IPv6 deployment at CERN - status update -

Slides:



Advertisements
Similar presentations
IPv6 Deployment CANTO Nate Davis, Chief Operating Officer 13 August 2014.
Advertisements

IPv6 Planning and Implementation at PSU.  1986 – PSU gets Class B network ( ) & 5 Class C networks  1988 – Department of Computer.
IPv6 at CERN Update on Network status David Gutiérrez Co-autor: Edoardo MartelliEdoardo Martelli Communication Services / Engineering
Understanding Internet Protocol
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 4 Installing and Configuring the Dynamic Host Configuration Protocol.
Module 4: Configuring Network Connectivity
Linux Networking TCP/IP stack kernel controls the TCP/IP protocol Ethernet adapter is hooked to the kernel in with the ipconfig command ifconfig sets the.
Agenda Network Infrastructures LCG Architecture Management
HEPiX IPv6 Working Group David Kelsey (STFC-RAL, UK) 4 May 2011 HEPiX, GSI, Darmstadt david.kelsey at stfc.ac.uk.
DYNAMIC HOST CONFIGURATION PROTOCOL (DHCP) BY: SAMHITA KAW IS 373.
Damian Leibaschoff Support Escalation Engineer Microsoft Becky Ochs Program Manager Microsoft.
Status of WLCG Tier-0 Maite Barroso, CERN-IT With input from T0 service managers Grid Deployment Board 9 April Apr-2014 Maite Barroso Lopez (at)
HEPiX IPv6 Working Group David Kelsey (STFC-RAL) 1 July 2011 UK HEP Sysman meeting.
Module 3: Designing IP Addressing. Module Overview Designing an IPv4 Addressing Scheme Designing DHCP Implementation Designing DHCP Configuration Options.
Module 4: Planning, Optimizing, and Troubleshooting DHCP
CERN IT Department CH-1211 Genève 23 Switzerland t IPv6 Deployment Project 2 April 2012
IPv6 at the University of Wisconsin Hopefully 79,228,162,514,264,337,593,543,950,336 IP addresses will be enough for a while. A subset of the UW IPv6 Task.
IPv6 – What You Need To Know Tom Hollingsworth CCNP,CCVP,CCSP, MCSE.
Links and LANs Link between two computers via cross cable The most simple way to connect two hosts is to link the two hosts with a cross cable.
Communication Between Networks How the Internet Got Its Name.
CHAPTER 3 PLANNING INTERNET CONNECTIVITY. D ETERMINING INTERNET CONNECTIVITY REQUIREMENTS Factors to be considered in internet access strategy: Sufficient.
News from the HEPiX IPv6 Working Group David Kelsey (STFC-RAL) WLCG GDB, CERN 8 July 2015.
News from the HEPiX IPv6 Working Group David Kelsey (STFC-RAL) GridPP35, Liverpool 11 Sep 2015.
The production deployment of IPv6 on WLCG David Kelsey (STFC-RAL) CHEP2015, OIST, Okinawa 16 Apr 2015.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 4: Addressing in an Enterprise Network Introducing Routing and Switching in the.
The HEPiX IPv6 Working Group David Kelsey EGI TF, Prague 18 Sep 2012.
Pack-it Technology Highly versatile Internet connectivity solution for non-Internet enabled devices. Seamless interface with RS232, Ethernet, switches,
The HEPiX IPv6 Working Group David Kelsey WLCG GDB, CERN 14 Nov 2012.
1 Using VPLS for VM mobility cern.ch cern.ch HEPIX Fall 2015.
HEPiX IPv6 Working Group David Kelsey GDB, CERN 11 Jan 2012.
A follow-up on network projects 10/29/2013 HEPiX Fall Co-authors:
The HEPiX IPv6 working group David Kelsey (STFC-RAL) HEPiX meeting, Bologna 17 Apr 2013.
The HEPiX IPv6 Working Group David Kelsey HEPiX, Prague 26 April 2012.
HEPiX IPv6 Working Group David Kelsey david DOT kelsey AT stfc DOT ac DOT uk (STFC-RAL) HEPiX, Vancouver 26 Oct 2011.
News from the HEPiX IPv6 Working Group David Kelsey (STFC-RAL) HEPIX, BNL 13 Oct 2015.
Network Layer IP Address.
Open source IP Address Management Software Review
HEPiX IPv6 Working Group David Kelsey (STFC-RAL) GridPP33 Ambleside 22 Aug 2014.
شركت ارتباطات زيرساخت آبان 1393
IPv4 shortage and CERN 15 January 2013
LESSON Networking Fundamentals Understand IPv4.
Chapter 05 Exam Review CCNA Discovery 01 – Computer and Network Fundamentals Presented by: Phillip Place Cisco Academy Instructor Lake Michigan College.
WLCG IPv6 deployment strategy
IPV6.
Discussion on DHCPv6 Routing Configuration
IPv6 Hands-on pre-GDB IPv6 workshop 7th of June 2016 edoardo
Support for IPv6-only CPU – an update from the HEPiX IPv6 WG
Update from the HEPiX IPv6 WG
Chapter 10: DHCP Routing & Switching Chapter 10: DHCP
Routing and Switching Essentials v6.0
Understand Networking Services
Introduction to Networking
Introduction to Networking
Introducing To Networking
WLCG and support for IPv6-only CPU
Welcome To : Group 1 VC Presentation
Chapter 9 Objectives Understand TCP/IP Protocol.
Net 431 D: ADVANCED COMPUTER NETWORKS
Routing and Switching Essentials v6.0
Microsoft Virtual Academy
Examining IP Addressing
Planning the Addressing Structure
DNS and DHCP Configuration
Planning the Addressing Structure
Ip addressing: dhcp & dns
AbbottLink™ - IP Address Overview
Chapter 11: Network Address Translation for IPv4
How To Configure Hotspot in Virtual Mikrotik on VMware
Module 12 Network Configuration
Project 172 Update Terry Gray 30 April 2003 Director,
Presentation transcript:

IPv6 deployment at CERN - status update - CERN, 4th of July 2013 edoardo.martelli@cern.ch CERN IT Department CH-1211 Genève 23 Switzerland www.cern.ch/it

Agenda IPv4 depletion CERN IPv6 service description IPv6 deployment status Challanges ahead HEPiX IPv6 working group Conclusion Test drive

IPv4 depletion

World IPv4 pools status Region Last /8 date Remaining /8 (16M) Asia-Pacific 19-Apr 2011 0.8562 Europe 14-Sep-2012 0.8892 North America 14-Apr-2014 2.1557 South America 05-Aug-2014 2.3016 Africa 24-Sep-2020 3.7124 [25th June 2013]

CERN IPv4 pools status (June 2013) 128.141.0.0/16 (64K) - GPN dynamics (~65% used) 128.142.0.0/16 (64K) - LCG statics (~41% used) 137.138.0.0/16 (64K) - GPN statics (~92% used) 188.184.0.0/17 (32K) - GPN statics (~9% used) 188.184.128.0/17 (32K) - LCG statics (~8% used) 188.185.0.0/16 (64K) - Wigner datacentre (~1% used) [as of 25th of June 2013]

CERN IPv4 pools status (Jan 2013) 128.141.0.0/16 (64K) - GPN dynamics (~65% used) 128.142.0.0/16 (64K) - LCG statics (~40% used) 137.138.0.0/16 (64K) - GPN statics (~92% used) 188.184.0.0/17 (32K) - GPN statics (~5% used) 188.184.128.0/17 (32K) - LCG statics (0% used) 188.185.0.0/16 (64K) - Wigner datacentre (0% used) [as of 7th of January 2013]

CERN IPv6 service description

CERN IPv6 service - Dual Stack - One IPv6 address assigned to every IPv4 one - Identical performance as IPv4, no degradation - Common provisioning tools for IPv4 and IPv6 - Same network services portfolio as IPv4 - Common security policies for IPv4 and IPv6

Dual stack services At least one IPv6 sub-prefix per physical subnet, public and/or local. Subnet size: /64 (i.e. 64 bits for the network address, 64 bits for the host address) Available host addresses per subnets: 264 (recommended size). Router Switch 137.138.14.0/24 2001:1458:0201:0E00::/64 Servers, Hosts

IPv6 ready The DNS device name .cern.ch will be resolved only with the IPv4 address until the user declares to LANDB (via WEBREQ) to be IPv6 ready. IPv6 ready means: - IPv6 connectivity is OK - all the server's applications are listening on both IPv4 and IPv6 protocols Consequences: - IPv6 security openings activated in the central firewall - name.cern.ch returns IPv4 and IPv6 addresses (A and AAAA records)

IPv6 deployment status

IT/CS Network services DNS: No DNS names for CERN IPv6 addresses DHCPv6 for statics: Ready DHCPv6 for portables: Testing NTP: Ready Internet: Ready Firewall: Static firewall only

IT/CS Network management Network database (LANDB): Ready IT/CS tools (CSDBWEB, cfmgr): Ready User web interface (WEBREQ): Testing SOAP interface: Testing Monitoring (Spectrum): Developing

Timeline - Testing of network devices: completed - IPv6 Testbed for CERN users: available - New LANDB schema: in production - Addressing plan in LANDB: in production - Provisioning tools (cfmgr and csdbweb): ready - User interfaces (webreq): testing - Network configuration: on going - Network services (DNS, DHCPv6...): on going - User training: on going - IPv6 Service ready for production in 2013 2011Q2 2011Q3 2021Q1 2012Q1 2012Q4 Today 2013Q4

Check the current status at Latest news: Check the current status at http://cern.ch/ipv6/content/implementation-plan

Challenges ahead

Opportunities.. - no more address poverty, no more fear to waste - multiple addresses per interface, even in the same IPv6 subnet - no IPv6 NAT (not even designed) - Internet of things

...and challenges - new operational issues - new software development - new protocols to test (DHCPv6...) - new security threats (attacks on mixed stacks...) - some applications don't work (AFS...) - not-homogeneous dual-stacks (private v4 and public v6)

Lots of VMs Current VMs adoption plan will cause IPv4 depletion during 2014. Then two alternative options: A) VMs with only public IPv6 addresses + Unlimited number of VMs - Several applications don't run over IPv6 today (PXE, AFS, ...) - Very few remote sites have IPv6 enabled (limited remote connectivity) + Will push IPv6 adoption in the WLCG community B) VMs with private IPv4 and public IPv6 + Works flawlessly inside CERN domain - No connectivity with remote IPv4-only hosts (NAT solutions not supported nor recommended)

HEPiX IPv6 working group

HEPiX IPv6 Working Group - Chairman: Dave Kelsey (RAL) - Active members: CERN, DESY, FNAL, FZU, GARR, Glasgow, INFN, KIT, Manchester, RAL, SLAC, USLHCnet (Caltech), CMS, ALICE and LHCb - Nearly 50 on the mail list - Regular video and face-to-face meetings

- IPv6 implementation check list WG activities - IPv6 implementation check list - Software and tools compliance survey - Distributed dual-stack testbed - Security awareness Your help is needed! Contact the WG at http://cern.ch/hepix-ipv6/contact

Conclusions

Conclusions - IPv6 deployment at CERN is progressing well - IPv6 will bring new functionalities and opportunities - Future deployments cannot rely on large amounts of IPv4 public addresses - Use of IPv6 in the WLCG has to start as soon as possible

More information: http://cern.ch/ipv6

Let's try

Ask ipv6@cern.ch to IPv6 enable your device

Renew the dhcp lease linux# dhclient -6 linux# ifconfig eth0 Link encap:Ethernet HWaddr 00:22:4d:83:03:19 inet6 addr: fe80::222:4dff:fe83:319/64 Scope:Link inet6 addr: 2001:1458:201:b459::100:5/64 Scope:Global C:\Windows>ipconfig /renew Ethernet adapter Local Area Connection: IPv6 Address. . . . . . . . . . . : 2001:1458:201:17::100:2 Link-local IPv6 Address . . . . . : fe80::a844:b2c4:8637:5e8e%11 Default Gateway . . . . . . . . . : fe80::215:60ff:feed:ce00%11 /macos> sudo ifconfig en0 up

Check: http://ipv6-test.com

SixOrNot Firefox add-on

Enjoy