SlideShare ist ein Scribd-Unternehmen logo
1 von 40
NAT64
Demonstration Deployment
RMv6TF 2013
Demo network was available during the live
presentation
Notes have been added to slides 30-32 to clarify FTP
issues.
1Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only
Agenda
• Introduction
• Problem Statement
• NAT64 Concepts
• Demo Setup
• NAT64 Experience
• Conclusion
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 2
Core Values and Beliefs
Network Utility Force believes that, above and beyond our
experience, it’s our values that drive our success in both
business and life. As such, NUF has adopted a system of Core
Values & Beliefs that we live by:
• We respect the individual, and believe that individuals who are treated with respect and given responsibility
respond by giving their best.
• We require complete honesty and integrity in everything we do.
• We make commitments with care, and then live up to them. In all things, we do what we say we are going to do.
• Work is an important part of life, and it should be fun. Being a good business person does not mean being stuffy
and boring.
• We are frugal. We guard and conserve the company's resources with at least the same vigilance that we would use
to guard and conserve our own personal resources.
• We insist on giving our best effort in everything we undertake.
• Furthermore, we see a huge difference between "good mistakes" (best effort, bad result) and "bad mistakes"
(sloppiness or lack of effort).
• Clarity in understanding our mission, our goals, and what we expect from each other is critical to our success.
• We are believers in the Golden Rule. In all our dealings we will strive to be friendly and courteous, as well as fair
and compassionate.
• We feel a sense of urgency on any matters related to our customers. We own problems and we are always
responsive. We are customer driven.
Permission to use these values granted by their creator, Charles Brewer of MindSpring.
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 3
INTRODUCTION
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 4
NUF Tenets
• Our reputation is EVERYTHING, without it, we are
worthless
– We will ALWAYS advise our clients on what we believe
is the right answer for them without exception
• Vendor neutral – The right tool for the right job
– Cisco, Juniper, Brocade, HP, Huawei, A10, Dell
(Force10), Extreme, Vyatta, ADVA, Arista, Alcatel, etc.,
etc
• No hardware sales, 100% professional services
• No geographical boundaries, we go where we are
needed
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 5
Who is NUF?
• Founded in December of 2011
• 6 principal consultants/owners
• Numerous specialist contractors
• Example experience
– Recently highlighted by local news for deployment of
community wifi network sponsored by Google
– Consulting for Ethiopia TLD
– Netrail, MindSpring, Comcast, Internap, numerous small
service providers
– ARIN, NANOG, IETF participation
• IPv6 training, architecture, deployment and address
management
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 6
Overview
Leader in Application
Networking Profitable with
consistent growth
Founded Q4/2004
Lee Chen, Founder of
Foundry & Centillion
Networks
Flagship Product
AX Series Platform
500+ employees
Customers in over 35 countries
PROBLEM STATEMENT
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net ©
2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 8
Problem Statement
I have run out of IPv4 addresses and need to
find a way to provide Internet access to my
clients. My core network supports IPv6, but
there are many IPv4-only resources my clients
need to reach. I want to go with IPv6 because I
want to future-proof my internal network,
however I understand I need connectivity to
IPv4 resources for quite some time.
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 9
IPv4 Exhaustion and IPv6
Migration Solutions
• No standard
compatibility
• Different
requirements
– Home
– Enterprise
– Service
Provider
• “IPv4 Legacy
Networks”
Transition Mechanisms
• Dual Stack – All network links and hosts have
both IPv4 and IPv6 addressing, all traffic is
native to its protocol
• Dual Stack – Lite (DS-Lite) – Allow distribution
network (including CPE) to have ONLY IPv6
addressing.
• NAT64 – Translate IPv6 into IPv4 and vice
versa.
• 6rd – Carry IPv6 across an IPv4-only network.
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 11
Protocol Translations
• May prefer to use IPv6-IPv4 protocol translation for:
– new kinds of Internet devices (e.g., cell phones, cars, appliances)
– benefits of shedding IPv4 stack (e.g., serverless autoconfig)
• Simple extension to NAT techniques, to translate header
format as well as addresses
– IPv6 nodes behind a translator get full IPv6 functionality when talking to
other IPv6 nodes located anywhere
– Get the normal (i.e., degraded) NAT functionality when talking to IPv4
devices
– Drawback : minimal gain over IPv4/IPv4 NAT approach
– Drawback : no support for legacy IPv4-only devices
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 12
NAT64 CONCEPTS
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 13
NAT64 and DNS64
• Provides stateful translation between IPv6 and IPv4
traffic when that traffic is initiated by an IPv6-only
node
– NAT64 translates IPv6 and IPv4 traffic
– DNS64 maps IPv6-only address record (AAAA) DNS queries
to IPv4 address record (A) queries
• Makes it possible for IPv6-only nodes to initiate
communications with IPv4-only nodes with no
changes to the IPv6-only node and the IPv4-only
node
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 14
NAT64
• No host or CPE support necessary
• No IPv4 address at all required on the CPE or
host to access IPv4 resources (compare with
DS-Lite which requires RFC1918 addresses)
• Host gets only an IPv6 address
• NAT44 issues for IPv4 traffic still apply
including session start from behind the NAT to
establish state and ALGs are necessary for
many protocols
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 15
NAT64 cont’d
• Workstation (which has only IPv6) requests communication
with a IPv4-only site (www.example.com)
– It asks for a AAAA record since it is IPv6 only
• DNS server (DNS64) first tries a AAAA query. If one exists, it
is passed to the client and the client communicates with
the site via IPv6. If no AAAA record exists, the DNS64
functionality will translate an A record into a AAAA.
– To translate, the DNS64 server must know the prefix in use in
the network for NAT64
• Can be assigned by administrator
• Can use well-known prefix 64:ff9b::/96
– When using a /96, simply concatenate the IPv4 address on the
end (more complex rules available for shorter prefixes, see
RFC6052)
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 16
NAT64 cont’d
• The workstation, having received a AAAA for
www.example.com initiates a TCP session with that
IPv6 address
• The NAT64 device has the IPv6 prefix just discussed
routed to it (could be OSPF, BGP, etc.)
• The NAT64 device recognizes that this address is an
encapsulated IPv4 address
– Adds NAT state if necessary
– Strips the prefix to find the IPv4 destination address
– Translates other parts of the header
– Sends packet to IPv4 host using a source IPv4 address from
a local pool
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 17
DEMO SETUP
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 18
Demo Topology
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net ©
2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 19
Wifi
Network
SSID:
Nat64NUF
A10 AX3530
NAT64
DNS64
RMv6TF
Network
Unix server
DHCPv6
2001:428:3804:64::/64
No IPv4
2001:428:3804::/64
10.2.0.70 (upstream
NAT 63.156.186.246)
A10 Config Bits
Inside config
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net ©
2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 20
Configure NAT pools
Configure NAT using the well-known prefix
A10 Config Bits
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 21
Demo Setup
Join the network using SSID: Nat64NUF
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 22
NAT64 EXPERIENCE
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 23
What works?
• Nearly everything
– A10’s implementation was solid, no signs of bugs
or performance problems
– Operating systems: Windows, MacOS, Linux
– Nearly all classic IP protocols:
POP, IMAP, SSH, Telnet, Standard web stuff, SMTP
– Many chat protocols: Google talk, FaceBook chat
– Entertainment: Pandora web
client, Netflix, YouTube, Hulu
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 24
IOS is Weird
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 25
We appear to be connected
IOS is Weird
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 26
Seems to be stuck in the process of connecting…
IOS is Weird
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net ©
2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 27
But look, it worked!
Whois broken??
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net ©
2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 28
Whois
• A few whois attempts later, everything was
working
• Does it depend on if the AAAA or A record
comes back first?
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 29
FTP before ALG
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 30
FTP with ALG, Outside
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 31
FTP with ALG, Inside
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net ©
2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 32
What doesn’t work?
• All Android based devices we tried did not
function
– We suspect that Android performs an IPv4
connectivity specific test and reject networks that
doesn’t have IPv4
– We also suspect that Android will not consider
DNS over IPv6 transport
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 33
AOL Instant Messenger
Won’t connect to the server, why?
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 34
Skype
Also won’t connect to the Skype network
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net ©
2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 35
CONCLUSION
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net ©
2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 36
NAT64 is good
• Works for most apps
• Most of the non-working apps seem
reasonably fixable
• Very good vendor support from A10
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 37
Thanks!!
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 38
Q and A
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012,
Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 39
Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013,
Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 40
Download the presentation here:
Brandon Ross – Chief Network Architect – Network Utility Force – bross@netuf.net
Erik Muller – Network Architect – Network Utility Force – em@netuf.net
René Paap - Technical Marketing Engineer – A10 network – rpaap@a10networks.com

Weitere ähnliche Inhalte

Ähnlich wie Network Utility Force IPv6 NAT64 Presentation for North American IPv6 Summit

12 steps for IPv6 Deployment in Governments and Enterprises
12 steps for IPv6 Deployment in Governments and Enterprises12 steps for IPv6 Deployment in Governments and Enterprises
12 steps for IPv6 Deployment in Governments and EnterprisesAPNIC
 
Cloud-Scale BGP and NetFlow Analysis
Cloud-Scale BGP and NetFlow AnalysisCloud-Scale BGP and NetFlow Analysis
Cloud-Scale BGP and NetFlow AnalysisAlex Henthorn-Iwane
 
Fast Data Overview
Fast Data OverviewFast Data Overview
Fast Data OverviewC. Scyphers
 
How Verizon Uses Disruptive Developments for Organized Progress
How Verizon Uses Disruptive Developments for Organized ProgressHow Verizon Uses Disruptive Developments for Organized Progress
How Verizon Uses Disruptive Developments for Organized ProgressMongoDB
 
SD-WAN & Hybrid-WAN Solutions for CSPs
SD-WAN & Hybrid-WAN Solutions for CSPsSD-WAN & Hybrid-WAN Solutions for CSPs
SD-WAN & Hybrid-WAN Solutions for CSPsRicky Pierson
 
Oracle Openworld Presentation with Paul Kent (SAS) on Big Data Appliance and ...
Oracle Openworld Presentation with Paul Kent (SAS) on Big Data Appliance and ...Oracle Openworld Presentation with Paul Kent (SAS) on Big Data Appliance and ...
Oracle Openworld Presentation with Paul Kent (SAS) on Big Data Appliance and ...jdijcks
 
Yahoo: Experiences with Percona Cluster
Yahoo: Experiences with Percona ClusterYahoo: Experiences with Percona Cluster
Yahoo: Experiences with Percona ClusterYashada Jadhav
 
MatterPoint Overview
MatterPoint OverviewMatterPoint Overview
MatterPoint OverviewBob Rivas
 
TienNguyen_Resume
TienNguyen_ResumeTienNguyen_Resume
TienNguyen_ResumeTien Nguyen
 
Sagar Datta_Resume
Sagar Datta_ResumeSagar Datta_Resume
Sagar Datta_Resumesagar datta
 
Fast Online Access to Massive Offline Data - SECR 2016
Fast Online Access to Massive Offline Data - SECR 2016Fast Online Access to Massive Offline Data - SECR 2016
Fast Online Access to Massive Offline Data - SECR 2016Felix GV
 
DataCommPresents-SecurNOC.ppt
DataCommPresents-SecurNOC.pptDataCommPresents-SecurNOC.ppt
DataCommPresents-SecurNOC.pptJimmyLim71
 
PLNOG 6: Jan Larsson - The History and Future of IPv6
PLNOG 6: Jan Larsson - The History and Future of IPv6PLNOG 6: Jan Larsson - The History and Future of IPv6
PLNOG 6: Jan Larsson - The History and Future of IPv6PROIDEA
 
ARM 7: TOT IPv6 Deployment Experiences
ARM 7: TOT IPv6 Deployment ExperiencesARM 7: TOT IPv6 Deployment Experiences
ARM 7: TOT IPv6 Deployment ExperiencesAPNIC
 
Fast Data Overview for Data Science Maryland Meetup
Fast Data Overview for Data Science Maryland MeetupFast Data Overview for Data Science Maryland Meetup
Fast Data Overview for Data Science Maryland MeetupC. Scyphers
 
Advanced SQL - Quebec 2014
Advanced SQL - Quebec 2014Advanced SQL - Quebec 2014
Advanced SQL - Quebec 2014Connor McDonald
 
Быстрый онлайн-доступ к огромному количеству оффлайн-данных в LinkedIn
Быстрый онлайн-доступ к огромному количеству оффлайн-данных в LinkedInБыстрый онлайн-доступ к огромному количеству оффлайн-данных в LinkedIn
Быстрый онлайн-доступ к огромному количеству оффлайн-данных в LinkedInCEE-SEC(R)
 
IPv6 Deployment: Why and Why not? - HostingCon 2013
IPv6 Deployment: Why and Why not? - HostingCon 2013IPv6 Deployment: Why and Why not? - HostingCon 2013
IPv6 Deployment: Why and Why not? - HostingCon 2013APNIC
 
Network Analysis & Design
Network Analysis & DesignNetwork Analysis & Design
Network Analysis & DesignErmanHamid3
 

Ähnlich wie Network Utility Force IPv6 NAT64 Presentation for North American IPv6 Summit (20)

12 steps for IPv6 Deployment in Governments and Enterprises
12 steps for IPv6 Deployment in Governments and Enterprises12 steps for IPv6 Deployment in Governments and Enterprises
12 steps for IPv6 Deployment in Governments and Enterprises
 
Cloud-Scale BGP and NetFlow Analysis
Cloud-Scale BGP and NetFlow AnalysisCloud-Scale BGP and NetFlow Analysis
Cloud-Scale BGP and NetFlow Analysis
 
PACE-IT: Introducing_NAT - N10 006
PACE-IT: Introducing_NAT - N10 006 PACE-IT: Introducing_NAT - N10 006
PACE-IT: Introducing_NAT - N10 006
 
Fast Data Overview
Fast Data OverviewFast Data Overview
Fast Data Overview
 
How Verizon Uses Disruptive Developments for Organized Progress
How Verizon Uses Disruptive Developments for Organized ProgressHow Verizon Uses Disruptive Developments for Organized Progress
How Verizon Uses Disruptive Developments for Organized Progress
 
SD-WAN & Hybrid-WAN Solutions for CSPs
SD-WAN & Hybrid-WAN Solutions for CSPsSD-WAN & Hybrid-WAN Solutions for CSPs
SD-WAN & Hybrid-WAN Solutions for CSPs
 
Oracle Openworld Presentation with Paul Kent (SAS) on Big Data Appliance and ...
Oracle Openworld Presentation with Paul Kent (SAS) on Big Data Appliance and ...Oracle Openworld Presentation with Paul Kent (SAS) on Big Data Appliance and ...
Oracle Openworld Presentation with Paul Kent (SAS) on Big Data Appliance and ...
 
Yahoo: Experiences with Percona Cluster
Yahoo: Experiences with Percona ClusterYahoo: Experiences with Percona Cluster
Yahoo: Experiences with Percona Cluster
 
MatterPoint Overview
MatterPoint OverviewMatterPoint Overview
MatterPoint Overview
 
TienNguyen_Resume
TienNguyen_ResumeTienNguyen_Resume
TienNguyen_Resume
 
Sagar Datta_Resume
Sagar Datta_ResumeSagar Datta_Resume
Sagar Datta_Resume
 
Fast Online Access to Massive Offline Data - SECR 2016
Fast Online Access to Massive Offline Data - SECR 2016Fast Online Access to Massive Offline Data - SECR 2016
Fast Online Access to Massive Offline Data - SECR 2016
 
DataCommPresents-SecurNOC.ppt
DataCommPresents-SecurNOC.pptDataCommPresents-SecurNOC.ppt
DataCommPresents-SecurNOC.ppt
 
PLNOG 6: Jan Larsson - The History and Future of IPv6
PLNOG 6: Jan Larsson - The History and Future of IPv6PLNOG 6: Jan Larsson - The History and Future of IPv6
PLNOG 6: Jan Larsson - The History and Future of IPv6
 
ARM 7: TOT IPv6 Deployment Experiences
ARM 7: TOT IPv6 Deployment ExperiencesARM 7: TOT IPv6 Deployment Experiences
ARM 7: TOT IPv6 Deployment Experiences
 
Fast Data Overview for Data Science Maryland Meetup
Fast Data Overview for Data Science Maryland MeetupFast Data Overview for Data Science Maryland Meetup
Fast Data Overview for Data Science Maryland Meetup
 
Advanced SQL - Quebec 2014
Advanced SQL - Quebec 2014Advanced SQL - Quebec 2014
Advanced SQL - Quebec 2014
 
Быстрый онлайн-доступ к огромному количеству оффлайн-данных в LinkedIn
Быстрый онлайн-доступ к огромному количеству оффлайн-данных в LinkedInБыстрый онлайн-доступ к огромному количеству оффлайн-данных в LinkedIn
Быстрый онлайн-доступ к огромному количеству оффлайн-данных в LinkedIn
 
IPv6 Deployment: Why and Why not? - HostingCon 2013
IPv6 Deployment: Why and Why not? - HostingCon 2013IPv6 Deployment: Why and Why not? - HostingCon 2013
IPv6 Deployment: Why and Why not? - HostingCon 2013
 
Network Analysis & Design
Network Analysis & DesignNetwork Analysis & Design
Network Analysis & Design
 

Mehr von Network Utility Force

IPv6 Technical Overview: Address Architecture, DHCPv6 and DNS
IPv6 Technical Overview: Address Architecture, DHCPv6 and DNSIPv6 Technical Overview: Address Architecture, DHCPv6 and DNS
IPv6 Technical Overview: Address Architecture, DHCPv6 and DNSNetwork Utility Force
 
How to Plan and Conduct IPv6 Field Trials
How to Plan and Conduct IPv6 Field TrialsHow to Plan and Conduct IPv6 Field Trials
How to Plan and Conduct IPv6 Field TrialsNetwork Utility Force
 
IPv6 Migration Infographic with IPv4 Exhaustion Timeline for 2014
IPv6 Migration Infographic with IPv4 Exhaustion Timeline for 2014IPv6 Migration Infographic with IPv4 Exhaustion Timeline for 2014
IPv6 Migration Infographic with IPv4 Exhaustion Timeline for 2014Network Utility Force
 
Roadmap to Next Generation IP Networks: A Review of the Fundamentals
Roadmap to Next Generation IP Networks: A Review of the FundamentalsRoadmap to Next Generation IP Networks: A Review of the Fundamentals
Roadmap to Next Generation IP Networks: A Review of the FundamentalsNetwork Utility Force
 
Network Utility Force IPv6 training brochure
Network Utility Force IPv6 training brochureNetwork Utility Force IPv6 training brochure
Network Utility Force IPv6 training brochureNetwork Utility Force
 

Mehr von Network Utility Force (9)

Outdoor Municipal WiFi Case Study
Outdoor Municipal WiFi Case StudyOutdoor Municipal WiFi Case Study
Outdoor Municipal WiFi Case Study
 
IPv6 Technical Overview: Address Architecture, DHCPv6 and DNS
IPv6 Technical Overview: Address Architecture, DHCPv6 and DNSIPv6 Technical Overview: Address Architecture, DHCPv6 and DNS
IPv6 Technical Overview: Address Architecture, DHCPv6 and DNS
 
How to Plan and Conduct IPv6 Field Trials
How to Plan and Conduct IPv6 Field TrialsHow to Plan and Conduct IPv6 Field Trials
How to Plan and Conduct IPv6 Field Trials
 
IPv6 Migration Infographic with IPv4 Exhaustion Timeline for 2014
IPv6 Migration Infographic with IPv4 Exhaustion Timeline for 2014IPv6 Migration Infographic with IPv4 Exhaustion Timeline for 2014
IPv6 Migration Infographic with IPv4 Exhaustion Timeline for 2014
 
Kinber ipv6-education-healthcare
Kinber ipv6-education-healthcareKinber ipv6-education-healthcare
Kinber ipv6-education-healthcare
 
IPv6 on the Interop Network
IPv6 on the Interop NetworkIPv6 on the Interop Network
IPv6 on the Interop Network
 
Roadmap to Next Generation IP Networks: A Review of the Fundamentals
Roadmap to Next Generation IP Networks: A Review of the FundamentalsRoadmap to Next Generation IP Networks: A Review of the Fundamentals
Roadmap to Next Generation IP Networks: A Review of the Fundamentals
 
Network Utility Force IPv6 training brochure
Network Utility Force IPv6 training brochureNetwork Utility Force IPv6 training brochure
Network Utility Force IPv6 training brochure
 
IPv6 Implementation and Migration
IPv6 Implementation and MigrationIPv6 Implementation and Migration
IPv6 Implementation and Migration
 

Kürzlich hochgeladen

IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Google AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAGGoogle AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAGSujit Pal
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxMalak Abu Hammad
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 

Kürzlich hochgeladen (20)

IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Google AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAGGoogle AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAG
 
The Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptxThe Codex of Business Writing Software for Real-World Solutions 2.pptx
The Codex of Business Writing Software for Real-World Solutions 2.pptx
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
#StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 

Network Utility Force IPv6 NAT64 Presentation for North American IPv6 Summit

  • 1. NAT64 Demonstration Deployment RMv6TF 2013 Demo network was available during the live presentation Notes have been added to slides 30-32 to clarify FTP issues. 1Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only
  • 2. Agenda • Introduction • Problem Statement • NAT64 Concepts • Demo Setup • NAT64 Experience • Conclusion Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 2
  • 3. Core Values and Beliefs Network Utility Force believes that, above and beyond our experience, it’s our values that drive our success in both business and life. As such, NUF has adopted a system of Core Values & Beliefs that we live by: • We respect the individual, and believe that individuals who are treated with respect and given responsibility respond by giving their best. • We require complete honesty and integrity in everything we do. • We make commitments with care, and then live up to them. In all things, we do what we say we are going to do. • Work is an important part of life, and it should be fun. Being a good business person does not mean being stuffy and boring. • We are frugal. We guard and conserve the company's resources with at least the same vigilance that we would use to guard and conserve our own personal resources. • We insist on giving our best effort in everything we undertake. • Furthermore, we see a huge difference between "good mistakes" (best effort, bad result) and "bad mistakes" (sloppiness or lack of effort). • Clarity in understanding our mission, our goals, and what we expect from each other is critical to our success. • We are believers in the Golden Rule. In all our dealings we will strive to be friendly and courteous, as well as fair and compassionate. • We feel a sense of urgency on any matters related to our customers. We own problems and we are always responsive. We are customer driven. Permission to use these values granted by their creator, Charles Brewer of MindSpring. Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 3
  • 4. INTRODUCTION Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 4
  • 5. NUF Tenets • Our reputation is EVERYTHING, without it, we are worthless – We will ALWAYS advise our clients on what we believe is the right answer for them without exception • Vendor neutral – The right tool for the right job – Cisco, Juniper, Brocade, HP, Huawei, A10, Dell (Force10), Extreme, Vyatta, ADVA, Arista, Alcatel, etc., etc • No hardware sales, 100% professional services • No geographical boundaries, we go where we are needed Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 5
  • 6. Who is NUF? • Founded in December of 2011 • 6 principal consultants/owners • Numerous specialist contractors • Example experience – Recently highlighted by local news for deployment of community wifi network sponsored by Google – Consulting for Ethiopia TLD – Netrail, MindSpring, Comcast, Internap, numerous small service providers – ARIN, NANOG, IETF participation • IPv6 training, architecture, deployment and address management Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 6
  • 7. Overview Leader in Application Networking Profitable with consistent growth Founded Q4/2004 Lee Chen, Founder of Foundry & Centillion Networks Flagship Product AX Series Platform 500+ employees Customers in over 35 countries
  • 8. PROBLEM STATEMENT Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 8
  • 9. Problem Statement I have run out of IPv4 addresses and need to find a way to provide Internet access to my clients. My core network supports IPv6, but there are many IPv4-only resources my clients need to reach. I want to go with IPv6 because I want to future-proof my internal network, however I understand I need connectivity to IPv4 resources for quite some time. Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 9
  • 10. IPv4 Exhaustion and IPv6 Migration Solutions • No standard compatibility • Different requirements – Home – Enterprise – Service Provider • “IPv4 Legacy Networks”
  • 11. Transition Mechanisms • Dual Stack – All network links and hosts have both IPv4 and IPv6 addressing, all traffic is native to its protocol • Dual Stack – Lite (DS-Lite) – Allow distribution network (including CPE) to have ONLY IPv6 addressing. • NAT64 – Translate IPv6 into IPv4 and vice versa. • 6rd – Carry IPv6 across an IPv4-only network. Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 11
  • 12. Protocol Translations • May prefer to use IPv6-IPv4 protocol translation for: – new kinds of Internet devices (e.g., cell phones, cars, appliances) – benefits of shedding IPv4 stack (e.g., serverless autoconfig) • Simple extension to NAT techniques, to translate header format as well as addresses – IPv6 nodes behind a translator get full IPv6 functionality when talking to other IPv6 nodes located anywhere – Get the normal (i.e., degraded) NAT functionality when talking to IPv4 devices – Drawback : minimal gain over IPv4/IPv4 NAT approach – Drawback : no support for legacy IPv4-only devices Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 12
  • 13. NAT64 CONCEPTS Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 13
  • 14. NAT64 and DNS64 • Provides stateful translation between IPv6 and IPv4 traffic when that traffic is initiated by an IPv6-only node – NAT64 translates IPv6 and IPv4 traffic – DNS64 maps IPv6-only address record (AAAA) DNS queries to IPv4 address record (A) queries • Makes it possible for IPv6-only nodes to initiate communications with IPv4-only nodes with no changes to the IPv6-only node and the IPv4-only node Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 14
  • 15. NAT64 • No host or CPE support necessary • No IPv4 address at all required on the CPE or host to access IPv4 resources (compare with DS-Lite which requires RFC1918 addresses) • Host gets only an IPv6 address • NAT44 issues for IPv4 traffic still apply including session start from behind the NAT to establish state and ALGs are necessary for many protocols Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 15
  • 16. NAT64 cont’d • Workstation (which has only IPv6) requests communication with a IPv4-only site (www.example.com) – It asks for a AAAA record since it is IPv6 only • DNS server (DNS64) first tries a AAAA query. If one exists, it is passed to the client and the client communicates with the site via IPv6. If no AAAA record exists, the DNS64 functionality will translate an A record into a AAAA. – To translate, the DNS64 server must know the prefix in use in the network for NAT64 • Can be assigned by administrator • Can use well-known prefix 64:ff9b::/96 – When using a /96, simply concatenate the IPv4 address on the end (more complex rules available for shorter prefixes, see RFC6052) Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 16
  • 17. NAT64 cont’d • The workstation, having received a AAAA for www.example.com initiates a TCP session with that IPv6 address • The NAT64 device has the IPv6 prefix just discussed routed to it (could be OSPF, BGP, etc.) • The NAT64 device recognizes that this address is an encapsulated IPv4 address – Adds NAT state if necessary – Strips the prefix to find the IPv4 destination address – Translates other parts of the header – Sends packet to IPv4 host using a source IPv4 address from a local pool Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 17
  • 18. DEMO SETUP Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 18
  • 19. Demo Topology Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 19 Wifi Network SSID: Nat64NUF A10 AX3530 NAT64 DNS64 RMv6TF Network Unix server DHCPv6 2001:428:3804:64::/64 No IPv4 2001:428:3804::/64 10.2.0.70 (upstream NAT 63.156.186.246)
  • 20. A10 Config Bits Inside config Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 20 Configure NAT pools Configure NAT using the well-known prefix
  • 21. A10 Config Bits Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 21
  • 22. Demo Setup Join the network using SSID: Nat64NUF Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 22
  • 23. NAT64 EXPERIENCE Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 23
  • 24. What works? • Nearly everything – A10’s implementation was solid, no signs of bugs or performance problems – Operating systems: Windows, MacOS, Linux – Nearly all classic IP protocols: POP, IMAP, SSH, Telnet, Standard web stuff, SMTP – Many chat protocols: Google talk, FaceBook chat – Entertainment: Pandora web client, Netflix, YouTube, Hulu Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 24
  • 25. IOS is Weird Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 25 We appear to be connected
  • 26. IOS is Weird Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 26 Seems to be stuck in the process of connecting…
  • 27. IOS is Weird Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 27 But look, it worked!
  • 28. Whois broken?? Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 28
  • 29. Whois • A few whois attempts later, everything was working • Does it depend on if the AAAA or A record comes back first? Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 29
  • 30. FTP before ALG Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 30
  • 31. FTP with ALG, Outside Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 31
  • 32. FTP with ALG, Inside Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 32
  • 33. What doesn’t work? • All Android based devices we tried did not function – We suspect that Android performs an IPv4 connectivity specific test and reject networks that doesn’t have IPv4 – We also suspect that Android will not consider DNS over IPv6 transport Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 33
  • 34. AOL Instant Messenger Won’t connect to the server, why? Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 34
  • 35. Skype Also won’t connect to the Skype network Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 35
  • 36. CONCLUSION Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 36
  • 37. NAT64 is good • Works for most apps • Most of the non-working apps seem reasonably fixable • Very good vendor support from A10 Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 37
  • 38. Thanks!! Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 38
  • 39. Q and A Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2012, Network Utility Force LLC Companyconfidential information, transmittal to third parties by prior permission only 39
  • 40. Network Utility Force LLC, 15 Wieuca Trace Northeast, Atlanta, Georgia, 30342 -- +1-404-635-6667 -- sales@netuf.net © 2013, Network Utility Force LLC Company confidential information, transmittal to third parties by prior permission only 40 Download the presentation here: Brandon Ross – Chief Network Architect – Network Utility Force – bross@netuf.net Erik Muller – Network Architect – Network Utility Force – em@netuf.net René Paap - Technical Marketing Engineer – A10 network – rpaap@a10networks.com

Hinweis der Redaktion

  1. Started with a mission to provide superior customer service and to be the industry true innovatorLeader in Application Networking Optimize the networks of web giants, enterprises and service providersGoing forward, we will focus primarily on AX, functionalities of EX and ID will be moved to the AX platformDue to all of you here today, A10 grew significantly, we have over 400 talented employees, 15 international branch offices, customers in 35 countries
  2. Making ipv6 practical
  3. IPv6 is increasing, networks must be ready.Each solution has its own pros & cons
  4. During the live presentation I didn’t explain this well. If you note line 38, an “EPRT” request was made to an IPv6 address, but without the FTP ALG enabled, the connection fails (packets 39-48)
  5. Here, the ALG is enabled, you can see the EPRT requests a connection with an IPv6 address (see next slide)
  6. And here you can see that the connection was successful on IPv4 side of the NAT64 using an IPv4 address.