IPv6 Implementation at a Network Service Provider

Slides:



Advertisements
Similar presentations
6TAP for an IPv6 Internet Becca L. Nitzan ESnet/Lawrence Berkeley National Lab STAR TAP Meeting June 22, 1999, San Jose, CA.
Advertisements

IPv6 Deployment CANTO Nate Davis, Chief Operating Officer 13 August 2014.
 IPv6 Has built in security via IPsec (Internet Protocol Security). ◦ IPsec Operates at OSI layer 3 or internet layer of the Internet Protocol Suite.
IPv4 - IPv6 Integration and Coexistence Strategies Warakorn Sae-Tang Network Specialist Professional Service Department A Subsidiary.
IPv6 Implementation Hints ________________________________________________ _ Andy Davidson Thursday 24 th November 2011 Hurricane Electric BELNET Conference,
IPv6 Keith Wichman. History Based on IPv4 Based on IPv4 Development initiated in 1994 Development initiated in 1994.
IPv6: Paving the way for next generation networks Tuesday, 16 July 2013 Nate Davis Chief Operating Officer, ARIN.
Transitioning to IPv6 April 15,2005 Presented By: Richard Moore PBS Enterprise Technology.
IPv4 to IPv6 Migration strategies. What is IPv4  Second revision in development of internet protocol  First version to be widely implied.  Connection.
IPv6: The Next Generation Internet Protocol CEOS WGISS 18: Beijing, China September 2004 Dave Hartzell Computer Sciences Corp, NASA Ames
IPv6: Application perspective Zaid Ali Chairman/President SFBAY ISOC
Project by: Palak Baid (pb2358) Gaurav Pandey (gip2103) Guided by: Jong Yul Kim.
IPv6 Planning and Implementation at PSU.  1986 – PSU gets Class B network ( ) & 5 Class C networks  1988 – Department of Computer.
IPv4 Depletion IPv6 Adoption 3 February /8s Remaining.
17/10/031 Summary Peer to peer applications and IPv6 Microsoft Three-Degrees IPv6 transition mechanisms used by Three- Degrees: 6to4 Teredo.
COSC 541 Data and Computer Communications IPV6 OVERVIEW Professor:Mort Anvari Student: Fuqiang Chen Student ID: Date:Mar
Technical Aspects of Peering Session 4. Overview Peering checklist/requirements Peering step by step Peering arrangements and options Exercises.
IPv4 Depletion and IPv6 Adoption Today Community Use Slide Deck Courtesy of ARIN May 2014.
© 2015 Global Technology Resources, Inc. All Rights Reserved. Contents may contain confidential information and are not to be copied. Tribal Telecom 2015.
1 IPv6 Address Management Rajiv Kumar. 2 Lecture Overview Introduction to IP Address Management Rationale for IPv6 IPv6 Addressing IPv6 Policies & Procedures.
Campus IPv6 Deployment Phillip Deneault WPI Network Security Officer 1.
Sean Mentzer IP Architecture Building an IPv6 Test Network.
7 IPv6: transition and security challenges Selected Topics in Information Security – Bazara Barry.
The Singapore Advanced Research & Education Network.
Lecture 4: BGP Presentations Lab information H/W update.
IPv6 for ISP Industry Sify Technologies Ltd Somasundaram Padmanabhan Network Engineering IPv6 Awareness Workshop.
ESnet Site Coordinators Committee (ESCC): IPv6 Activities & Directions Phil DeMar (ESCC Chair) HEPix IPv6 Workshop (CERN) June 22, 2011.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNP 1 v3.0 Module 2 Advanced IP Addressing Management Cisco Networking Academy.
Addressing Issues David Conrad Internet Software Consortium.
MENU Implications of Securing Router Infrastructure NANOG 31 May 24, 2004 Ryan McDowell
AARNet Copyright 2007 AARNet IPv6 Update IPv6 Workshop APAN 24, Xi’An 2007 Bruce Morgan.
Juan Ortega 8/13/09 NTS300. “The problem with version 5 relates to an experimental TCP/IP protocol called the Internet Stream Protocol, Version 2, originally.
IPv6 on vBNS+ Greg Miller NANOG - Albuquerque, NM June 12, 2000
Is Cyber Security IPv6-Ready? HEPiXX – Vancouver, BC Bob Cowles October, 2011.
1 © 2004 Cisco Systems, Inc. All rights reserved. Session Number Presentation_ID Early vs. Cautious IPv6 deployment Issues and trade-offs Tony Hain Cisco.
© 2005 Cisco Systems, Inc. All rights reserved. BGP v3.2—6-1 Scaling Service Provider Networks Scaling IGP and BGP in Service Provider Networks.
APAN 24, August 28, 2007, Xi’an IPv6Deployment in European Academic Networks Tim Chown School of Electronics and Computer Science University of Southampton.
APNIC IPv6 Allocation Update IPv6 SIG APNIC 14, Kitakyushu, Japan 4 September 2002.
IPv6 Security Issues Georgios Koutepas, NTUA IPv6 Technology and Advanced Services Oct.19, 2004.
Building SDN-ready high bandwidth IXP M.Sc.E.E. Goran Slavić
Sprintlink IPv6 rob rockell Goals play Value-Add for customers and others –free –not under SLA Test Implementations, think about.
Central Management of 300 Firewalls and Access-Lists Fabian Mauchle TNC 2012 Reykjavík, 21-May-2012.
IPv4 shortage and CERN 15 January 2013
Chapter 4: Network Layer
IPV6 TECHNIQUES TO Re-IMAGINE RESEARCH AND EDUCATION NETWORKS
Ipv6 addressing Chapter 5d.
Keeping local stuff local
The activities of IPv6 in IIJ
Network Architecture Layered system with alternative abstractions available at a given layer.
Next Generation: Internet Protocol, Version 6 (IPv6) RFC 2460
Paola Grosso SLAC October
Server Concepts Dr. Charles W. Kann.
ECSE-6600: Internet Protocols
Stateless Source Address Mapping for ICMPv6 Packets
Introducing Novell IPv6 Stack
IS3120 Network Communications Infrastructure
CS 457 – Lecture 14 Global Internet
IPv6 Address Allocation APNIC
Kireeti Kompella Juniper Networks
CERNET2 IPv6-only Practice: Backbone, Servers, Clients and 4aaS
Chapter 4: Network Layer
Chapter 4: Network Layer
Chapter 4: Network Layer
Introduction to IPv6 Last modified
IPv6 in Internet2 This is a general overview presentation about Internet2. Internet2 is a consortium, led by US universities, which is recreating the partnership.
Host and Small Network Relaying Howard C. Berkowitz
Computer Networks Protocols
Advanced Services – IPv6
IPv6 Current version of the Internet Protocol is Version 4 (v4)
When Can We Start Dropping IPv4 on the DNS Root Servers?
Presentation transcript:

IPv6 Implementation at a Network Service Provider 2010 Inter Agency IPv6 Information Exchange August 4, 2010 R. Kevin Oberman Sr. Network Engineer

Who Are We? ESnet is the network provider for the Department of Energy’s Office of Science ESnet is a networking pioneer with nearly a quarter century of networking Began as MFEnet in 1976 Became ESnet with broader mission in 1986 Started support of BGP4 and modern peering in 1994 Multicast support since 1995 Provide network connectivity to DOE Science funded laboratories and research projects Provides full commercial connectivity with over 100 commercial peers ESnet is transit free

Pioneered IPv6 ESnet has pioneered IPv6 since its inception ESnet started working on IPv6 in 1996 Tony Hain and Bob Fink chaired the main IPng IETF working groups ESnet worked closely with Sun, Digital, Kame, and Cisco in the development and testing of IPv6 developmental code Instrumental in the development of the 6-Bone Partnered with Viagenie to create 6Tap, the first IPv6 Internet Exchange Received the first production IPv6 address allocation from ARIN First production addressed system, hershey.es.net still sits in my office in Berkeley.

IPv6 Status IPv6 is a fully supported production service of ESnet Since 2004 Available to all sites and peerings ESnet web services, NTP, DNS, and mail use IPv6 Currently we are our own best customers That is changing Sites are adding IPv6 connectivity Even a couple of IPv6 services

ESnet4 Backbone Topology Router node 10G link

IPv6 Implementation IGP is ISIS Common implementation for many protocols Security advantages iBGP advertizes IPv6 over a common mesh with IPv4 Be careful of next-hop self Not all route vendors support this eBGP is all native ESnet does not use tunnels

Internal use ESnet uses IPv6 whenever possible (and it usually is) Our mail and web services are IPv6 DNS is IPv6 NTP is IPv6 Network management uses IPv6 (SNMP) Fully implemented on CA Spectrum Network Management system Console access to most systems is ssh over IPv6

Site support Provide technical assistance for sites implementing IPv6 Provide address space (Provider aggregable) in /48 chunks

IPv6 Peering No significant differences between IPv6 and IPv4 peering Most major providers now have some level of IPv6 capability Some run full dual stacks on peering routers Some still depend on tunnels to reach a limited number of dual-stack routers Some provide IPv6 only at a limited number of locations The situation has improved significantly in the past 12 month for commercial providers

Issues with IPv6 support Many management tools do not yet support IPv6 This is changing, but rather slowly Will change must more quickly when customers start demanding FULL IPv6 feature parity (you all do that already, don’t you?) Not much of a registry for IPv6 routing information Many peering monitoring tools have limited or buggy IPv6 support You need an addressing plan (or two or three)

IPv6 Addressing Plans Addressing plans are crucial to successful deployment The are seldom easy Will need occasional adjustment May even require full replacement This can almost always be avoided Design the addressing plan for you logical topology Always allocate more bits than you need! Addresses are plentiful and cheap Don’t be penny wise and pound foolish Assignments should be on nibble boundaries

The problem that is SLAAC SLAAC is StateLess Address Auto Configuration SLAAC seemed like a good idea Simplifies readdressing Does not need a DHCPv6 server, only a router SLAAC is a bad idea Removes control Adds vulnerabilities Lack ability to provide added information like: DNS servers NTP servers Fallback gateways Eats the last 64 bits of the address

You Can’t Say “NO!” to SLAAC Inherent in IPv6 design Systems often become RAs by accident Turning it off essentially turns off IPv6 Demand RA-Guard to block rogue RAs

There is little or no basis for this! IPv6 Security It was often claimed that IPv6 has better security than IPv4 There is little or no basis for this! IPv6 implementations have far less testing to find vulnerabilities IPv6 is often not treated correctly by firewalls and filters IPv6 has the dread Next Header system which allows “hiding” malicious headers beyond the reach of most routers Hacker have been using IPv6 for some time and know it well Often not used for hacking, but as a means of hiding activities Ping-pong DOS attacks are often easy But they are easy to prevent/fix

Summary IPv6 generally works well on modern routing equipment Extra fees to run IPv6 are vanishing IPv6 is easy to set up in a backbone Mostly can be handled exactly like IPv4 Your Address plan is important SLAAC is evil (Did I mention RA-Guard?) Many management and security tools are weak or simply don’t support IPv6 IPv6 presents security concerns (though most are similar to IPv4) The hard part of IPv6 is the services Network folks have the easy part