IPv6 Status, Management, & Configuration Issues Winter 2013 ESCC meeting January 18, 2013.

Slides:



Advertisements
Similar presentations
IPv4 - IPv6 Integration and Coexistence Strategies Warakorn Sae-Tang Network Specialist Professional Service Department A Subsidiary.
Advertisements

IPv6 Planning and Implementation at PSU.  1986 – PSU gets Class B network ( ) & 5 Class C networks  1988 – Department of Computer.
IPv6 Privacy Hannes Tschofenig, Tara Whalen. Agenda Privacy Threats Layering Addressing Policy Questionnaire.
Implementing IPv6 Module B 8: Implementing IPv6
Enabling IPv6 in Corporate Intranet Networks
IPv6 at CERN Update on Network status David Gutiérrez Co-autor: Edoardo MartelliEdoardo Martelli Communication Services / Engineering
©2012 ClearOne Communications. Confidential and proprietary. COLLABORATE ® Video Conferencing Networking Basics.
US Labs IPv6 Planning & Deployment Status Phil DeMar Oct. 4,
5-Network Defenses Dr. John P. Abraham Professor UTPA.
Cosc 4765 Network Security: Routers, Firewall, filtering, NAT, and VPN.
Network Security Topologies Chapter 11. Learning Objectives Explain network perimeter’s importance to an organization’s security policies Identify place.
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents may contain confidential information and are not to be copied. Tribal Telecom 2015.
Lesson 18-Internet Architecture. Overview Internet services. Develop a communications architecture. Design a demilitarized zone. Understand network address.
Transition Mechanisms for Ipv6 Hosts and Routers RFC2893 By Michael Pfeiffer.
Firewall 2 * Essential Network Security Book Slides. IT352 | Network Security |Najwa AlGhamdi 1.
(part 3).  Switches, also known as switching hubs, have become an increasingly important part of our networking today, because when working with hubs,
Treaded Case Study Computer Networks 2002 Daire Sheriden Ronan Monaghan Mark Gilmore.
© 2012 Cisco and/or its affiliates. All rights reserved. 1 CCNA Security 1.1 Instructional Resource Chapter 10 – Implementing the Cisco Adaptive Security.
Advanced Networking for DVRs
IPv6 Site Renumbering Gap Analysis draft-ietf-6renum-gap-analysis-02 draft-ietf-6renum-gap-analysis-02 Bing Liu (speaker), Sheng Jiang, Brian.E.Carpenter,
Khaja Ahmed Architect Windows Networking Microsoft Corporation.
Installing a DHCP Server role on Windows Server 2008 R2 in a home network. This is intended as a guide to install the DHCP role on a Domain Controller.
CS426Fall 2010/Lecture 361 Computer Security CS 426 Lecture 36 Perimeter Defense and Firewalls.
Virtual Company Group 8 Presentation Date: June /04/2017
Campus IPv6 Deployment Phillip Deneault WPI Network Security Officer 1.
IPv6 Are we there yet?. Problem The Internet keeps growing Running out of IPv4 addresses Running out of time!
IPv6 Home Networking Architecture - update IETF homenet WG Interim meeting Philadelphia, 6 th Oct 2011 draft-chown-homenet-arch-00.
Firewall and Internet Access Mechanism that control (1)Internet access, (2)Handle the problem of screening a particular network or an organization from.
XTM Networking Tips and Tricks Carlo Alvarez Technical Trainer - APAC.
Objectives Configure routing in Windows Server 2008 Configure Routing and Remote Access Services in Windows Server 2008 Network Address Translation 1.
1 The Firewall Menu. 2 Firewall Overview The GD eSeries appliance provides multiple pre-defined firewall components/sections which you can configure uniquely.
EMEA Partners XTM Network Training
Module 3: Designing IP Addressing. Module Overview Designing an IPv4 Addressing Scheme Designing DHCP Implementation Designing DHCP Configuration Options.
Wireless Networks and the NetSentron By: Darren Critchley.
IPv6 at the University of Wisconsin Hopefully 79,228,162,514,264,337,593,543,950,336 IP addresses will be enough for a while. A subset of the UW IPv6 Task.
Guide to TCP/IP Fourth Edition Chapter 11: Deploying IPv6.
Connecting to a Network Lesson 5. Objectives Understand the OSI Reference Model and its relationship to Windows 7 networking Install and configure networking.
IPv6 – What You Need To Know Tom Hollingsworth CCNP,CCVP,CCSP, MCSE.
 An Internet Protocol address (IP address) is a numerical label assigned to each device (e.g., computer, printer) participating in a computer network.
CHAPTER 3 PLANNING INTERNET CONNECTIVITY. D ETERMINING INTERNET CONNECTIVITY REQUIREMENTS Factors to be considered in internet access strategy: Sufficient.
APNIC Update The state of IP address distribution and IPv6 deployment status Miwa Fujii Senior IPv6 Program Specialist APNIC.
ESnet Site Coordinators Committee (ESCC): IPv6 Activities & Directions Phil DeMar (ESCC Chair) HEPix IPv6 Workshop (CERN) June 22, 2011.
Campus Networking Best Practices Hervey Allen NSRC & University of Oregon Dale Smith University of Oregon & NSRC
Ch 6: IPv6 Deployment Last modified Topics 6.3 Transition Mechanisms 6.4 Dual Stack IPv4/IPv6 Environments 6.5 Tunneling.
Securing the Network Infrastructure. Firewalls Typically used to filter packets Designed to prevent malicious packets from entering the network or its.
Data Communications and Networks Chapter 10 – Network Hardware and Software ICT-BVF8.1- Data Communications and Network Trainer: Dr. Abbes Sebihi.
Switch Features Most enterprise-capable switches have a number of features that make the switch attractive for large organizations. The following is a.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 11: Network Address Translation for IPv4 Routing And Switching.
BNL PDN Enhancements. Perimeter Load Balancers Scaleable Performance Fault Tolerance Server Maintainability User Convenience Perimeter Security.
Configuring Network Connectivity Lesson 7. Skills Matrix Technology SkillObjective DomainObjective # Using the Network and Sharing Center Use the Network.
6.1 © 2004 Pearson Education, Inc. Exam Designing a Microsoft ® Windows ® Server 2003 Active Directory and Network Infrastructure Lesson 6: Designing.
Role Of Network IDS in Network Perimeter Defense.
ORNL Site Report ESCC July 15, 2013 Susan Hicks David Wantland.
IPv6 at FNAL IPv6 at FNAL (Where We Are; Where We are Going) Phil DeMar NLIT 2013 May 14, 2013.
IPv6 Security Issues Georgios Koutepas, NTUA IPv6 Technology and Advanced Services Oct.19, 2004.
© 2015 Infoblox Inc. All Rights Reserved. Tom Coffeen, IPv6 Evangelist UKNOF January 2015 Tom Coffeen, IPv6 Evangelist UKNOF January 2015 DHCPv6 Operational.
ITMT Windows 7 Configuration Chapter 5 – Connecting to a Network ITMT 1371 – Windows 7 Configuration 1.
SMOOTHWALL FIREWALL By Nitheish Kumarr. INTRODUCTION  Smooth wall Express is a Linux based firewall produced by the Smooth wall Open Source Project Team.
11 MAINTAINING A NETWORK INFRASTRUCTURE Chapter 9.
IPv6 Status Update & Discussion Phil DeMar Winter 2014 ESCC meeting February 25, 2014.
IPv6 Status Stuff Phil DeMar Summer 2011 JointTechs meeting July 14, 2011.
DOE /ESnet-related IPv6 Activities Phil DeMar HEPix IPv6 Workshop (CERN) Sept. 6,
25/09/ Firewall, IDS & IPS basics. Summary Firewalls Intrusion detection system Intrusion prevention system.
IPv6 investigation within Informatics George Ross
Firewalls.
IPv6 investigation within Informatics George Ross
I. Basic Network Concepts
AbbottLink™ - IP Address Overview
Chapter 10: Advanced Cisco Adaptive Security Appliance
Chapter 11: Network Address Translation for IPv4
Presentation transcript:

IPv6 Status, Management, & Configuration Issues Winter 2013 ESCC meeting January 18, 2013

Current Site OMB 2012 Milestone Status Comment: Includes IPv6 support into network core

Current Site OMB 2014 Milestone Status Comment:Expect to implement 18 month pilot project to provide production quality IPv6 support to Computing Division staff and general wireless users (voluntary)

OMB 2014 Compliance Comment: Includes IPv6 support into network core

Comments on Current Site IPv6 Status (I) We have enabled IPv6 dual stack support on wireless for a limited scope pilot test. It provides IPv6 DNS & DHCP services. DNS is IPv6 enabled. Delays waiting on cyber tools to be v6 enabled. There is some effort in the Cyber department to get their arms around firewall and border blocking of IPv6 addresses. Cyber is also working on collecting Netflow for IPv6 traffic. Looking into support for IPv6 support for our proxy servers that web traffic is routed through. There is also some thinking of how to handle host IPv6 addresses. How do we force a host to use a specific IPv6 address. We will IPv6ify additional PDN services to provide basic IPv6 site-to-site connectivity. I.E. SSH and FTP will be available in the near term Currently holding with external facing services operational. When activity resumes we will likely start with a small (operational) testbed on the production network.

Comments on Current Site IPv6 Status (II) We outsource a number of services. So, a large risk for our environment is not having support from 3rd party vendors. Growing executive's interest in IPv6 thanks mainly to peer pressure. Critical path blocked by lack of suitable IPAM system. Generally following OMB road map, but not attempting to adhere to its timelines. There is an R&D project to test IPv6 with LHC middleware & applications in conjunction with with Hepix IPv6 work group. We have implemented a partial solution, but do not consider it a top priority. We are also working with 'appliance' vendors, like Proofpoint and Infoblox, to support IPv6. They are finally starting to take it seriously.

Comments on Current Site IPv6 Status (III) We developed patches for IPv6 support in our IPAM and deployed them into production. It generates correct IPv4 and IPv6 DNS records. We will be adding more patches to our IPAM to generate DHCPv6 configs. We had extreme unfriendly behavior trying to put IPv6 through our production Cisco firewalls, but have already purchased replacements. So we rolled our IPv6 network equipment support into our 10-gig project. New firewall vendor had support issues with IPv6, particularly in HA failover mode, but they've since patched. We have purchased all equipment, including switches and firewalls, and we are expecting to begin deploying our core changes in stages by next days.

Discussion Points on Site IPv6 Support What is your site’s perspective on the need to support IPv6?  When? What’s the current level of commitment at your site toward supporting IPv6?  How has it changed (or is changing…)? What is the view on the OMB IPv6 milestones at your site?

IPv6 Status – The Big Picture Systems/Devices:  Windows 7 & MacOS 10.6 support IPv6 by default  Linux supports IPv6 (not by default)  Tablets & smart phones generally have IPv6 support Internet service providers:  Comcast targeting home IPv6 availability to homes by end of year Content service providers:  Google, Facebook, Yahoo, Youtube, Wikipedia Google IPv6 Access Monitoring

Problems with Valentine’s Day for the Person that has Everything? IPv6-addressable light bulb (LED)  Uses 6LoWPAN over IEEE  $200 for the kit  $30/light bulb 10 In case you were wondering why we might need an undecillion addresses…

Shadow IPv6 Networks Blue Coat: “Shadow IPv6 networks are here today”

Shadow IPv6 Networks (I) Comments:We have IDS (BRO) monitoring and blocking IPv6 traffic. We are assessing the potential impact of transitioning technology in dual stack environment. Windows clients have tight configuration control. Less so for other clients. v6 tunneling protocols (6to4, teredo) are blocked at site border. Investigating doing same between internal subnets. Would like to do RA guard, unsure of sw licensing issues on our installed switches.

Shadow IPv6 Networks (II) Comments:We have the capability of monitoring or checking unexpected IPv6 traffic traversing our DMZ if needed. Using wireshark to capture LAN traffic, with IPv6 filters Structured at the border, but less so internally. Network monitors do detect native and tunneled ipv6 in some cases. ipv6 is not routed on any L3 or routing equipment.

Shadow IPv6 Networks (III) Comments:We disable udp 3544 and protocol 41 v6 tunneling protocols (6to4, teredo) are blocked at site border. For 6-to-4, blocking the 6-to-4 anycast address and IPv4 protocol 41. For Toredo, blocking UDP port block IP protocol 41 at border as well as v6 transition technology addresses block known ports/protocols for tunneling, add as we discover others. tunnel is not allowed out through the firewall

Discussion Points on Shadow IPv6 Networks Ideas on whether/what/how to develop IPv6 visibility tools?  Other than buy a BlueCoat PacketShaper, of course

IPv6 Technology Issues

Site Expectations for SLAAC Support Comments:Definitely in guest network environments; unclear about general wireless or user LANs Still investigating, reluctant to use on servers SLAAC provides no capability to serve DNS server addresses. Since we must provide DHCPv6 to provide DNS addresses, it makes no sense to run both SLAAC and DHCPv6 in parallel. Would prefer a DHCP like solution that would be more like our current management scheme.

Expectations for Auto-configuration Controls Comments:We do expect to control RA but not clear on an effective implementation. RA guard very desirable. Not sure of the feasibility on all existing access devices not currently, but eventually We block it where we have the ability to in hardware Will configure L3 network equipment to not support

SLAAC & ND Issues/Concerns/Best Practices SLAAC does provide the capability to provide DNS server information (RFC 5006, obsoleted by 6106), but there is very little support for that in OS/router implementation. Is anyone using this feature? Is anyone running DHCPv6 in production? How are you handling issues like default router configuration, etc.? What about client identification?

Unique Local Addresses (ULAs) Comments: No RFC1918 and NAT support on production network ULA might be used for site-only networks. Unclear how much advantage vs filter at site border. Don't seem to be many reasonable alternatives for RFC1918 addresses, except border blocking. Assign block of v6 space and block at border We support IPv4 RFC1918 addresses only on closed non-routable VLANs. We have no plans to deploy ULAs on other VLANs, even in parallel with public routeable IPv6. We support RFC1918, but will use assigned ipv6 addresses, but will be firewalled

ULA Issues/Concerns/Best Practices Are there any new HPCC or massively parallel systems going into production? Will those systems use IPv6 for their internal addresses? Are there other places where ULA is being considered? Any concerns about the future of ULA?

Non-Default IPv6 Configurations Comments: Expect AD to enforce some group policy in protocol preferences or host tunneling capabilities. Would like to at least disable host tunnel capabilities. Privacy addresses are a management concern. Our machine network registration policy requires 1:1 assignment of addresses to machines. Therefore, we intend to use group policy wherever possible to disable privacy addresses. Most likely we will to avoid unwanted defaults, but not clear because of BYOD & variety of system types.

IPv6 Configuration Guidance & Best Practices Is anyone scraping their routers for NDP (or even ARP) information? Anyone using tools for this, like netdisco or netdot? (Did anyone watch the TIP presentation on netdot?) How useful is this sort of thing for us? Like it or not, privacy addresses are now becoming the default on OSes.