2. Why IPv6 is important
⢠The Internet grows... a lot more than during the dot.com
days
⢠IPv6 is the only solution for growth
⢠Continued IPv4 use will lead to walled gardens, separate
Internet islands with little or no connectivity
⢠IPv6 enables global realtime communication between all
connected devices
3. The Internet grows... more than during
the dot.com days
⢠Internet growth is bigger now than during the worst growth
during the dot.com explosion
⢠We have more Internet-enabled smart phones than IPv4
addresses
⢠An explosion of Internet-connected things is already happening.
4. We are global
⢠The Internet is growing personal and global.
⢠The only solution for global realtime communication is IPv6
⢠The current solution costs too much and is not global any more
5. No D-Day
⢠The change will go gradually
⢠IPv4 NAT will keep us alive
⢠Donât count with more public IP addresses for servers and
services.
⢠Donât panic, but start acting.
6. First notice
⢠Your contacts/customers in Asia will complain that they canât e-
mail you, or reach your web
⢠You buy a cool gadget in the Duty-Free electronic store, and it
just wonât connect
⢠Your ISP or hosting center says they will have to charge 1.000
Euro for the new IP address - per year.
7. IPv6 is the only solution
⢠There is no other magic solution to Internet growth and scalability
with IPv4
9. 1. Learn IPv6
⢠You need to upgrade your network engineers
⢠Itâs not hard, but remember, itâs a new protocol
⢠A new protocol means new security issues
10. 2. Get addresses
⢠Your ISP (or your next ISP) will give you a /48 network
⢠You will have more addresses than the current Internet and all of
IPv4 - yourself!
11. 3. Require IPv6
⢠Donât buy any network services, equipment or computers that
does not support IPv6
⢠Wake up, itâs 2015
⢠If no IPv6 support, take the cost this year, because you will soon
have to replace it.
12. 4. Convert public services
⢠Convert e-mail, DNS,VoIP and web to IPv6
⢠Make sure the world can reach you
13. 5. Check vendors
⢠Does your bank, consultants, outsourcing partners, vendors
support IPv6?
⢠API Services you use?
⢠Whatâs the status of your business neighbourhood?
14. 6. Dual stack on PCs
⢠When buying new PCs or upgrading, implement dual stack
⢠Supported by Linux, Mac,Windows
⢠Very simple to enable
15. 7. Use IPv6 - only
⢠If all clients have dual stack, donât be afraid to use ONLY ipv6 on
new servers
⢠Old servers are harder to move away from IPv4
⢠Use NAT64 for IPv4 reachability
16. 8. Move the IT
department
⢠Let the IT department PCs be IPv6 only
17. 9. BeneďŹt from IPv6
⢠VPNs are much easier
⢠You have a large address space - use it
⢠Mobility is built in
⢠IPv6 over IPv6, IPv6 over IPv4
⢠No more NAT traversal issues
18. 10. Donât panic.
⢠There is urgency, but your business wonât collapse if this doesnât
work today
⢠Make IPv6 part of every IT project
⢠Donât make it a special project
⢠Start now.
19. Stay connected!
⢠The beauty of the Internet is global reachability, global connectivity
⢠Without IPv6, the Internet will be fragmented into separate
islands and walled gardens
⢠We donât want that. No one wants that. Stay connected.â¨
Go IPv6 today!
20. Help your customers
⢠Wake them up
⢠Train them on all levels
⢠Introduce IPv6 in all current projects
⢠Help them test
⢠Get their public services connected to IPv6
⢠Require IPv6 from all your vendors
21. This is the new Internet.â¨
Do not stay behind!
23. IPv6 basics
⢠Larger IP packet headers - IP address 128 bits instead of 32
⢠AllTCP/UDP protocols behave like before
⢠Protocols that embedd IP address will have to support the new formats
⢠Subnetting like before with CIDR preďŹxes
128 bit
address
128 bit
address
24. A common enterprise model
48 bitâ¨
preďŹx
64 bitâ¨
device
16 bitâ¨
subnet
65536 networks!
ISP get /32â¨
Enterprise /48 or /56
30. Multiple addresses
per interface
Link local address based on MAC (FE80::)
Site local address - ULA FDxx
Global address based on network preďŹx and MAC
Global address based on network preďŹx and random data
Link local multicast addresses
Service speciďŹc multicast address
Loopback address (only for loopback interface)
The app selects
source address
31. Different views in OS/X
Network conďŹguration
shows only IPv4
Advanced showsâ¨
ONE IPv6 address
ifconďŹg
32. Distributing IPv6 addresses
Local Link (FE80::) - automatically
Global based on RA preďŹx - automatic (SLAAC)
Global based on DHCP - automatic (SLAAC)
Static - manual conďŹguration
Based on MAC address
Based on random data for privacy (temporary address)
34. DHCPv6 for ISPâs
NETWORKâ¨
PROVISIONING
Network preďŹx, subnet maskâ¨
router
Home gateway
Gets a network (not an address)â¨
from the service provider.
Distributes real Internet addresses toâ¨
network hosts. No NAT.
35. DUID = Device IdentiďŹer
SYSTEM
IF
IF
IF
DUID - Device Unique IdentiďŹer
IAID - Interface Adapter IdentiďŹer
In IPv4 DHCP the MACâ¨
is the system!
36. Where are they?
DUID
IAID
IAID
ETH0
WLAN0
Only shown in Microsoftâ¨
Windows 7. I canât ďŹnd itâ¨
easily in any other system.
!
Required to set up staticâ¨
DHCPv6 addressâ¨
management.
37. Various options
RA +â¨
SLAAC
SLAAC
+ DHCPv6
RA
+ DHCPv6
⢠Announce a preďŹx and a
router withâ¨
RADVD or RTSOL support
⢠MAC or temporary
⢠Simple, but not much control
⢠RA tells device to use
SLAAC and fetch more
options in DHCPv6
⢠DNS address, NTP server
⢠Better management, but still
not much control
⢠RA tells device to get IP and
more options in DHCPv6
⢠Device sends DUID+IAID
⢠Better management - log in
DHCP server
⢠Where is the DUID?
38. Privacy enhanced
⢠âWelcome back.Youâre using a
MacBook Pro 10th generation
from Sollentuna, Sweden.â
⢠Why should I let everyone see my
MAC address? And that I use
multiple devices?
⢠All systems support this.Windows
enable it by default. No other
system has it in the UI.
39. The end
...or is it the
beginning?
We need to make IPv6 a normal â¨
part of all network projects. Now.