Internetdagarna 2008: DNSSEC and IPv6 deployment workshop 20 October 2008 Norra Latin, Stockholm IPv6 Golden Networks Jeroen Massar, SixXS

Slides:



Advertisements
Similar presentations
Software Version: DSS ver up01
Advertisements

1 © 2001, Cisco Systems, Inc. Updated_ Mobile IP Lessons Learned The early years.
MCT620 – Distributed Systems
Network Layer Delivery Forwarding and Routing
Computer Networks TCP/IP Protocol Suite.
IPv6 Transition Roque Gagliano What is transition? IPv4 only.IPv4 Only Bone is borned IPv4 Only Experimental IPv6. Majority:
Stacking it Up Experimental Observations on the operation of Dual Stack Services in todays Network Geoff Huston APNIC R&D February
Stacking it Up Experimental Observations on the operation of Dual Stack Services Geoff Huston IETF-80 March
ARIN Public Policy Meeting
Measuring IPv6 Deployment Geoff Huston George Michaelson
1 An Update on Multihoming in IPv6 Report on IETF Activity IPv6 Technical SIG 1 Sept 2004 APNIC18, Nadi, Fiji Geoff Huston.
Network Monitoring System In CSTNET Long Chun China Science & Technology Network.
1 IPv6 Development in China Xing Li Outline l A brief history l Experience l CNGI project l CERNET2 design.
Security Issues In Mobile IP
IPv6 deployment at Netnod (Nurani streaming Kurtis - but slower and without an Åland accent…) Who is Netnod? –IXP in Sweden, operator of i.root-servers.net,
APNIC IPv6 Allocation Update IPv6 Technical SIG APRICOT, Bangkok 5 March 2002.
Multihoming and Multi-path Routing
Planning Your Conversion from IPv4 to IPv6 John Curran ARIN President & CEO This presentation describes the impending depletion of Internet Protocol version.
Deploying IPv6: The time is now Are you ready? SFTA 24 May 2012 John Curran President and CEO, ARIN.
IPv6: No Longer Optional John Curran President & CEO, ARIN.
Demystifying IPv6: Ensuring a Smooth Transition John Curran ARIN President & CEO This presentation describes the impending depletion of Internet Protocol.
Spearheading Internet technology and policy development in the African Region Resource Services Report.
Stacking it Up Experimental Observations on the operation of Dual Stack Services Geoff Huston IETF-80 March
Title Subtitle.
1 Linux IP Masquerading Brian Vargyas XNet Information Systems.
Fred P. Baker CCIE, CCIP(security), CCSA, MCSE+I, MCSE(2000)
Internet Number Resources 1. Internet IPv4 addresses IPv6 addresses Autonomous System number Fully Qualified Domain Name Key Internet resources.
Protocol layers and Wireshark Rahul Hiran TDTS11:Computer Networks and Internet Protocols 1 Note: T he slides are adapted and modified based on slides.
Jennifer Rexford Princeton University MW 11:00am-12:20pm Logically-Centralized Control COS 597E: Software Defined Networking.
SAVI Requirements and Solutions for ISP IPv6 Access Network ISP-access-01.txt.
Chapter 1: Introduction to Scaling Networks
Local Area Networks - Internetworking
The Platform as a Service Model for Networking Eric Keller, Jennifer Rexford Princeton University INM/WREN 2010.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Chapter 8: Subnetting IP Networks Network Fundamentals.
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v MPLS VPN Technology Introducing MPLS VPN Architecture.
Christophe Jelger – CS221 Network and Security - Universität Basel Christophe Jelger Post-doctoral researcher IP Multicasting.
© 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 1 © 2010 Cisco and/or its affiliates. All rights reserved. LISP Mobility.
IP Multicast Information management 2 Groep T Leuven – Information department 2/14 Agenda •Why IP Multicast ? •Multicast fundamentals •Intradomain.
Chapter 20 Network Layer: Internet Protocol
1 Network Address Translation (NAT) Relates to Lab 7. Module about private networks and NAT.
The TCP/IP Model  Internet Protocol Address.  Defined By IANA [Internet Assigned Number Authority] in  IP Address is a Logical Address and it.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 EN0129 PC AND NETWORK TECHNOLOGY I IP ADDRESSING AND SUBNETS Derived From CCNA Network Fundamentals.
IPv6 Routing.
1 © 2004, Cisco Systems, Inc. All rights reserved. CCNA 1 v3.1 Module 10 Routing Fundamentals and Subnets.
DMZ (De-Militarized Zone)
DMZ (De-Militarized Zone)
06-Sep-2006Copyright (C) 2006 Internet Initiative Japan Inc.1 Prevent DoS using IP source address spoofing MATSUZAKI ‘maz’ Yoshinobu.
Bringing IPv6 connectivity to the general public.
RIPE 44: IPv6 WG 29 January 2003 Hotel Krasnapolsky, Amsterdam Jeroen Massar
Internetdagarna October 2008 Folkets Hus, Stockholm IPv6 Golden Networks Jeroen Massar, SixXS /
IPv6 Activities and Update in Thailand Sinchai Kamolphiwong IPv6 Forum Thailand IPv6 WG, UniNet NGI.
Chapter 9: Subnetting IP Networks
25 seconds left…...
44212: Web-site Development
© 2006 Cisco Systems, Inc. All rights reserved. MPLS v2.2—5-1 MPLS VPN Implementation Configuring BGP as the Routing Protocol Between PE and CE Routers.
1 © 2003, Cisco Systems, Inc. All rights reserved. CCNA TCP/IP Protocol Suite and IP Addressing Halmstad University Olga Torstensson
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
1 © 2004, Cisco Systems, Inc. All rights reserved. CCNA 1 v3.1 Module 9 TCP/IP Protocol Suite and IP Addressing.
Mirjam Kühne 1 RIPE 34, September 1999 RIPE NCC Status RIPE NCC Staff presented by Mirjam Kühne.
TCP/IP Protocol Suite 1 Chapter 18 Upon completion you will be able to: Remote Login: Telnet Understand how TELNET works Understand the role of NVT in.
IPv6-Kongress 2014 An I.P.V. SixXS Overview Jeroen Massar, SixXS
NANOG February 2010 Austin, Texas, USA IPv6 Golden Networks Jeroen Massar, SixXS /
Summary of Certification Process (part 1). IPv6 Client IPv6 packets inside IPv4 packets.
Internetdagarna October 2008 Folkets Hus, Stockholm IPv6 Golden Networks Jeroen Massar, SixXS /
Ch 6: IPv6 Deployment Last modified Topics 6.3 Transition Mechanisms 6.4 Dual Stack IPv4/IPv6 Environments 6.5 Tunneling.
RIPE 46: IPv6 WG 03 September 2003 Hotel Krasnapolsky, Amsterdam Jeroen Massar IPv6 Routing Table Anomalies.
ITP 457 Network Security Networking Technologies III IP, Subnets & NAT.
IPv6 Security Issues Georgios Koutepas, NTUA IPv6 Technology and Advanced Services Oct.19, 2004.
Practice Test Questions QUESTION 1 Which two actions must you perform to enable and use window scaling on a router? (Choose two.) A. Execute the.
CIS 82 Routing Protocols and Concepts Chapter 11 NAT
Presentation transcript:

Internetdagarna 2008: DNSSEC and IPv6 deployment workshop 20 October 2008 Norra Latin, Stockholm IPv6 Golden Networks Jeroen Massar, SixXS / IPv6 - real life operations and experience with customers

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::2 SixXS Service for providing ISPs with a quick way of enabling their user base with IPv6. Tunnel Broker PoPs in Belgium, Estonia, Finland, Germany, Ireland, Italy, The Netherlands, New Zealand, Norway, Poland, Portugal, Slovenia, Sweden, Switzerland, United Kingdom and the United States. Thanks to all the ISPs who are providing these PoPs, as without them it would not be possible to do this! FAQ, Wiki and Forum active users and tunnels active subnets (/48’s).

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::3 Protocol 41 Protocol 41 = IPv6 It specifies how to put an IPv6 packet inside IPv4. Protocol 41 is static only. Protocol 41 doesn’t cross NATs.

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::4 Heartbeat Dynamic/non-24/7 IPv4 endpoints. Proto-41 is static. The moment the user unplugs, another user can get that IPv4 address. That user then gets proto-41 packets and the firewall tool beeps with warnings, which sometimes results in abuse reports because we are attacking them. Allows one to move around proto-41 tunnels automatically or enable/disable them on the fly.

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::5 AYIYA – Anything in Anything Proto-41 tunnels can’t cross NATs. Proto-41 tunnels are not authenticated. (read: one can spoof them easily) Heartbeat runs next-to the proto-41 tunnel. Heartbeat might work, proto-41 might not. AYIYA solves these issues by tunneling IPv6 inside IPv4/UDP and signing these packets.

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::6 AICCU Automatic IPv6 Connectivity Client Utility Proto-41, heartbeat and AYIYA tunnels. Windows GUI, Debian Debconf, CLI. Currently a small “Test” mode for diagnosing common issues, testing at least that the basics work. Soon: Public AYIYA/DNS support. Comprehensive “test” mode. GUI for all platforms.

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::7 IPv6Gate Allows access to any IPv4 website over IPv6 from IPv6-only hosts. Also allows the reverse: IPv6-only site from IPv4-only host:

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::8 RFC ULA IPv6 ULA (Unique Local Address) RFC4193 Registration fd00::/8 ULA Locally Assigned. It is Unique, but maybe not Unique enough as it has a chance that it is not. fc00::/8 ULA “Registered” – not specified and thus can’t be used. Nearly 200 registrations Of course not guaranteed, when people don’t check this list it can’t be.

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::9 GRH – Ghost Route Hunter Peers actively with over 150 ISPs around the world. A tool for detecting and hunting down Ghost Routes in the IPv6 routing tables and displaying DFP availability. Distributed Looking Glass Missing Prefixes Prefix Comparison

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::10 GRH - Sweden Sweden (.se) has: 52 IPv6 DFPs. 2 (3.85%) reclaimed (6BONE). 2 (3.85%) returned (6BONE). 26 (50.00%) unannounced. 22 (42.31%) announced. Contains I.root-server.net prefix First RIR prefixes allocated in 2000 to SWIPNET and SUNET.

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::11 Top 10 IPv6 Problems On special request…. The top 10 IPv6 Problems (actually just a grab out of a somewhat bottomless pit, and it really depends on what kind of problems one is looking at (user, administrator), thus a top 2000 would be more appropriate)

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::12 Top 10 IPv6 Problems ::0 ISP/upstream doesn’t want/do IPv6 Bug them a lot and hope you carry enough weight

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::13 Top 10 IPv6 Problems ::1 No IPv6 hardware/software support When you find a program which doesn’t support IPv6, patch it, I do {check the about->license page of PuTTY and various others} Read: “Porting applications to IPv6 by Eva M. Castro”:

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::14 Top 10 IPv6 Problems ::2 Firewall blocks packets completely Can happen on the local host (some firewall product properly drop anything not IPv4 and not explicitly allowed)

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::15 Top 10 IPv6 Problems ::3 IPv4 NAT Protocol-41 doesn’t travel over NATs

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::16 Top 10 IPv6 Problems ::4 6to4 Packets flow in two directions, but are also tunneled, thus issues can arise on the path from and to the hosts in IPv4 and IPv6, where both can be even made more difficult to diagnose due to routing issues On top of that the 6to4 IPv4 address is anycasted, which makes it even more fun to figure out where a problem might be.

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::17 Top 10 IPv6 Problems ::5 ICMP Packet Too Large Filtered by a Firewall Causes your TCP connection to hang when the packet is too large, and thus gets dropped. Easy to recognize symptom though.

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::18 Top 10 IPv6 Problems ::6 IPv6 is slow! DNS relay/server implementation in the NAT box drops AAAA requests

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::19 Top 10 IPv6 Problems ::7 Longest Distance Routing The winners for the first annual Longest Distance Routing contest are: 2001:256::/ at km flowing through Australia, US, Africa, US, and China. Unfortunately, this one is not correct, TENET has a router in NY, and though their network is African these packets are not being shipped to Africa and back to the US again. 2001:200:a000::/ , , , 2500 at km 2001:200:a000::/ , 26943, , , , 2500 at km going through The Netherlands, US, Japan, US, and Japan. These two take the internal network of Your.org, so these two doesn't count either, although they are getting pretty long! But these though are most likely pretty accurate: 2001:200:a000::/ , 3257, 3549, 6939, , , 2500 at km flowing through Ireland, Germany, Netherlands, US, Japan, US and Japan. 2001:200:a000::/ , 3549, 6939, , , 2500 at km flowing through Switzerland, Netherlands, US, Japan, US, and Japan.

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::20 Top 10 IPv6 Problems ::8 Subnet anycast address ::/127 ::0 = subnet anycast address ::1 the only IP left This is why one should either use a /126 if one wants to be really minimalist in “wasting” address space, or just use a /64 like advised by the IETF.

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::21 Top 10 IPv6 Problems ::9 L2 Switch doesn’t handle multicast properly And even though you are trying only to do unicast IPv6, you need multicast IPv6 for Neighbor Discovery (ND) and Duplicate Address Detection (DAD), Router Advertisements (RA) etc, thus if multicast on L2 doesn’t work, IPv6 won’t easily work. (generic solution btw is to set the interface to PROMISC mode)

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::22 Top 10 IPv6 Problems ::a

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::23 Really Nasty IPv6 Problems Multihoming for “small sites” / endusers Mobility Traffic Engineering Multicast … But these problems make it fun to do networking, as where would be without a challenge?

Jeroen Massar – Internetdagarna 2008 : DNSSEC and IPv6 deployment workshop ::24 Questions? Jeroen Massar JRM1-RIPE