Real World IPv6 Migration Solutions. Asoka De Saram Sr. Director of Systems Engineering, A10 Networks



Similar documents
Carrier Grade NAT. Requirements and Challenges in the Real World. Amir Tabdili Cypress Consulting

A10 Networks IPv6 Overview. November 2011

Transition to IPv6 for Managed Service Providers: Meet Customer Requirements for IP Addressing

WHITE PAPER. Best Practices for Deploying IPv6 over Broadband Access

EXPEDITING ACCESS TO V6 SERVICES: GETTING WEB CONTENT AVAILABLE OVER IPV6 QUICKLY AND AT LOW COST

PowerLink Bandwidth Aggregation Redundant WAN Link and VPN Fail-Over Solutions

TR-296 IPv6 Transition Mechanisms Test Plan

Challenges in NetFlow based Event Logging

IPv4 and IPv6 Integration. Formation IPv6 Workshop Location, Date

Source-Connect Network Configuration Last updated May 2009

464XLAT in mobile networks

IPv6 TRANSITION TECHNOLOGIES

Residential IPv6 IPv6 a t at S wisscom Swisscom a, n an overview overview Martin Gysi

Next Generation IPv6 Network Security a Practical Approach Is Your Firewall Ready for Voice over IPv6?

Smart Tips. Enabling WAN Load Balancing. Key Features. Network Diagram. Overview. Featured Products. WAN Failover. Enabling WAN Load Balancing Page 1

Digi Connect WAN Application Helper NAT, GRE, ESP and TCP/UPD Forwarding and IP Filtering

Securing the Transition Mechanisms

IPv6 deployment status & Migration Strategy

UIP1868P User Interface Guide

Strategies for Getting Started with IPv6

Juniper Networks and IPv6. Tim LeMaster Ipv6.juniper.net

HOSTED VOICE Bring Your Own Bandwidth & Remote Worker. Install and Best Practices Guide

IPv6-only hosts in a dual stack environnment

Multi-Homing Security Gateway

SSVVP SIP School VVoIP Professional Certification

IPv6, Perspective from small to medium ISP

CGN Deployment with MPLS/VPNs

HP and IPv6 Deployment. Bill Medlin HP-UX IPv6 Project Manager

SSVP SIP School VoIP Professional Certification

Networking 4 Voice and Video over IP (VVoIP)

Campus IPv6 connection Campus IPv6 deployment

GPRS / 3G Services: VPN solutions supported

Design and Implementation Guide. Apple iphone Compatibility

WATCHGUARD FIREBOX SOHO 6TC AND SOHO 6

Transition to IPv6 in Service Providers

NAT Tutorial. Dan Wing, IETF78, Maastricht July 25, 2010

ProCurve Networking IPv6 The Next Generation of Networking

MOC 6435A Designing a Windows Server 2008 Network Infrastructure

Ensuring a Smooth Transition to Internet Protocol Version 6 (IPv6)

F5 Silverline DDoS Protection Onboarding: Technical Note

IPV6 DEPLOYMENT GUIDELINES FOR. ARRIS Group, Inc.

How To Use A Cisco Wvvvdns4400N Wireless-N Gigabit Security Router For Small Businesses

How To Connect Xbox 360 Game Consoles to the Router by Ethernet cable (RJ45)?

Hosted Voice. Best Practice Recommendations for VoIP Deployments

Broadband Phone Gateway BPG510 Technical Users Guide

R4: Configuring Windows Server 2008 Network Infrastructure

NetScaler carriergrade network

WAN Traffic Management with PowerLink Pro100

Firewalls und IPv6 worauf Sie achten müssen!

Internet Privacy Options

Cisco WRVS4400N Wireless-N Gigabit Security Router: Cisco Small Business Routers

Cisco Wireless Security Gateway R2

Understanding the Cisco VPN Client

5.0 Network Architecture. 5.1 Internet vs. Intranet 5.2 NAT 5.3 Mobile Network

An Architecture View of Softbank

ITL BULLETIN FOR JANUARY 2011

Edgewater Routers User Guide

NAT and Firewall Traversal with STUN / TURN / ICE

INTRODUCTION TO FIREWALL SECURITY

ALLNET ALL-VPN10. VPN/Firewall WLAN-N WAN Router

Jive Core: Platform, Infrastructure, and Installation

Application Delivery Networking

France Telecom s IPv6 Strategy. C. Jacquenet, M. Sall

Whitepaper IPv6. OpenScape UC Suite IPv6 Transition Strategy

Virtual private network. Network security protocols VPN VPN. Instead of a dedicated data link Packets securely sent over a shared network Internet VPN

Lab Testing Summary Report

VPN. Date: 4/15/2004 By: Heena Patel

MINIMUM NETWORK REQUIREMENTS 1. REQUIREMENTS SUMMARY... 1

Firewalls P+S Linux Router & Firewall 2013

Virtual Private Networks

Unified Services Routers

Matt Ryanczak Network Operations Manager

Aerohive Networks Inc. Free Bonjour Gateway FAQ

Edgewater Routers User Guide

VoIP Reliability in Managed Service Deployments

BT 21CN Network IPv6 Transformation

IPv4/IPv6 Transition Mechanisms. Luka Koršič, Matjaž Straus Istenič

HughesNet Broadband VPN End-to-End Security Enabled by the HN7700S-R

Chapter 5. Data Communication And Internet Technology

Gigabit Multi-Homing VPN Security Router

Cisco RV180 VPN Router

ADTRAN 3120 / 3130 Internet Configuration Guide

Integrate VoIP with your existing network

Load Balance Router R258V

Deploying IPv6 for Service Providers. Benoit Lourdelet IPv6 Product Manager, NSSTG

Copyright 2008 Link Technologies,Inc. A Proud Vendor Member of the

Applications that Benefit from IPv6

Definition of a White Box. Benefits of White Boxes

Appendix A: Configuring Firewalls for a VPN Server Running Windows Server 2003

Deploying IPv6 at Scale As an ISP. Clinton Work Member of the TELUS team October 2015

Firewall Defaults, Public Server Rule, and Secondary WAN IP Address

Chapter 15: Advanced Networks

High Performance VPN Solutions Over Satellite Networks

IPv6 Opportunity and challenge

Cisco Integrated Services Routers Performance Overview

V310 Support Note Version 1.0 November, 2011

1 Basic Configuration of Cisco 2600 Router. Basic Configuration Cisco 2600 Router

Transcription:

Real World IPv6 Migration Solutions Asoka De Saram Sr. Director of Systems Engineering, A10 Networks 1

Agenda Choosing the right solutions Design considerations IPv4 to IPv6 migration road map Consumer side considerations Network Service Provider side considerations Content Provider side considerations 2

What do you have to think about? Choosing the right technology. There are many CGN, NAT64, DS-Lite, SLB-PT, 6rd, More possible in the future Why so many technologies? Every network is different Application requirements Service Level Agreements Comfort level (i.e. stateful vs stateless, maturity of the IPv6 stack) Subscriber base (mobile vs fixed landline) After choosing the right technology How will it scale? What are the performance metrics? Budget considerations 3

Design Considerations Choosing the right network topology Inline mode vs one armed mode Placement of the solution (edge, core vs. aggregation) Security considerations Infrastructure considerations (DNS, DHCP, L2/L3 changes) Proof of Concept Interoperability testing Application testing Performance testing and high availability testing Field User Trials Partial real world testing with friendly subscribers Security assumptions validations Observing application behavior Verifying application requirements 4

IPv6 Migration Techniques Dual-Stack Encapsulation Translation 5

Carrier Grade NAT Topology (NAT444) Two Layers of NAT Customer Premise Equipment NAT (Traditional NAT) Service Provider NAT (CGN) Public IPv4 Internet Carrier Grade NAT Provider Private IPv4 Network CPE NAT CPE NAT Consumer Private IPv4 6

Carrier Grade NAT Topology (NAT44) Single Layer of NAT Provider provisioned end devices Ideal for mobile handsets Public IPv4 Internet Carrier Grade NAT Provider Private IPv4 Network 7

CGN Deployment Topology Inline Mode Public IPv4 Internet Carrier Grade NAT Carrier Grade NAT Internal Network Private IPv4 8

CGN Deployment Topology One Armed Mode Public IPv4 Internet Carrier Grade NAT Carrier Grade NAT Internal Network Private IPv4 9

DS-Lite - Topology IPv4 Content IPv6 Content Native IPv4 Packets IPv4 Core Network / Internet DS-Lite ISP Device (AFTR) IPv6 Network / Internet IPv4-in-IPv6 Tunneled Packets Provider Network IPv6 Native IPv6 Packets IPv6 Address Native IPv4 Packets IPv4 Clients IPv6 Clients 10

SLB-PT Topology IPv4 and IPv6 Servers AX SLB-PT IPv4 VIP AX SLB-PT IPv6 VIP IPv4 Internet IPv6 Internet IPv4 Clients IPv6 Clients 11

NAT64/DNS64 Deployment Topology DNS Server Farm IPv6 Internet IPv6/v4 IPv6 Servers IPv6 Client IPv6 Provider IPv4 Internet NAT64 + DNS64 Synthesis Address Family Translation IPv4 Servers 12

Networking Considerations Fixed Networks (Cable, DSL, Ethernet Networks) Two layers of NAT (Home NAT + Provider NAT) Choice of provider specific private IPv4 addressing critical More subscribers with IPv6 ready devices Higher bandwidth consumption per subscriber More concurrent connections per subscriber Mobile Networks (3G/4G, WiFi Networks) One layer of NAT Choice of Provider specific private IPv4 addressing not as critical Fewer subscribers with IPv6 ready devices Lower bandwidth requirements Low concurrent connections per subscriber 13

Application Considerations Client Server Applications Web Email DNS Application that require special handling Streaming Media (RTSP) File Services (FTP) Voice over IP (SIP) Virtual Private Networking (PPTP, IPSec) Peer to Peer Applications Gaming Instant messaging File sharing 14

Security Considerations Mandating and maintaining the existing security policies How does the migration technology effect security? Standards based approaches IETF Behave TCP IETF Behave UDP How flexible and adaptable is my implementation? What options are available to adjust parameters, for example: End Point Independent Filtering End Point Independent Mapping User quota Address selection mechanisms Various application timers and behaviors Long lived vs short lived (Ex. VPN vs DNS) Peer to peer applications vs client server applications 15

Logging Considerations Required by law enforcement agencies Service Provider Considerations Dynamic vs. Deterministic port allocation Content Provider Considerations Log port number and IPv4 address Consider Logging Impact Performance impact to CGN Storage requirements Data retention requirements Cost of the logging infrastructure (CPU, Disk, Memory) Log Reduction Techniques Hex Logging, and Binary Logging (String size reduction) Batch Logging, Fixed NAT, and Deterministic NAT (Volume reduction) 16

IPv6 Migration Road Map Roadmaps are specific to type of deployments Consumer space Home networks Mobile subscribers Network Service Providers Dual Stack (IPv4 and IPv6) NAT64/DNS64 Tunneling Content Providers and Enterprises SLB-PT IPv4 IPv4 6to4 IPv4 CGN 6rd SLB-PT IPv4 IPv6 CGN DS-Lite SLB-PT NAT64 6rd IPv6 IPv4 NAT64 IPv6 17

Migration Considerations Home Networks Organic upgrades to IPv6 capable systems Wireless Routers, set-top boxes, handsets, laptops, gaming consoles Application availability Customer-premises equipment (DSL, Cable Routers) Service Provider Networks Upgrading the plumbing to support IPv6 Service Provider support infrastructure (provisioning tools) Scalability and performance Dedicated translation technologies Content Provider and Enterprise Side Considerations Number of administrative domains Production grade IPv6 content Service Level Agreements 18

IPv6 in the Enterprise Infrastructure Costs Servers, firewall, routers, switches, and load balancer upgrades Application accessibility and vendor readiness End user requirements new laptops, handsets Business Continuity Seamless migration strategies Minimizing downtime Economics Additional Expenses Return on investment Migration Technologies Dual Stack SLB-PT NAT64 with DNS64 19

Summary Moving to IPv6 is no longer an option Many challenges Many approaches Many different technologies and considerations Progress is happening on many fronts Infrastructure Vendors Service Providers Content Providers Application Vendors Need more commitment and coordination 20

How is A10 involved? Working with many different parties in the transition process Support for many different technologies CGN DS-Lite NAT64/DNS64 NAT46 SLB-PT 6rd Full IPv6 feature parity with IPv4 SLB features Capability to support all these technologies concurrently Flexible, feature-rich, scalable, high performing and adaptable implementation 21

Questions? 22

End Point Independent Filtering Port 8080 Port 1024 Port 8081 Host B Host A Inside Outside Port 8080 Internal External Filter A:1024/B:8080 X:9001/B:8080 *:*/X:9001 Port 8081 Host C 23

Address and Port Dependent Filtering Port 8080 Port 1024 Port 8081 Host B Host A Inside Outside Port 8080 Internal External Filter A:1024/B:8080 X:9001/B:8080 B:8080/X:9001 Port 8081 Host C 24