That is why Rabobank has IPv6

Slides:



Advertisements
Similar presentations
Stonesoft Roadmap WHAT FEATURES WILL COME IN
Advertisements

Firewalls By Tahaei Fall What is a firewall? a choke point of control and monitoring interconnects networks with differing trust imposes restrictions.
1 BIG-IP Global Traffic Manager Presented by: your name, your title.
Introduction to ISA 2004 Dana Epp Microsoft Security MVP.
Trusted Internet Connections. Background Pervasive and sustained cyber attacks against the United States continue to pose a potentially devastating impact.
NAT Network Address Translation. NAT Links cisco.shtmlhttp:// cisco.shtml.
Lesson 1: Understanding Browsers. This unit is a set of investigations into how to protect against digital threats, and how to detect digital crimes.
Norman SecureSurf Protect your users when surfing the Internet.
1 The SpaceWire Internet Tunnel and the Advantages It Provides For Spacecraft Integration Stuart Mills, Steve Parkes Space Technology Centre University.
How STERIS is using Cloud Technology to Protect Web Access Presented By: Ed Pollock, CISSP-ISSMP, CISM CISO STERIS Corporation “Enabling Business”
Threat Management Gateway 2010 Questo sconosciuto? …ancora per poco! Manuela Polcaro Security Advisor.
Net Neutrality and its implications JANVIER NGNOULAYE, PhD. University of Yaounde 1 – Cameroon The African Internet Governance Forum.
FIREWALKING. KNOW YOUR ENEMY: FIREWALLS What is a firewall? A device or set of devices designed to permit or deny network transmissions based upon a set.
CSIS  We need to create some logic to the environment  We want to keep like devices together  We want to make money leasing the use of the space.
Network and Perimeter Security Paula Kiernan Senior Consultant Ward Solutions.
ISP Edge NAT 10/8 “Home” Network Upstreams and Peers /32
Securing the Network Infrastructure. Firewalls Typically used to filter packets Designed to prevent malicious packets from entering the network or its.
Computer networks Internet, Intranet, Extranet, Lan, Wan, characteristics and differences.
Juan Ortega 8/20/09 NTS300. Right now IPv4 dominates the Internet with some experts believing the need for IPv6 isn’t necessary because of NAT. But even.
B2C Hosting March 21, Executive Summary Business Problem: The primary goal of the project is to provide a world class web hosting Infrastructure.
CITA 310 Section 3 Additional Topics. Common IPv4 Classes ClassFirst numberSubnet maskNumber of networks Number of addresses Class A0 – ,777,216.
Office 365 Performance Management. Meet Paul Andrew Office 365 Technical Product Manager – Office 365 datacenter, networking, identity management.
Presented by: Philippe Bogaerts Sr. Channel Field Systems Engineer Benelux Building an agile IPv6 infrastructure.
Implementing a Security Policy JISC – ICT Security Threats & Promises, April 2002 Mick Ismail ICT Services Manager City of Wolverhampton College.
Siân Shordon Schools Broadband Manager Schools’ Broadband Service.
HCNA-Security Huawei Certified Network Associate Security (HCNA-Security) validates the basics of network security knowledge and skills to support the.
Aarnet Australia's Academic and Research Network Glen Turner IPv6 birds of a feather meeting QUESTnet 2011 IPv6 — the elevator pitch.
CS 3700 Networks and Distributed Systems
Could SP-NAT Save the Internet?
WHY VIDEO SURVELLIANCE
WHY VIDEO SURVELLIANCE
CompTIA Security+ Study Guide (SY0-401)
Top 5 Open Source Firewall Software for Linux User
Optimize your network for the cloud
Daniel “3ICE” Berezvai Reverse Proxy Presentation by:
Chapter 7: Identifying Advanced Attacks
Do you know who your employees are sharing their credentials with
Network Address Translation (NAT)
CONNECTING TO THE INTERNET
Set up your own Cloud The search for a secure and acceptable means of gaining access to your files stored at the office from a remote location.
TECHNOLOGY GUIDE THREE
Network Address Translation
Securing the Network Perimeter with ISA 2004
Practical Censorship Evasion Leveraging Content Delivery Networks
Network Address Translation (NAT)
Web Hosting What you need to know!.
Introducing To Networking
Who should be responsible for risks to basic Internet infrastructure?
Acutelearn BIG IP F5 LTM Training in Hyderabad Classroom Training Instructor led trainings at Acutelearn premises Corporate Training Custom tailored trainings.
Advanced Security Architecture for System Engineers Cisco Dumps Get Full Exam Info From: /cisco-question-answers.html.
Jon Peppler, Menlo Security Channels
The Hacking Suite for Governmental Interception
CompTIA Security+ Study Guide (SY0-401)
Your Business Opportunity
Free 2018 Cisco Questions-Cisco Dumps PDF Cisco Dumps
COMPREHENSIVE APPROACH TO INFORMATION SECURITY IN ADVANCED COMPANIES
Privacy Through Anonymous Connection and Browsing
AKAMAI INTELLIGENT PLATFORM™
CS 3700 Networks and Distributed Systems
IS4680 Security Auditing for Compliance
An Update on Multihoming in IPv6 Report on IETF Activity
Siân Shordon Schools Broadband Manager
Matías Heinrich VP Operations Latam October 2011
IPv6 Deploying The Foundation For Tomorrow
WHY VIDEO SURVELLIANCE
WHY VIDEO SURVELLIANCE
was not invented by Al Gore…
Office 365 – How NOT to do it UKNOF43.
AT&T Dedicated Internet (ADI)
AT&T Firewall Battlecard
Presentation transcript:

That is why Rabobank has IPv6 External facing IPv6 Friso Feenstra Netw0rk Specialist

Why IPv6 2014 investigation: Is IPv6 necessary for our corporate websites (www.rabobank.nl) Is IPv6 necessary for our internal network

Why IPv6 2014 investigation: Is IPv6 necessary for our corporate websites (www.rabobank.nl) Is IPv6 necessary for our internal network My expectation: NO !!!! No IPv6

Why IPv6 2014 investigation: Is IPv6 necessary for our corporate websites (www.rabobank.nl) Is IPv6 necessary for our internal network My expectation: NO !!!! No IPv6 Internet for office NAT44 to provider IP space internal addressing: private (17 million addresses) Migration costs time and money external adressing: Rabobank IP space 145.72.0.0/16 (65.000 addresses) Migration Risk

Why IPv6 2014 investigation: Is IPv6 necessary for our corporate websites (www.rabobank.nl) Is IPv6 necessary for our internal network My expectation: NO !!!! No IPv6 Internet for office NAT44 to provider IP space internal addressing: private (17 million addresses) Migration costs time and money external adressing: Rabobank IP space 145.72.0.0/16 (65.000 addresses) Migration Risk Still investigation for Are there reasons for IPv6 for Rabobank?

Investigation: Why IPv6 What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed

Investigation: Why IPv6 Currently no problem: Websites relevant for Rabobank banking will be reachable through IPv4 for the coming years What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed

Investigation: Why IPv6 Currently no problem: Websites relevant for Rabobank banking will be reachable through IPv4 for the coming years What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed But what about financial web sites in countries with little IPv4 space???

Investigation: Why IPv6 What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed For the coming years no problem: Communication with NAT or proxy in DMZ

Investigation: Why IPv6 What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed

Investigation: Why IPv6 Customers connected through ISP’s (KPN, Vodafone, Ziggo, etc.) What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed

Investigation: Why IPv6 Customers connected through ISP’s (KPN, Vodafone, Ziggo, etc.) What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed ISPs have IPv4 space for existing customers

Investigation: Why IPv6 Customers connected through ISP’s (KPN, Vodafone, Ziggo, etc.) What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed ISPs have IPv4 space for existing customers New customers? New networks?

Investigation: Why IPv6 New customers? New networks? New networks – new customers G3 / G4 Wifi New area’s Mergers IPv4 NAT is used as solution Expensive solution Not for all customers Recovery after disruption Alternative: IPv6 + IPv4 NAT Because all main content is available on IPv6

Investigation: Why IPv6 New customers? New networks? New networks – new customers G3 / G4 Wifi New area’s Mergers IPv4 NAT is used as solution Expensive solution Not for all customers Recovery after disruption Alternative: IPv6 + IPv4 NAT Because all main content is available on IPv6 So more and more customers will be behind NAT if we don’t act.

Investigation: Why IPv6 New customers? New networks? New networks – new customers G3 / G4 Wifi New area’s Mergers IPv4 NAT is used as solution Expensive solution Not for all customers Recovery after disruption Alternative: IPv6 + IPv4 NAT Because all main content is available on IPv6 So more and more customers will be behind NAT if we don’t act. Is that a problem???

Investigation: Why IPv6 More customers behind IPv4 NAT. Problem??

Investigation: Why IPv6 More customers behind IPv4 NAT. Problem?? Security Operations Centre “The majority of the SOC tooling for protection of customer traffic becomes unreliable of unusable” Reason: Tooling is often based on IP addresses, for instance blocking one IP address leads to blocking whole groups of customers

Investigation: Why IPv6 More customers behind IPv4 NAT. Problem?? Security Operations Centre “The majority of the SOC tooling for protection of customer traffic becomes unreliable of unusable” Reason: Tooling is often based on IP addresses, for instance blocking one IP address leads to blocking whole groups of customers Transaction monitoring, withing FEC (Financial Economic Crime) “IP address is one of the more important pillors for detection of Phishing” “Many security components will lose effectiveness”

Investigation: Why IPv6 More customers behind IPv4 NAT. Problem?? Security Operations Centre “The majority of the SOC tooling for protection of customer traffic becomes unreliable of unusable” Reason: Tooling is often based on IP addresses, for instance blocking one IP address leads to blocking whole groups of customers Transaction monitoring, withing FEC (Financial Economic Crime) “IP address is one of the more important pillors for detection of Phishing” “Many security components will lose effectiveness” VCM (Virtual Channel Monitoring), within FEC “More then 15% customers traffic behind provider NAT is not acceptable”

Investigation: Why IPv6 What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed

Investigation: Why IPv6 But once there will be IPv6-only: Features Applications Web sites That we need!!! What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed

Investigation: Why IPv6 But once there will be IPv6-only: Features Applications Web sites That we need!!! What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed When is this going to happen When will we know this How much lead time do we have Is this enough

Investigation: Why IPv6 But once there will be IPv6-only: Features Applications Web sites That we need!!! What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed When is this going to happen When will we know this How much lead time do we have Is this enough Expectation: 2018 - 2025

Investigation: Why IPv6 But once there will be IPv6-only: Features Applications Web sites That we need!!! What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed When is this going to happen When will we know this How much lead time do we have Is this enough Expectation: 2018 - 2025 .5 – 1 year in advance

Investigation: Why IPv6 But once there will be IPv6-only: Features Applications Web sites That we need!!! What happens with IP adresses for Web sites Third parties Customers If we stay on IPv4 will we miss something Can we pospone migration for the coming years: Other parties can get the experience Bugs and error have been solved We have more time Best practises can be developed When is this going to happen When will we know this How much lead time do we have Is this enough Expectation: 2018 - 2025 .5 – 1 year in advance NO!!!

Approach External facing IPv6 project IPv6 internal project Started Q2-3 2015 IPv6 until external Load Balancer Multiple departments involved Networking (tooling, training and technical aspects) Security Operations Centre (monitoring, DDOS mitigation, IPDS, etc.) VCM (rapporting, fraud prevention, anti-physing), etc. Project per department for department acvitities with governance project for communication and time lines Finished www.rabobank.nl  2a02:cc4:2000::10 IPv6 internal project Planned to start in 2017 Three levels (network, platform, applications) Target network + platform  dual stack; applications is possible IPv6

Topology for main external facing Rabobank web sites Internet IPv4 IPv6 EK 4&6 DDOS IPDS 4&6 External Load Bal. 4&6 Content Inspection 4&6 Internal Load Bal. 4&6 Content Processing 4

Topology for main external facing Rabobank web sites Internet IPv4 IPv6 EK 4&6 DDOS IPDS 4&6 External Load Bal. 4&6 Content Inspection 4&6 Internal Load Bal. 4&6 Content Processing 4 IPv4 & IPv6 session state! Two load balancers?

Topology for main external facing Rabobank web sites Internet peering SSL offloading X-forward RFC 7239 Internet IPv4 IPv6 EK 4&6 DDOS IPDS 4&6 External Load Bal. 4&6 Content Inspection 4&6 Internal Load Bal. 4&6 Content Processing 4 IPv4 & IPv6 session state! Two load balancers?

Topology for main external facing Rabobank web sites Clear text Internet peering SSL offloading X-forward RFC 7239 Internet IPv4 IPv6 EK 4&6 DDOS IPDS 4&6 External Load Bal. 4&6 Content Inspection 4&6 Internal Load Bal. 4&6 Content Processing 4 IPv4 & IPv6 session state! Two load balancers?

Topology for main external facing Rabobank web sites Clear text Internet peering SSL offloading X-forward RFC 7239 Internet IPv4 IPv6 EK 4&6 DDOS IPDS 4&6 External Load Bal. 4&6 Content Inspection 4&6 Internal Load Bal. 4&6 Content Processing 4 Triggers IPDS Defense IPv4 & IPv6 session state! Two load balancers?

Topology for main external facing Rabobank web sites LTM IPv4 SNAT Clear text Internet peering SSL offloading X-forward RFC 7239 Internet IPv4 IPv6 EK 4&6 DDOS IPDS 4&6 External Load Bal. 4&6 Content Inspection 4&6 Internal Load Bal. 4&6 Content Processing 4 IPv4 & IPv6 session state! Two load balancers?

Q&A??