SlideShare uma empresa Scribd logo
1 de 9
Baixar para ler offline
US	
  Federal	
  IPv6	
  Deployments	
  

                 ION	
  San	
  Diego	
  
                      11	
  Dec,	
  2012	
  
                      San	
  Diego,	
  CA	
  
                               	
  


                   Ron	
  Broersma	
  
              DREN	
  Chief	
  Engineer	
  
        SPAWAR	
  Network	
  Security	
  Manager	
  
            Federal	
  IPv6	
  Task	
  Force	
  
             ron@spawar.navy.mil	
  
US	
  Federal	
  IPv6	
  Status	
  
•  NIST	
  IPv6	
  Deployment	
  Monitor	
  
                      hOp://fedv6-­‐deployment.antd.nist.gov/	
  




11-­‐Dec-­‐2012	
                                                   2	
  
Looking	
  forward	
  
•  What	
  is	
  the	
  incenSve	
  to	
  keep	
  the	
  pressure	
  on	
  
   aTer	
  the	
  deadline?	
  
          –  .gov	
  domains	
  will	
  not	
  be	
  renewed	
  if	
  that	
  
             organizaSon	
  has	
  not	
  met	
  the	
  mandates	
  for	
  IPv6	
  
             (and	
  maybe	
  DNSSEC	
  as	
  well).	
  
          –  Other	
  organizaSons	
  should	
  consider	
  similar	
  
             incenSves	
  



11-­‐Dec-­‐2012	
                                                                     3	
  
Top	
  Enterprise	
  Deployment	
  Challenges	
  
•  Lack	
  of	
  IPv6/IPv4	
  feature	
  parity	
  
          –  taking	
  way	
  too	
  long	
  to	
  get	
  there	
  
•  Vendors	
  not	
  eaSng	
  own	
  dogfood	
  
          –  but	
  this	
  is	
  starSng	
  to	
  change	
  
•  Rogue	
  RAs	
  due	
  to	
  Windows	
  ICS	
  
          –  set	
  router	
  priority	
  to	
  “high”	
  as	
  workaround	
  
•  Privacy	
  Addresses	
  (RFC4941)	
  break	
  address	
  stability	
  
          –  no	
  easy	
  way	
  to	
  centrally	
  disable	
  
•  Lack	
  of	
  DHCPv6	
  client	
  support	
  in	
  older	
  OS’s	
  
•  Network	
  Management	
  over	
  IPv6	
  not	
  quite	
  there	
  
•  OperaSonal	
  Complexity	
  with	
  dual-­‐stack	
  



11-­‐Dec-­‐2012	
                                                                4	
  
Keys	
  to	
  success	
  
•  Clear	
  simple	
  achievable	
  vision	
  and	
  mandate,	
  with	
  
   deadlines,	
  from	
  the	
  top	
  (CIO)	
  
•  Responsibility,	
  accountability,	
  and	
  authority	
  established	
  
   and	
  managed	
  at	
  the	
  execuSve	
  level	
  
•  Public	
  reporSng	
  of	
  status	
  along	
  the	
  way,	
  both	
  internally	
  
   and	
  externally	
  
•  Bring	
  in	
  experts	
  that	
  have	
  IPv6	
  operaSonal	
  experience,	
  if	
  
   you	
  don’t	
  have	
  it	
  organically	
  in	
  your	
  organizaSon.	
  	
  
•  Early	
  (and	
  consistent)	
  interacSon	
  with	
  service	
  and	
  
   technology	
  providers,	
  to	
  communicate	
  requirements.	
  	
  
          –  and	
  be	
  willing	
  to	
  switch	
  providers	
  to	
  acquire	
  IPv6	
  support	
  
•  Dual-­‐stack	
  support	
  from	
  ISP(s)	
  

11-­‐Dec-­‐2012	
                                                                                        5	
  
Benefits	
  of	
  IPv6	
  today	
  (examples)	
  
•  Addressing	
  
          –      can	
  beOer	
  map	
  subnets	
  to	
  reality	
  
          –      can	
  align	
  with	
  security	
  topology,	
  simplifying	
  ACLs	
  
          –      sparse	
  addressing	
  (harder	
  to	
  scan/map)	
  
          –      never	
  have	
  to	
  worry	
  about	
  “growing”	
  a	
  subnet	
  to	
  hold	
  new	
  machines	
  
          –      auto-­‐configuraSon,	
  plug-­‐n-­‐play	
  
          –      universal	
  subnet	
  size,	
  no	
  surprises,	
  no	
  operator	
  confusion,	
  no	
  bitmath	
  
          –      shorter	
  addresses	
  in	
  some	
  cases	
  
          –      at	
  home:	
  mulSple	
  subnets	
  rather	
  than	
  single	
  IP	
  that	
  you	
  have	
  to	
  NAT	
  
•  Link	
  Local	
  address	
  on	
  every	
  interface	
  
•  MulScast	
  is	
  simpler	
  
          –  embedded	
  RP	
  
          –  no	
  MSDP	
  
•  Mobile	
  IPv6	
  is	
  cleaner/simpler	
  than	
  in	
  IPv4	
  



11-­‐Dec-­‐2012	
                                                                                                              6	
  
IPv6-­‐Only	
  Management	
  LAN	
  
Management	
  over	
  IPv6	
  in	
  some	
  products	
  

                SSH         DNS   Syslog   SNMP         NTP           RADIUS             TFTP          Flow     Unified MIB   CDP    IPv6   No v4
                HTTPS                                                                    FTP           export   RFC4293       LLDP   MTU

Cisco3                                                                                                      6
Brocade1                                                                                                                               9
Juniper                                                                                                     5
ALU                                                                                                         4
A10                                                                                                         7
Aruba




                                            1.    Can’t	
  reboot	
  using	
  SNMP	
  over	
  IPv6	
  
                                            2.    	
  .	
  
                                            3.    	
  15.2(2)TR	
  
                                            4.    	
  10.0R6	
  (Nov	
  2012)	
  
                                            5.    	
  12.3R1	
  Nov	
  2012	
  (beta	
  in	
  August)	
  
                                            6.    	
  ASR1K:3.7S	
  (July	
  2012)	
  
                                            7.    	
  3.0	
  release,	
  2012Q4	
  
                                            8.    No	
  plans	
  
                                            9.    fix	
  planned	
  for	
  Apr	
  2013	
  


      11-­‐Dec-­‐2012	
                                                                                                                        8	
  
END	
  

Contact	
  me:	
  	
  ron@spawar.navy.mil	
  

Mais conteúdo relacionado

Mais procurados

Configuration & Routing of Clos Networks
Configuration & Routing of Clos NetworksConfiguration & Routing of Clos Networks
Configuration & Routing of Clos NetworksCumulus Networks
 
Инновации Cisco для операторов связи
Инновации Cisco для операторов связиИнновации Cisco для операторов связи
Инновации Cisco для операторов связиCisco Russia
 
BIND’s New Security Feature: DNSRPZ - the "DNS Firewall"
BIND’s New Security Feature: DNSRPZ - the "DNS Firewall"BIND’s New Security Feature: DNSRPZ - the "DNS Firewall"
BIND’s New Security Feature: DNSRPZ - the "DNS Firewall"Barry Greene
 
Webinar: Network Automation [Tips & Tricks]
Webinar: Network Automation [Tips & Tricks]Webinar: Network Automation [Tips & Tricks]
Webinar: Network Automation [Tips & Tricks]Cumulus Networks
 
Network Architecture for Containers
Network Architecture for ContainersNetwork Architecture for Containers
Network Architecture for ContainersCumulus Networks
 
Implementing an IPv6 Enabled Environment for a Public Cloud Tenant
Implementing an IPv6 Enabled Environment for a Public Cloud TenantImplementing an IPv6 Enabled Environment for a Public Cloud Tenant
Implementing an IPv6 Enabled Environment for a Public Cloud TenantShixiong Shang
 
State of the Dolphin, at db tech showcase Osaka 2014
State of the Dolphin, at db tech showcase Osaka 2014State of the Dolphin, at db tech showcase Osaka 2014
State of the Dolphin, at db tech showcase Osaka 2014Ryusuke Kajiyama
 
Inside Microsoft's FPGA-Based Configurable Cloud
Inside Microsoft's FPGA-Based Configurable CloudInside Microsoft's FPGA-Based Configurable Cloud
Inside Microsoft's FPGA-Based Configurable Cloudinside-BigData.com
 
NFD9 - Dinesh Dutt, Data Center Architectures
NFD9 - Dinesh Dutt, Data Center ArchitecturesNFD9 - Dinesh Dutt, Data Center Architectures
NFD9 - Dinesh Dutt, Data Center ArchitecturesCumulus Networks
 
High Availability != High-cost
High Availability != High-costHigh Availability != High-cost
High Availability != High-costnormanmaurer
 
SDN - OpenFlow + OpenVSwitch + Quantum
SDN - OpenFlow + OpenVSwitch + QuantumSDN - OpenFlow + OpenVSwitch + Quantum
SDN - OpenFlow + OpenVSwitch + QuantumThe Linux Foundation
 
Scality, Cloud Storage pour Zimbra
Scality, Cloud Storage pour ZimbraScality, Cloud Storage pour Zimbra
Scality, Cloud Storage pour ZimbraAntony Barroux
 
Running a Local Copy of the DNS Root Zone
Running a Local Copy of the DNS Root ZoneRunning a Local Copy of the DNS Root Zone
Running a Local Copy of the DNS Root ZoneAPNIC
 
OpenStack Neutron IPv6 Lessons
OpenStack Neutron IPv6 LessonsOpenStack Neutron IPv6 Lessons
OpenStack Neutron IPv6 LessonsAkihiro Motoki
 
Solaris cluster roadshow day 1 technical presentation
Solaris cluster roadshow day 1 technical presentationSolaris cluster roadshow day 1 technical presentation
Solaris cluster roadshow day 1 technical presentationxKinAnx
 
Solaris cluster roadshow day 2 technical presentation
Solaris cluster roadshow day 2 technical presentationSolaris cluster roadshow day 2 technical presentation
Solaris cluster roadshow day 2 technical presentationxKinAnx
 

Mais procurados (20)

Configuration & Routing of Clos Networks
Configuration & Routing of Clos NetworksConfiguration & Routing of Clos Networks
Configuration & Routing of Clos Networks
 
suresh-linux-v7
suresh-linux-v7suresh-linux-v7
suresh-linux-v7
 
Инновации Cisco для операторов связи
Инновации Cisco для операторов связиИнновации Cisco для операторов связи
Инновации Cisco для операторов связи
 
BIND’s New Security Feature: DNSRPZ - the "DNS Firewall"
BIND’s New Security Feature: DNSRPZ - the "DNS Firewall"BIND’s New Security Feature: DNSRPZ - the "DNS Firewall"
BIND’s New Security Feature: DNSRPZ - the "DNS Firewall"
 
Webinar: Network Automation [Tips & Tricks]
Webinar: Network Automation [Tips & Tricks]Webinar: Network Automation [Tips & Tricks]
Webinar: Network Automation [Tips & Tricks]
 
Network Architecture for Containers
Network Architecture for ContainersNetwork Architecture for Containers
Network Architecture for Containers
 
Implementing an IPv6 Enabled Environment for a Public Cloud Tenant
Implementing an IPv6 Enabled Environment for a Public Cloud TenantImplementing an IPv6 Enabled Environment for a Public Cloud Tenant
Implementing an IPv6 Enabled Environment for a Public Cloud Tenant
 
State of the Dolphin, at db tech showcase Osaka 2014
State of the Dolphin, at db tech showcase Osaka 2014State of the Dolphin, at db tech showcase Osaka 2014
State of the Dolphin, at db tech showcase Osaka 2014
 
Inside Microsoft's FPGA-Based Configurable Cloud
Inside Microsoft's FPGA-Based Configurable CloudInside Microsoft's FPGA-Based Configurable Cloud
Inside Microsoft's FPGA-Based Configurable Cloud
 
NFD9 - Dinesh Dutt, Data Center Architectures
NFD9 - Dinesh Dutt, Data Center ArchitecturesNFD9 - Dinesh Dutt, Data Center Architectures
NFD9 - Dinesh Dutt, Data Center Architectures
 
Dnssec
DnssecDnssec
Dnssec
 
High Availability != High-cost
High Availability != High-costHigh Availability != High-cost
High Availability != High-cost
 
SDN - OpenFlow + OpenVSwitch + Quantum
SDN - OpenFlow + OpenVSwitch + QuantumSDN - OpenFlow + OpenVSwitch + Quantum
SDN - OpenFlow + OpenVSwitch + Quantum
 
Scality, Cloud Storage pour Zimbra
Scality, Cloud Storage pour ZimbraScality, Cloud Storage pour Zimbra
Scality, Cloud Storage pour Zimbra
 
Running a Local Copy of the DNS Root Zone
Running a Local Copy of the DNS Root ZoneRunning a Local Copy of the DNS Root Zone
Running a Local Copy of the DNS Root Zone
 
OpenStack Neutron IPv6 Lessons
OpenStack Neutron IPv6 LessonsOpenStack Neutron IPv6 Lessons
OpenStack Neutron IPv6 Lessons
 
Solaris cluster roadshow day 1 technical presentation
Solaris cluster roadshow day 1 technical presentationSolaris cluster roadshow day 1 technical presentation
Solaris cluster roadshow day 1 technical presentation
 
IPv6 Security und Hacking
IPv6 Security und HackingIPv6 Security und Hacking
IPv6 Security und Hacking
 
Solaris cluster roadshow day 2 technical presentation
Solaris cluster roadshow day 2 technical presentationSolaris cluster roadshow day 2 technical presentation
Solaris cluster roadshow day 2 technical presentation
 
Managing IPv6 Deployments
Managing IPv6 DeploymentsManaging IPv6 Deployments
Managing IPv6 Deployments
 

Destaque

Las Novedades Que Nos Ofrece El Eurocentro
Las Novedades Que Nos Ofrece El EurocentroLas Novedades Que Nos Ofrece El Eurocentro
Las Novedades Que Nos Ofrece El Eurocentroguest6e89ba
 
Hot Issues in Cyberspace: 10 Things You Should Know About Online Advertising
Hot Issues in Cyberspace: 10 Things You Should Know About Online AdvertisingHot Issues in Cyberspace: 10 Things You Should Know About Online Advertising
Hot Issues in Cyberspace: 10 Things You Should Know About Online AdvertisingInternet Law Center
 
Książka a strange story - Dominique Imbert i Focus
Książka a strange story - Dominique Imbert i FocusKsiążka a strange story - Dominique Imbert i Focus
Książka a strange story - Dominique Imbert i FocusKoperfam Sp. z o.o.
 
Premio integra. bbva.
Premio integra. bbva.Premio integra. bbva.
Premio integra. bbva.José María
 
Community manager-maestros-del-web
Community manager-maestros-del-webCommunity manager-maestros-del-web
Community manager-maestros-del-webJavier SaaDapart
 
Piensa. Manuel Palma
Piensa. Manuel PalmaPiensa. Manuel Palma
Piensa. Manuel PalmaIbero Puebla
 
Louisiana Channel
Louisiana ChannelLouisiana Channel
Louisiana ChannelMariPou
 
Servicios STS
Servicios STSServicios STS
Servicios STScaessars
 
E-commerce Paris 2013 - De l'email tactique au programme d'email marketing ar...
E-commerce Paris 2013 - De l'email tactique au programme d'email marketing ar...E-commerce Paris 2013 - De l'email tactique au programme d'email marketing ar...
E-commerce Paris 2013 - De l'email tactique au programme d'email marketing ar...Contactlab
 
Catalogo CABLAS 2015 - Schermature Antix e Accessori per Radiologia
Catalogo CABLAS 2015 - Schermature Antix e Accessori per RadiologiaCatalogo CABLAS 2015 - Schermature Antix e Accessori per Radiologia
Catalogo CABLAS 2015 - Schermature Antix e Accessori per RadiologiaCABLAS
 
Sociedades produtoras revolução neolític a
Sociedades produtoras                    revolução neolític aSociedades produtoras                    revolução neolític a
Sociedades produtoras revolução neolític aTeresa Maia
 
Infosys – Hi Tech Order Management Distribution Planning Solution - Case Study
Infosys – Hi Tech Order Management Distribution Planning Solution - Case StudyInfosys – Hi Tech Order Management Distribution Planning Solution - Case Study
Infosys – Hi Tech Order Management Distribution Planning Solution - Case StudyInfosys
 
Solar Decathlon 17.04.2014 @ TIS | David Calas (LISI on tour)
Solar Decathlon 17.04.2014 @ TIS | David Calas (LISI on tour)Solar Decathlon 17.04.2014 @ TIS | David Calas (LISI on tour)
Solar Decathlon 17.04.2014 @ TIS | David Calas (LISI on tour)IDM Südtirol - Alto Adige
 
2015 Trafigura Responsibility Report
2015 Trafigura Responsibility Report 2015 Trafigura Responsibility Report
2015 Trafigura Responsibility Report Trafigura
 
Escenario de colvatel(etb)
Escenario de colvatel(etb)Escenario de colvatel(etb)
Escenario de colvatel(etb)uniminuto
 

Destaque (20)

Las Novedades Que Nos Ofrece El Eurocentro
Las Novedades Que Nos Ofrece El EurocentroLas Novedades Que Nos Ofrece El Eurocentro
Las Novedades Que Nos Ofrece El Eurocentro
 
Hot Issues in Cyberspace: 10 Things You Should Know About Online Advertising
Hot Issues in Cyberspace: 10 Things You Should Know About Online AdvertisingHot Issues in Cyberspace: 10 Things You Should Know About Online Advertising
Hot Issues in Cyberspace: 10 Things You Should Know About Online Advertising
 
Książka a strange story - Dominique Imbert i Focus
Książka a strange story - Dominique Imbert i FocusKsiążka a strange story - Dominique Imbert i Focus
Książka a strange story - Dominique Imbert i Focus
 
CV. Luis J. Vega
CV. Luis J. VegaCV. Luis J. Vega
CV. Luis J. Vega
 
Premio integra. bbva.
Premio integra. bbva.Premio integra. bbva.
Premio integra. bbva.
 
Himno de la enfermera
Himno de la enfermeraHimno de la enfermera
Himno de la enfermera
 
Community manager-maestros-del-web
Community manager-maestros-del-webCommunity manager-maestros-del-web
Community manager-maestros-del-web
 
R
RR
R
 
Tutorial app
Tutorial appTutorial app
Tutorial app
 
Piensa. Manuel Palma
Piensa. Manuel PalmaPiensa. Manuel Palma
Piensa. Manuel Palma
 
Louisiana Channel
Louisiana ChannelLouisiana Channel
Louisiana Channel
 
Servicios STS
Servicios STSServicios STS
Servicios STS
 
E-commerce Paris 2013 - De l'email tactique au programme d'email marketing ar...
E-commerce Paris 2013 - De l'email tactique au programme d'email marketing ar...E-commerce Paris 2013 - De l'email tactique au programme d'email marketing ar...
E-commerce Paris 2013 - De l'email tactique au programme d'email marketing ar...
 
Actividad1
Actividad1Actividad1
Actividad1
 
Catalogo CABLAS 2015 - Schermature Antix e Accessori per Radiologia
Catalogo CABLAS 2015 - Schermature Antix e Accessori per RadiologiaCatalogo CABLAS 2015 - Schermature Antix e Accessori per Radiologia
Catalogo CABLAS 2015 - Schermature Antix e Accessori per Radiologia
 
Sociedades produtoras revolução neolític a
Sociedades produtoras                    revolução neolític aSociedades produtoras                    revolução neolític a
Sociedades produtoras revolução neolític a
 
Infosys – Hi Tech Order Management Distribution Planning Solution - Case Study
Infosys – Hi Tech Order Management Distribution Planning Solution - Case StudyInfosys – Hi Tech Order Management Distribution Planning Solution - Case Study
Infosys – Hi Tech Order Management Distribution Planning Solution - Case Study
 
Solar Decathlon 17.04.2014 @ TIS | David Calas (LISI on tour)
Solar Decathlon 17.04.2014 @ TIS | David Calas (LISI on tour)Solar Decathlon 17.04.2014 @ TIS | David Calas (LISI on tour)
Solar Decathlon 17.04.2014 @ TIS | David Calas (LISI on tour)
 
2015 Trafigura Responsibility Report
2015 Trafigura Responsibility Report 2015 Trafigura Responsibility Report
2015 Trafigura Responsibility Report
 
Escenario de colvatel(etb)
Escenario de colvatel(etb)Escenario de colvatel(etb)
Escenario de colvatel(etb)
 

Semelhante a ION San Diego - US Federal IPv6 Deployments

Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011IPv6no
 
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...gogo6
 
Ipv6 neighbor discovery problems and mitigations
Ipv6 neighbor discovery problems and mitigationsIpv6 neighbor discovery problems and mitigations
Ipv6 neighbor discovery problems and mitigationsKarunakant Rai
 
IPv6 Neighbor Discovery Problems (and mitigations)
IPv6 Neighbor Discovery Problems (and mitigations)IPv6 Neighbor Discovery Problems (and mitigations)
IPv6 Neighbor Discovery Problems (and mitigations)Juniper Networks
 
Rapid IPv6 Deployment for ISP Networks
Rapid IPv6 Deployment for ISP NetworksRapid IPv6 Deployment for ISP Networks
Rapid IPv6 Deployment for ISP NetworksSkeeve Stevens
 
Sipforum SIP & IPv6 discussion slides
Sipforum SIP & IPv6 discussion slidesSipforum SIP & IPv6 discussion slides
Sipforum SIP & IPv6 discussion slidesOlle E Johansson
 
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...gogo6
 
Transition to ipv6 cgv6-edited
Transition to ipv6  cgv6-editedTransition to ipv6  cgv6-edited
Transition to ipv6 cgv6-editedFred Bovy
 
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn FortinetDigicomp Academy AG
 
IPv6 Security - Workshop mit Live Demo
IPv6 Security - Workshop mit Live DemoIPv6 Security - Workshop mit Live Demo
IPv6 Security - Workshop mit Live DemoDigicomp Academy AG
 
DPDK Summit - 08 Sept 2014 - 6WIND - High Perf Networking Leveraging the DPDK...
DPDK Summit - 08 Sept 2014 - 6WIND - High Perf Networking Leveraging the DPDK...DPDK Summit - 08 Sept 2014 - 6WIND - High Perf Networking Leveraging the DPDK...
DPDK Summit - 08 Sept 2014 - 6WIND - High Perf Networking Leveraging the DPDK...Jim St. Leger
 
BigData Clusters Redefined
BigData Clusters RedefinedBigData Clusters Redefined
BigData Clusters RedefinedDataWorks Summit
 
Introduction to DPDK
Introduction to DPDKIntroduction to DPDK
Introduction to DPDKKernel TLV
 
12.00 - Dr. Tim Chown - University of Southampton
12.00 - Dr. Tim Chown - University of Southampton12.00 - Dr. Tim Chown - University of Southampton
12.00 - Dr. Tim Chown - University of SouthamptonIPv6 Summit 2010
 
AusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other Observations
AusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other ObservationsAusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other Observations
AusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other ObservationsMark Smith
 

Semelhante a ION San Diego - US Federal IPv6 Deployments (20)

Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011
 
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
 
IPv6 at CSCS
IPv6 at CSCSIPv6 at CSCS
IPv6 at CSCS
 
Ipv6 neighbor discovery problems and mitigations
Ipv6 neighbor discovery problems and mitigationsIpv6 neighbor discovery problems and mitigations
Ipv6 neighbor discovery problems and mitigations
 
IPv6 Neighbor Discovery Problems (and mitigations)
IPv6 Neighbor Discovery Problems (and mitigations)IPv6 Neighbor Discovery Problems (and mitigations)
IPv6 Neighbor Discovery Problems (and mitigations)
 
Rapid IPv6 Deployment for ISP Networks
Rapid IPv6 Deployment for ISP NetworksRapid IPv6 Deployment for ISP Networks
Rapid IPv6 Deployment for ISP Networks
 
Sipforum SIP & IPv6 discussion slides
Sipforum SIP & IPv6 discussion slidesSipforum SIP & IPv6 discussion slides
Sipforum SIP & IPv6 discussion slides
 
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
 
Transition to ipv6 cgv6-edited
Transition to ipv6  cgv6-editedTransition to ipv6  cgv6-edited
Transition to ipv6 cgv6-edited
 
Deploying IPv6 on OpenStack
Deploying IPv6 on OpenStackDeploying IPv6 on OpenStack
Deploying IPv6 on OpenStack
 
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
 
IPv6 Security - Workshop mit Live Demo
IPv6 Security - Workshop mit Live DemoIPv6 Security - Workshop mit Live Demo
IPv6 Security - Workshop mit Live Demo
 
DPDK Summit - 08 Sept 2014 - 6WIND - High Perf Networking Leveraging the DPDK...
DPDK Summit - 08 Sept 2014 - 6WIND - High Perf Networking Leveraging the DPDK...DPDK Summit - 08 Sept 2014 - 6WIND - High Perf Networking Leveraging the DPDK...
DPDK Summit - 08 Sept 2014 - 6WIND - High Perf Networking Leveraging the DPDK...
 
Presd1 09
Presd1 09Presd1 09
Presd1 09
 
BigData Clusters Redefined
BigData Clusters RedefinedBigData Clusters Redefined
BigData Clusters Redefined
 
6Rd
6Rd6Rd
6Rd
 
Introduction to DPDK
Introduction to DPDKIntroduction to DPDK
Introduction to DPDK
 
12.00 - Dr. Tim Chown - University of Southampton
12.00 - Dr. Tim Chown - University of Southampton12.00 - Dr. Tim Chown - University of Southampton
12.00 - Dr. Tim Chown - University of Southampton
 
AusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other Observations
AusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other ObservationsAusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other Observations
AusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other Observations
 
implementing IPv6 in an ISP network, case study and lessons learned - Amos Ro...
implementing IPv6 in an ISP network, case study and lessons learned - Amos Ro...implementing IPv6 in an ISP network, case study and lessons learned - Amos Ro...
implementing IPv6 in an ISP network, case study and lessons learned - Amos Ro...
 

Mais de Deploy360 Programme (Internet Society)

Mais de Deploy360 Programme (Internet Society) (20)

ION Belgrade - Jordi Palet Martinez IPv6 Success Stories
ION Belgrade - Jordi Palet Martinez IPv6 Success StoriesION Belgrade - Jordi Palet Martinez IPv6 Success Stories
ION Belgrade - Jordi Palet Martinez IPv6 Success Stories
 
ION Belgrade - ISOC Serbia Belgrade Chapter Presentation
ION Belgrade - ISOC Serbia Belgrade Chapter PresentationION Belgrade - ISOC Serbia Belgrade Chapter Presentation
ION Belgrade - ISOC Serbia Belgrade Chapter Presentation
 
ION Belgrade - IETF Update
ION Belgrade - IETF UpdateION Belgrade - IETF Update
ION Belgrade - IETF Update
 
ION Belgrade - Opening Slides
ION Belgrade - Opening SlidesION Belgrade - Opening Slides
ION Belgrade - Opening Slides
 
ION Belgrade - MANRS by Serbian Open eXchange (SOX)
ION Belgrade - MANRS by Serbian Open eXchange (SOX)ION Belgrade - MANRS by Serbian Open eXchange (SOX)
ION Belgrade - MANRS by Serbian Open eXchange (SOX)
 
ION Belgrade - Closing Slides
ION Belgrade - Closing SlidesION Belgrade - Closing Slides
ION Belgrade - Closing Slides
 
AusNOG - Two Years of Good MANRS
AusNOG - Two Years of Good MANRSAusNOG - Two Years of Good MANRS
AusNOG - Two Years of Good MANRS
 
ION Malta - IETF Update
ION Malta - IETF UpdateION Malta - IETF Update
ION Malta - IETF Update
 
ION Malta - MANRS Introduction
ION Malta - MANRS IntroductionION Malta - MANRS Introduction
ION Malta - MANRS Introduction
 
ION Malta - Introduction to DNSSEC
ION Malta - Introduction to DNSSECION Malta - Introduction to DNSSEC
ION Malta - Introduction to DNSSEC
 
ION Malta - DANE: The Future of TLS
ION Malta - DANE: The Future of TLSION Malta - DANE: The Future of TLS
ION Malta - DANE: The Future of TLS
 
ION Malta - IANA Transition Roles & Accountability
ION Malta - IANA Transition Roles & AccountabilityION Malta - IANA Transition Roles & Accountability
ION Malta - IANA Transition Roles & Accountability
 
ION Malta - IPv6 Case Study: Finland
ION Malta - IPv6 Case Study: FinlandION Malta - IPv6 Case Study: Finland
ION Malta - IPv6 Case Study: Finland
 
ION Malta - Seeweb Thoughts on IPv6 Transition
ION Malta - Seeweb Thoughts on IPv6 TransitionION Malta - Seeweb Thoughts on IPv6 Transition
ION Malta - Seeweb Thoughts on IPv6 Transition
 
ION Malta - Seeweb Why MANRS is good for you
ION Malta - Seeweb Why MANRS is good for youION Malta - Seeweb Why MANRS is good for you
ION Malta - Seeweb Why MANRS is good for you
 
ION Malta - Opening Slides
ION Malta - Opening SlidesION Malta - Opening Slides
ION Malta - Opening Slides
 
ION Malta - Closing Slides
ION Malta - Closing SlidesION Malta - Closing Slides
ION Malta - Closing Slides
 
ION Durban - How peering behaviour affects growth of the internet
ION Durban - How peering behaviour affects growth of the internetION Durban - How peering behaviour affects growth of the internet
ION Durban - How peering behaviour affects growth of the internet
 
ION Durban - Introduction to ISOC Gauteng Chapter
ION Durban - Introduction to ISOC Gauteng ChapterION Durban - Introduction to ISOC Gauteng Chapter
ION Durban - Introduction to ISOC Gauteng Chapter
 
ION Durban - What's Happening at the IETF?
ION Durban - What's Happening at the IETF?ION Durban - What's Happening at the IETF?
ION Durban - What's Happening at the IETF?
 

ION San Diego - US Federal IPv6 Deployments

  • 1. US  Federal  IPv6  Deployments   ION  San  Diego   11  Dec,  2012   San  Diego,  CA     Ron  Broersma   DREN  Chief  Engineer   SPAWAR  Network  Security  Manager   Federal  IPv6  Task  Force   ron@spawar.navy.mil  
  • 2. US  Federal  IPv6  Status   •  NIST  IPv6  Deployment  Monitor   hOp://fedv6-­‐deployment.antd.nist.gov/   11-­‐Dec-­‐2012   2  
  • 3. Looking  forward   •  What  is  the  incenSve  to  keep  the  pressure  on   aTer  the  deadline?   –  .gov  domains  will  not  be  renewed  if  that   organizaSon  has  not  met  the  mandates  for  IPv6   (and  maybe  DNSSEC  as  well).   –  Other  organizaSons  should  consider  similar   incenSves   11-­‐Dec-­‐2012   3  
  • 4. Top  Enterprise  Deployment  Challenges   •  Lack  of  IPv6/IPv4  feature  parity   –  taking  way  too  long  to  get  there   •  Vendors  not  eaSng  own  dogfood   –  but  this  is  starSng  to  change   •  Rogue  RAs  due  to  Windows  ICS   –  set  router  priority  to  “high”  as  workaround   •  Privacy  Addresses  (RFC4941)  break  address  stability   –  no  easy  way  to  centrally  disable   •  Lack  of  DHCPv6  client  support  in  older  OS’s   •  Network  Management  over  IPv6  not  quite  there   •  OperaSonal  Complexity  with  dual-­‐stack   11-­‐Dec-­‐2012   4  
  • 5. Keys  to  success   •  Clear  simple  achievable  vision  and  mandate,  with   deadlines,  from  the  top  (CIO)   •  Responsibility,  accountability,  and  authority  established   and  managed  at  the  execuSve  level   •  Public  reporSng  of  status  along  the  way,  both  internally   and  externally   •  Bring  in  experts  that  have  IPv6  operaSonal  experience,  if   you  don’t  have  it  organically  in  your  organizaSon.     •  Early  (and  consistent)  interacSon  with  service  and   technology  providers,  to  communicate  requirements.     –  and  be  willing  to  switch  providers  to  acquire  IPv6  support   •  Dual-­‐stack  support  from  ISP(s)   11-­‐Dec-­‐2012   5  
  • 6. Benefits  of  IPv6  today  (examples)   •  Addressing   –  can  beOer  map  subnets  to  reality   –  can  align  with  security  topology,  simplifying  ACLs   –  sparse  addressing  (harder  to  scan/map)   –  never  have  to  worry  about  “growing”  a  subnet  to  hold  new  machines   –  auto-­‐configuraSon,  plug-­‐n-­‐play   –  universal  subnet  size,  no  surprises,  no  operator  confusion,  no  bitmath   –  shorter  addresses  in  some  cases   –  at  home:  mulSple  subnets  rather  than  single  IP  that  you  have  to  NAT   •  Link  Local  address  on  every  interface   •  MulScast  is  simpler   –  embedded  RP   –  no  MSDP   •  Mobile  IPv6  is  cleaner/simpler  than  in  IPv4   11-­‐Dec-­‐2012   6  
  • 8. Management  over  IPv6  in  some  products   SSH DNS Syslog SNMP NTP RADIUS TFTP Flow Unified MIB CDP IPv6 No v4 HTTPS FTP export RFC4293 LLDP MTU Cisco3 6 Brocade1 9 Juniper 5 ALU 4 A10 7 Aruba 1.  Can’t  reboot  using  SNMP  over  IPv6   2.   .   3.   15.2(2)TR   4.   10.0R6  (Nov  2012)   5.   12.3R1  Nov  2012  (beta  in  August)   6.   ASR1K:3.7S  (July  2012)   7.   3.0  release,  2012Q4   8.  No  plans   9.  fix  planned  for  Apr  2013   11-­‐Dec-­‐2012   8  
  • 9. END   Contact  me:    ron@spawar.navy.mil