ipv6-when-do-you-really-need-to- http://social.technet.microsoft.com/ Requirements for IPv6 Prefix switch/2444 Forums/en-US/ipv6/thread/ Delegation 5757980a-5983-4efc- http://tools.ietf.org/html/rfc3769 Portal IPv6 NIC.br a5f3-27687b90fe41/ http://ipv6.br IPv6 Prefix Options for DHCP version 6 Delivering DNS via IPv6 Router http://www.ietf.org/rfc/rfc3633.txt IPv6 http://www.itdojo.com/2011/05/02/ http://en.wikipedia.org/wiki/IPv6 delivering-dns-via-ipv6-router- IP Version 6 Addressing Architecture advertisements/ http://tools.ietf.org/html/rfc4291 IPv6 transition mechanisms http://en.wikipedia.org/wiki/ IPv6_transition_mechanisms