SlideShare uma empresa Scribd logo
1 de 7
Baixar para ler offline
Dead	
  Men	
  Walking:	
  
 IPv6	
  and	
  DNSSEC	
  
Bill.St.Arnaud@gmail.com	
  
        ION	
  -­‐	
  Toronto	
  	
  
    November	
  14,	
  2011	
  
The	
  IPv6	
  Challenge	
  
•  Despite	
  considerable	
  publicity	
  and	
  predicMons	
  	
  of	
  IPv4	
  address	
  
     Armageddon	
  adopMon	
  of	
  IPv6	
  is	
  anemic	
  
	
  
•  Although	
  IPv6	
  is	
  deployed	
  on	
  many	
  networks,	
  take	
  up	
  by	
  end	
  users/
     devices	
  is	
  slow	
  
	
  
•  Carrier	
  grade	
  NAT	
  seems	
  to	
  be	
  the	
  default	
  path	
  for	
  IPv4	
  exhausMon	
  
       –  RouMng	
  vendors	
  like	
  it	
  because	
  they	
  can	
  sell	
  more	
  complex	
  and	
  expensive	
  
            gear	
  
       –  Carriers	
  like	
  it	
  because	
  they	
  can	
  lock	
  in	
  their	
  customers	
  
       	
  
•  If	
  aSer	
  10	
  years	
  we	
  sMll	
  can’t	
  make	
  IPv6	
  fly,	
  then	
  maybe	
  its	
  Mme	
  to	
  rethink	
  
   our	
  strategy,	
  especially	
  for	
  those	
  of	
  who	
  believe	
  in	
  the	
  original	
  Internet	
  
   vision.	
  	
  Two	
  approaches:	
  
       –  New	
  business	
  models	
  for	
  market	
  adopMon	
  
       –  New	
  technology	
  
New	
  Market	
  AdopMon	
  IPv6	
  
                        SURFnet-­‐KPN	
  pilot	
  
•      Most	
  future	
  internet	
  access	
  will	
  be	
  mobile	
  devices	
  like	
  iPad	
  and	
  iPhone	
  

•      SURFnet-­‐KPN	
  pilot	
  will	
  be	
  world’s	
  fist	
  enterprise	
  centric	
  integrated	
  LTE-­‐mobile	
  
       network	
  	
  -­‐	
  extremely	
  low	
  data	
  prices	
  
	
  
•      SURFnet	
  “leasing	
  /8”	
  to	
  KPN	
  in	
  exchange	
  for	
  pilot	
  on	
  naMonal	
  wireless	
  mobile	
  
       broadband	
  for	
  universiMes	
  and	
  students	
  
	
  
•      SURFmobile	
  will	
  be	
  LTE	
  with	
  IPv6	
  only	
  with	
  integrated	
  campus	
  Wifi	
  at	
  universiMes,	
  
       coffee	
  shops,	
  trains,	
  etc	
  
	
  
•      Will	
  use	
  IPv6	
  Eduroam	
  to	
  allow	
  free	
  internaMonal	
  roaming	
  

•      Other	
  pilots	
  under	
  development	
  in	
  UK,	
  US,	
  Australia,	
  etc.	
  	
  Canada??	
  
	
  
•      h`p://www.blogger.com/blogger.g?blogID=8586756976616257717#editor/
       target=post;postID=2782224431972329057	
  
IPv6	
  alternaMve?	
  
•  Most	
  Internet	
  traffic	
  is	
  not	
  end-­‐to-­‐end	
  
      –  45-­‐90%	
  of	
  traffic	
  terminates	
  at	
  CDN	
  or	
  cloud	
  
      –  Major	
  implicaMon	
  in	
  terms	
  for	
  IPv4/IPv6	
  desMnaMon	
  based	
  rouMng	
  and	
  
           addressing	
  
      	
  
•  Numeric	
  addressing	
  is	
  an	
  anachronism	
  imposed	
  by	
  limitaMons	
  of	
  
     forwarding	
  engine	
  on	
  routers	
  
	
  
•  Possible	
  	
  IPv6	
  alternaMves:	
  
      –  Named	
  Data	
  Networking	
  	
  (NDN)–	
  Van	
  Jacobson	
  
      –  Delay	
  Tolerant	
  Networking	
  (DTN)	
  –	
  Vint	
  Cerf	
  -­‐	
  late	
  binding	
  of	
  DNS	
  +	
  XML	
  
      –  XML	
  rouMng	
  and	
  addressing	
  (W3C)	
  
      	
  
•  h`p://billstarnaud.blogspot.com/2011/11/named-­‐data-­‐networking-­‐how-­‐
   lte-­‐networks.html	
  
DNSSEC	
  –	
  the	
  next	
  IPv6?	
  
•  Again,	
  to	
  us	
  techies,	
  there	
  seems	
  to	
  be	
  a	
  clear	
  and	
  
     compelling	
  need	
  for	
  DNSSEC	
  
	
  
•  Already	
  several	
  events	
  of	
  DNS	
  cache	
  poisoning	
  in	
  Brazil	
  and	
  
     elsewhere	
  
	
  
•  Is	
  signing	
  and	
  delegaMng	
  the	
  root	
  sufficient?	
  

•  Do	
  we	
  just	
  sit	
  back	
  and	
  wait	
  for	
  ISPs	
  and	
  users	
  to	
  adopt?	
  
	
  
•  Or	
  do	
  we	
  try	
  to	
  be	
  more	
  proacMve	
  with	
  new	
  business	
  
     models	
  that	
  make	
  life	
  easier	
  for	
  end	
  users	
  and	
  insMtuMons?	
  
Netherlands	
  pilot	
  to	
  deploy	
  DNSSEC	
  at	
  
                 universiMes	
  
•      Many	
  universiMes	
  in	
  Netherlands	
  starMng	
  to	
  outsource	
  DNS	
  management	
  
	
  
•      SURFdomeinen	
  is	
  a	
  web-­‐based	
  portal	
  that	
  allows	
  DNS	
  operators	
  of	
  connected	
  
       insMtuMons	
  to:	
  
        –  register	
  or	
  migrate	
  domain	
  names	
  in	
  the	
  following	
  top-­‐level	
  domains	
  
             (TLDs):	
  .nl,	
  .com,	
  .net,	
  .org,	
  .info	
  and	
  .eu;	
  
        –  manage	
  contact	
  details	
  for	
  contacts	
  associated	
  with	
  registered	
  domains;	
  
        –  create	
  secondary	
  DNS	
  configuraMons	
  on	
  SURFnet	
  name	
  servers	
  for	
  their	
  domains;	
  
        –  manage	
  complete	
  DNS	
  zones	
  that	
  are	
  then	
  served	
  out	
  by	
  SURFnet	
  name	
  servers.	
  
        –  DNSSEC	
  support	
  has	
  been	
  integrated	
  into	
  the	
  managed	
  DNS	
  funcMonality.	
  
        	
  
•      Not	
  yet	
  deliver	
  a	
  full	
  end-­‐user	
  service	
  due	
  to	
  restricMons	
  imposed	
  by	
  the	
  fact	
  that	
  
       SIDN	
  does	
  not	
  yet	
  have	
  a	
  process	
  for	
  automated	
  submission	
  of	
  secure	
  delegaMons	
  
       (DS)	
  for	
  the	
  .nl	
  zone.	
  

•      h`ps://dnssec.surfnet.nl/wp-­‐content/uploads/2011/01/D1c-­‐DNSSEC-­‐in-­‐
       SURFdomeinen-­‐end-­‐report-­‐v1.0.pdf	
  
Conclusions	
  
•  IPv6	
  and	
  DNNSEC	
  is	
  hard	
  and	
  costly	
  
	
  
•  On	
  its	
  own	
  provides	
  NO	
  new	
  benefits,	
  only	
  protecMon	
  from	
  possible	
  
     real	
  and	
  hypotheMcal	
  negaMve	
  externaliMes	
  
	
  
•  To	
  promote	
  success	
  need	
  to	
  link	
  these	
  technologies	
  to	
  services	
  that	
  
     enable	
  new	
  capabiliMes	
  	
  e.g.	
  
     –  Low	
  cost	
  broadband	
  mobile	
  wireless	
  
     –  Out	
  sourcing	
  DNS	
  management	
  

•  Need	
  funding	
  program	
  and	
  early	
  adopters	
  such	
  as	
  universiMes	
  and	
  
   R&E	
  networks	
  to	
  promote	
  adopMon	
  
     –  A	
  sitng	
  back	
  and	
  hope	
  strategy	
  will	
  not	
  work	
  

Mais conteúdo relacionado

Destaque

Central Asia: Internet Structure and Trends (DYN)
 Central Asia: Internet Structure and Trends (DYN) Central Asia: Internet Structure and Trends (DYN)
Central Asia: Internet Structure and Trends (DYN)Internet Society
 
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...Internet Society
 
BGP and Traffic Engineering with Akamai
BGP and Traffic Engineering with AkamaiBGP and Traffic Engineering with Akamai
BGP and Traffic Engineering with AkamaiInternet Society
 
Peering and Transit Tutorials: Practical Every Day BGP Filtering
Peering and Transit Tutorials: Practical Every Day BGP FilteringPeering and Transit Tutorials: Practical Every Day BGP Filtering
Peering and Transit Tutorials: Practical Every Day BGP FilteringInternet Society
 
Peering Negotiations at AfPIF
Peering Negotiations at AfPIFPeering Negotiations at AfPIF
Peering Negotiations at AfPIFInternet Society
 
IXP Panel: Presentation by DECIX
IXP Panel: Presentation by DECIXIXP Panel: Presentation by DECIX
IXP Panel: Presentation by DECIXInternet Society
 
Internet Exchange Points in the Middle East
Internet Exchange Points in the Middle EastInternet Exchange Points in the Middle East
Internet Exchange Points in the Middle EastInternet Society
 
African Internet Exchange Points
African Internet Exchange PointsAfrican Internet Exchange Points
African Internet Exchange PointsInternet Society
 

Destaque (10)

Central Asia: Internet Structure and Trends (DYN)
 Central Asia: Internet Structure and Trends (DYN) Central Asia: Internet Structure and Trends (DYN)
Central Asia: Internet Structure and Trends (DYN)
 
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...
Mind Your MANRS: Improving the Security and Resilience of the Global Routing ...
 
BGP and Traffic Engineering with Akamai
BGP and Traffic Engineering with AkamaiBGP and Traffic Engineering with Akamai
BGP and Traffic Engineering with Akamai
 
Peering and Transit Tutorials: Practical Every Day BGP Filtering
Peering and Transit Tutorials: Practical Every Day BGP FilteringPeering and Transit Tutorials: Practical Every Day BGP Filtering
Peering and Transit Tutorials: Practical Every Day BGP Filtering
 
Peering Negotiations at AfPIF
Peering Negotiations at AfPIFPeering Negotiations at AfPIF
Peering Negotiations at AfPIF
 
IXP Panel: Presentation by DECIX
IXP Panel: Presentation by DECIXIXP Panel: Presentation by DECIX
IXP Panel: Presentation by DECIX
 
Internet Exchange Points in the Middle East
Internet Exchange Points in the Middle EastInternet Exchange Points in the Middle East
Internet Exchange Points in the Middle East
 
African Internet Exchange Points
African Internet Exchange PointsAfrican Internet Exchange Points
African Internet Exchange Points
 
Peering introductions-2
Peering introductions-2Peering introductions-2
Peering introductions-2
 
Internet ecosystem
Internet ecosystemInternet ecosystem
Internet ecosystem
 

Mais de Internet Society

IXP growth challenges in West Africa: The Ghana Experience
IXP growth challenges in West Africa: The Ghana ExperienceIXP growth challenges in West Africa: The Ghana Experience
IXP growth challenges in West Africa: The Ghana ExperienceInternet Society
 
IXP growth challenges in Central Africa
IXP growth challenges in Central AfricaIXP growth challenges in Central Africa
IXP growth challenges in Central AfricaInternet Society
 
IXP growth challenges in Côte D’Ivoire
IXP growth challenges in Côte D’IvoireIXP growth challenges in Côte D’Ivoire
IXP growth challenges in Côte D’IvoireInternet Society
 
Keynote Presentation : “80/20 by 2020”
Keynote Presentation : “80/20 by 2020”Keynote Presentation : “80/20 by 2020”
Keynote Presentation : “80/20 by 2020”Internet Society
 
International Bandwidth and Pricing Trends in Sub-Sahara Africa
International Bandwidth and Pricing Trends in Sub-Sahara Africa International Bandwidth and Pricing Trends in Sub-Sahara Africa
International Bandwidth and Pricing Trends in Sub-Sahara Africa Internet Society
 
In Search of Low Cost Bandwidth
In Search of Low Cost BandwidthIn Search of Low Cost Bandwidth
In Search of Low Cost BandwidthInternet Society
 
“BIG” IXP Jedi and TraceMON: RIPE Atlas tools in Africa
“BIG” IXP Jedi and TraceMON: RIPE Atlas tools in Africa“BIG” IXP Jedi and TraceMON: RIPE Atlas tools in Africa
“BIG” IXP Jedi and TraceMON: RIPE Atlas tools in AfricaInternet Society
 
Looking for Latency Clusters in Africa's internet
Looking for Latency Clusters in Africa's internetLooking for Latency Clusters in Africa's internet
Looking for Latency Clusters in Africa's internetInternet Society
 
Fantsuam: Ideas for the sustainability of Community Networks
Fantsuam: Ideas for the sustainability of Community NetworksFantsuam: Ideas for the sustainability of Community Networks
Fantsuam: Ideas for the sustainability of Community NetworksInternet Society
 
Mawingu: Ideas for the sustainability of Community Networks
Mawingu: Ideas for the sustainability of Community NetworksMawingu: Ideas for the sustainability of Community Networks
Mawingu: Ideas for the sustainability of Community NetworksInternet Society
 
Zenzeleni Networks Update Report
Zenzeleni Networks Update ReportZenzeleni Networks Update Report
Zenzeleni Networks Update ReportInternet Society
 
Canadian Victory Garden: Overview of an Off Grid Solution
Canadian Victory Garden: Overview of an Off Grid SolutionCanadian Victory Garden: Overview of an Off Grid Solution
Canadian Victory Garden: Overview of an Off Grid SolutionInternet Society
 

Mais de Internet Society (20)

IXP growth challenges in West Africa: The Ghana Experience
IXP growth challenges in West Africa: The Ghana ExperienceIXP growth challenges in West Africa: The Ghana Experience
IXP growth challenges in West Africa: The Ghana Experience
 
IXP growth challenges in Central Africa
IXP growth challenges in Central AfricaIXP growth challenges in Central Africa
IXP growth challenges in Central Africa
 
Benin IX: 3 Years After!
Benin IX: 3 Years After!Benin IX: 3 Years After!
Benin IX: 3 Years After!
 
IXP growth challenges in Côte D’Ivoire
IXP growth challenges in Côte D’IvoireIXP growth challenges in Côte D’Ivoire
IXP growth challenges in Côte D’Ivoire
 
IXP Masterclass
IXP MasterclassIXP Masterclass
IXP Masterclass
 
PeeringDB Updates
PeeringDB UpdatesPeeringDB Updates
PeeringDB Updates
 
Peering Personals #2
Peering Personals #2Peering Personals #2
Peering Personals #2
 
Keynote Presentation : “80/20 by 2020”
Keynote Presentation : “80/20 by 2020”Keynote Presentation : “80/20 by 2020”
Keynote Presentation : “80/20 by 2020”
 
International Bandwidth and Pricing Trends in Sub-Sahara Africa
International Bandwidth and Pricing Trends in Sub-Sahara Africa International Bandwidth and Pricing Trends in Sub-Sahara Africa
International Bandwidth and Pricing Trends in Sub-Sahara Africa
 
In Search of Low Cost Bandwidth
In Search of Low Cost BandwidthIn Search of Low Cost Bandwidth
In Search of Low Cost Bandwidth
 
IPv6 @ Cloudflare
IPv6 @ CloudflareIPv6 @ Cloudflare
IPv6 @ Cloudflare
 
Interconnection Evolution
Interconnection EvolutionInterconnection Evolution
Interconnection Evolution
 
Peering Personals #1
Peering Personals #1Peering Personals #1
Peering Personals #1
 
“BIG” IXP Jedi and TraceMON: RIPE Atlas tools in Africa
“BIG” IXP Jedi and TraceMON: RIPE Atlas tools in Africa“BIG” IXP Jedi and TraceMON: RIPE Atlas tools in Africa
“BIG” IXP Jedi and TraceMON: RIPE Atlas tools in Africa
 
Looking for Latency Clusters in Africa's internet
Looking for Latency Clusters in Africa's internetLooking for Latency Clusters in Africa's internet
Looking for Latency Clusters in Africa's internet
 
Fantsuam: Ideas for the sustainability of Community Networks
Fantsuam: Ideas for the sustainability of Community NetworksFantsuam: Ideas for the sustainability of Community Networks
Fantsuam: Ideas for the sustainability of Community Networks
 
Mawingu: Ideas for the sustainability of Community Networks
Mawingu: Ideas for the sustainability of Community NetworksMawingu: Ideas for the sustainability of Community Networks
Mawingu: Ideas for the sustainability of Community Networks
 
Zenzeleni Networks Update Report
Zenzeleni Networks Update ReportZenzeleni Networks Update Report
Zenzeleni Networks Update Report
 
Canadian Victory Garden: Overview of an Off Grid Solution
Canadian Victory Garden: Overview of an Off Grid SolutionCanadian Victory Garden: Overview of an Off Grid Solution
Canadian Victory Garden: Overview of an Off Grid Solution
 
TVWS use case in Kenya
TVWS use case in KenyaTVWS use case in Kenya
TVWS use case in Kenya
 

Último

Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical InfrastructureVarsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructureitnewsafrica
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsRavi Sanghani
 
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfpanagenda
 
All These Sophisticated Attacks, Can We Really Detect Them - PDF
All These Sophisticated Attacks, Can We Really Detect Them - PDFAll These Sophisticated Attacks, Can We Really Detect Them - PDF
All These Sophisticated Attacks, Can We Really Detect Them - PDFMichael Gough
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPathCommunity
 
Infrared simulation and processing on Nvidia platforms
Infrared simulation and processing on Nvidia platformsInfrared simulation and processing on Nvidia platforms
Infrared simulation and processing on Nvidia platformsYoss Cohen
 
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sectoritnewsafrica
 
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...panagenda
 
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Nikki Chapple
 
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxfnnc6jmgwh
 
React Native vs Ionic - The Best Mobile App Framework
React Native vs Ionic - The Best Mobile App FrameworkReact Native vs Ionic - The Best Mobile App Framework
React Native vs Ionic - The Best Mobile App FrameworkPixlogix Infotech
 
React JS; all concepts. Contains React Features, JSX, functional & Class comp...
React JS; all concepts. Contains React Features, JSX, functional & Class comp...React JS; all concepts. Contains React Features, JSX, functional & Class comp...
React JS; all concepts. Contains React Features, JSX, functional & Class comp...Karmanjay Verma
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...Wes McKinney
 
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...itnewsafrica
 
Irene Moetsana-Moeng: Stakeholders in Cybersecurity: Collaborative Defence fo...
Irene Moetsana-Moeng: Stakeholders in Cybersecurity: Collaborative Defence fo...Irene Moetsana-Moeng: Stakeholders in Cybersecurity: Collaborative Defence fo...
Irene Moetsana-Moeng: Stakeholders in Cybersecurity: Collaborative Defence fo...itnewsafrica
 
Accelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with PlatformlessAccelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with PlatformlessWSO2
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesBernd Ruecker
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentPim van der Noll
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Strongerpanagenda
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality AssuranceInflectra
 

Último (20)

Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical InfrastructureVarsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
Varsha Sewlal- Cyber Attacks on Critical Critical Infrastructure
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and Insights
 
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdfSo einfach geht modernes Roaming fuer Notes und Nomad.pdf
So einfach geht modernes Roaming fuer Notes und Nomad.pdf
 
All These Sophisticated Attacks, Can We Really Detect Them - PDF
All These Sophisticated Attacks, Can We Really Detect Them - PDFAll These Sophisticated Attacks, Can We Really Detect Them - PDF
All These Sophisticated Attacks, Can We Really Detect Them - PDF
 
UiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to HeroUiPath Community: Communication Mining from Zero to Hero
UiPath Community: Communication Mining from Zero to Hero
 
Infrared simulation and processing on Nvidia platforms
Infrared simulation and processing on Nvidia platformsInfrared simulation and processing on Nvidia platforms
Infrared simulation and processing on Nvidia platforms
 
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector
4. Cobus Valentine- Cybersecurity Threats and Solutions for the Public Sector
 
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
Why device, WIFI, and ISP insights are crucial to supporting remote Microsoft...
 
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
 
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
 
React Native vs Ionic - The Best Mobile App Framework
React Native vs Ionic - The Best Mobile App FrameworkReact Native vs Ionic - The Best Mobile App Framework
React Native vs Ionic - The Best Mobile App Framework
 
React JS; all concepts. Contains React Features, JSX, functional & Class comp...
React JS; all concepts. Contains React Features, JSX, functional & Class comp...React JS; all concepts. Contains React Features, JSX, functional & Class comp...
React JS; all concepts. Contains React Features, JSX, functional & Class comp...
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
 
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
 
Irene Moetsana-Moeng: Stakeholders in Cybersecurity: Collaborative Defence fo...
Irene Moetsana-Moeng: Stakeholders in Cybersecurity: Collaborative Defence fo...Irene Moetsana-Moeng: Stakeholders in Cybersecurity: Collaborative Defence fo...
Irene Moetsana-Moeng: Stakeholders in Cybersecurity: Collaborative Defence fo...
 
Accelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with PlatformlessAccelerating Enterprise Software Engineering with Platformless
Accelerating Enterprise Software Engineering with Platformless
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architectures
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
 

Dead Men Walking: IPv6 & DNSSEC (ION Toronto 2011)

  • 1. Dead  Men  Walking:   IPv6  and  DNSSEC   Bill.St.Arnaud@gmail.com   ION  -­‐  Toronto     November  14,  2011  
  • 2. The  IPv6  Challenge   •  Despite  considerable  publicity  and  predicMons    of  IPv4  address   Armageddon  adopMon  of  IPv6  is  anemic     •  Although  IPv6  is  deployed  on  many  networks,  take  up  by  end  users/ devices  is  slow     •  Carrier  grade  NAT  seems  to  be  the  default  path  for  IPv4  exhausMon   –  RouMng  vendors  like  it  because  they  can  sell  more  complex  and  expensive   gear   –  Carriers  like  it  because  they  can  lock  in  their  customers     •  If  aSer  10  years  we  sMll  can’t  make  IPv6  fly,  then  maybe  its  Mme  to  rethink   our  strategy,  especially  for  those  of  who  believe  in  the  original  Internet   vision.    Two  approaches:   –  New  business  models  for  market  adopMon   –  New  technology  
  • 3. New  Market  AdopMon  IPv6   SURFnet-­‐KPN  pilot   •  Most  future  internet  access  will  be  mobile  devices  like  iPad  and  iPhone   •  SURFnet-­‐KPN  pilot  will  be  world’s  fist  enterprise  centric  integrated  LTE-­‐mobile   network    -­‐  extremely  low  data  prices     •  SURFnet  “leasing  /8”  to  KPN  in  exchange  for  pilot  on  naMonal  wireless  mobile   broadband  for  universiMes  and  students     •  SURFmobile  will  be  LTE  with  IPv6  only  with  integrated  campus  Wifi  at  universiMes,   coffee  shops,  trains,  etc     •  Will  use  IPv6  Eduroam  to  allow  free  internaMonal  roaming   •  Other  pilots  under  development  in  UK,  US,  Australia,  etc.    Canada??     •  h`p://www.blogger.com/blogger.g?blogID=8586756976616257717#editor/ target=post;postID=2782224431972329057  
  • 4. IPv6  alternaMve?   •  Most  Internet  traffic  is  not  end-­‐to-­‐end   –  45-­‐90%  of  traffic  terminates  at  CDN  or  cloud   –  Major  implicaMon  in  terms  for  IPv4/IPv6  desMnaMon  based  rouMng  and   addressing     •  Numeric  addressing  is  an  anachronism  imposed  by  limitaMons  of   forwarding  engine  on  routers     •  Possible    IPv6  alternaMves:   –  Named  Data  Networking    (NDN)–  Van  Jacobson   –  Delay  Tolerant  Networking  (DTN)  –  Vint  Cerf  -­‐  late  binding  of  DNS  +  XML   –  XML  rouMng  and  addressing  (W3C)     •  h`p://billstarnaud.blogspot.com/2011/11/named-­‐data-­‐networking-­‐how-­‐ lte-­‐networks.html  
  • 5. DNSSEC  –  the  next  IPv6?   •  Again,  to  us  techies,  there  seems  to  be  a  clear  and   compelling  need  for  DNSSEC     •  Already  several  events  of  DNS  cache  poisoning  in  Brazil  and   elsewhere     •  Is  signing  and  delegaMng  the  root  sufficient?   •  Do  we  just  sit  back  and  wait  for  ISPs  and  users  to  adopt?     •  Or  do  we  try  to  be  more  proacMve  with  new  business   models  that  make  life  easier  for  end  users  and  insMtuMons?  
  • 6. Netherlands  pilot  to  deploy  DNSSEC  at   universiMes   •  Many  universiMes  in  Netherlands  starMng  to  outsource  DNS  management     •  SURFdomeinen  is  a  web-­‐based  portal  that  allows  DNS  operators  of  connected   insMtuMons  to:   –  register  or  migrate  domain  names  in  the  following  top-­‐level  domains   (TLDs):  .nl,  .com,  .net,  .org,  .info  and  .eu;   –  manage  contact  details  for  contacts  associated  with  registered  domains;   –  create  secondary  DNS  configuraMons  on  SURFnet  name  servers  for  their  domains;   –  manage  complete  DNS  zones  that  are  then  served  out  by  SURFnet  name  servers.   –  DNSSEC  support  has  been  integrated  into  the  managed  DNS  funcMonality.     •  Not  yet  deliver  a  full  end-­‐user  service  due  to  restricMons  imposed  by  the  fact  that   SIDN  does  not  yet  have  a  process  for  automated  submission  of  secure  delegaMons   (DS)  for  the  .nl  zone.   •  h`ps://dnssec.surfnet.nl/wp-­‐content/uploads/2011/01/D1c-­‐DNSSEC-­‐in-­‐ SURFdomeinen-­‐end-­‐report-­‐v1.0.pdf  
  • 7. Conclusions   •  IPv6  and  DNNSEC  is  hard  and  costly     •  On  its  own  provides  NO  new  benefits,  only  protecMon  from  possible   real  and  hypotheMcal  negaMve  externaliMes     •  To  promote  success  need  to  link  these  technologies  to  services  that   enable  new  capabiliMes    e.g.   –  Low  cost  broadband  mobile  wireless   –  Out  sourcing  DNS  management   •  Need  funding  program  and  early  adopters  such  as  universiMes  and   R&E  networks  to  promote  adopMon   –  A  sitng  back  and  hope  strategy  will  not  work