some of you may have seen my last
blog post
about the preparation of the Troopers network. Today I want to give you a little
teaser on what to expect for the
talk
I will present during the IPv6 Security Summit. As the title implies, it’s not
only about building a secure IPv6 WiFi, but also a reliable one. One might think
that there aren’t many differences in comparison to IPv4, but the heavy reliance
on multicast of IPv6 does have implications for Wi-Fi networks in general.
I am currently preparing the Troopers network in a
lab environment to ensure that we all will have a smooth Wi-Fi experience during
Troopers. I wanted to spice things up a little bit for the Wi-Fi deployment
(more on that in a following blogpost) and get rid of IPv4 wherever possible.
Our Wi-Fi infrastructure consists of typical Cisco Access Points (1602) and a
2504 Wireless LAN Controller. Beginning with WLC image 8.0 it is finally
supported to establish the CAPWAP tunnel between the AP and the WLC over IPv6,
which is awesome and I wanted to implement it right away.
Troopers is right around the corner and as
I am responsible for the whole conference network I wanted to make sure that
everything is working as expected. I went to the venue on Friday because of two
things I wanted/needed to setup. Compared to last year’s setup we had a couple
of changes in regards to the provider connection (resulting in some changes for
our network setup). First, we now have a rather big pipe for the uplink and more
importantly (well that depends on the point of view ;)) there is a native IPv6
connection. Before that I had to tunnel all IPv6 traffic from the venue to one
of our gateways and to forward it out (as native IPv6) from there. As this step
isn’t necessary anymore, and the staff on the venue isn’t that experienced with
IPv6, I had in mind to setup and verify that IPv6 is working as desired. The
router used over there is a
Mikrotek Routerboard. As I haven’t
worked with these devices before, I was curious whether everything works as it
should ;).
Given that Enno and I are network geeks, and that I am responsible for setting
up the Troopers Wifi network I was curious
which components might be used at Cisco Live and which IPv6 related
configuration was done for the Wifi network to ensure a reliable network and
reduce the chatty nature of IPv6. Andrew Yourtchenko
(@ayourtch) already did an amazing job last year
at Cisco Live Europe explaining in detail (at the time
session BRKEWN-2666) the
intricacies of IPv6 in Wifi networks, and how to optimize IPv6 for these
networks. He was also a great inspiration for me when setting up the
Troopers Wifi network
a couple of weeks later. Thank You!
I know I am a bit late with this post, but I was speaking on the
North American IPv6 Summit
in Denver three weeks ago. The focus of my talk was on
Why IPv6 Security is hard – Structural Deficits of IPv6 & Their Implications
(slightly modified/updated from the
Troopers IPv6 Security Summit).
We consider the NA IPv6 Summit as one of the most important IPv6 events at all
and we were happy to contribute to the overall success. The conference was
organized for the 7^(th) time by the
Rocky Mountain IPv6 Task Force and took place in the
Grand Hyatt Denver (37th floor ;-)). Luckily the weather was perfect, and the
view of the landscape from the conference rooms was just amazing. I really
enjoyed the time in Denver, as the organizer sdid all they could to treat the
speaker well J. The talks were of mix of regular research or case-study type
talks and some sponsored talks ranging from deployment experience, security and
statistics to SDN (Yes, I said it ;)) and the Internet of Things (I said it
again ;)). The line-up was nicely put together.
I recently stumbled over a
document from
Microsoft which lists all services/applications that support IPv6. Most of the
content wasn’t new for me, but one item caught my attention. Windows Update. I
haven’t heard before that Windows Update can be done over IPv6 (but this could
just be me not looking hard enough ;)), so I was eager to test it out seeing if
this is really the case. I was also curious why Microsoft referenced this
document
in the respective column.
Some of you may already know (the ones who are following Enno on
Twitter) that Enno and I had our lab day
in preparation for the
IPv6 Security Summit
at Troopers. We had a brand new and shiny Cat4948E
as our lab device to do some testing of the current generation of Cisco’s IPv6
First Hop Security (FHS) mechanisms. The Catalyst was running the latest image
available (15.1(2)SG3).
In this small blog post, we will take a look at the configuration and behavior
of IPv6 Snooping and DHCPv6 Guard. So let’s start with IPv6 Snooping:
I am little bit late to the party, but I had the pleasure to present a talk
about VoIP based toll fraud incidents (more on this in a following blogpost, for
the moment my slides can be found
here) at the
annual t2 security conference in Helsinki. The conference took
place from 24th to 25th October in the Radisson Blu Royal hotel. I must say that
it was a blast. Tomi (the host) took really good care of all speakers, and I
really liked the spirit of the conference, very similar to
Troopers. It is not an commercial event, seats are
limited to 100 and it is all about delivering a
great set of talks to the audience and having a
good time during and after the conference. Sure the conference has some sponsors
and tickets are sold, but Tomi doesn’t do it to earn money. His only intention
is to cover the cost for setting up this great event.
Last week I read about the new networking features of the integrated vSwitch of
Hyper-V 3.0. I was quite surprised that RA Guard will be natively supported and
was curious about implementation and functionality. If you don’t know how RA
Guard works, I recommend reading our previous blog posts
here,
here,
here,
here
and
here,
or have a look at our workshop at
Troopers12.
I downloaded Windows Server 2012 RC to do some practical testing. Since my
girlfriend was working the whole weekend, I had plenty of time to play around
with all that stuff without risking trouble 😉
TROOPERS12 came to an end last week on Friday; needless to say it was an
awesome event. 😉
The first two days offered workshops on various topics. On Monday Enno,
Marc “Van Hauser” Heuse and I gave a one day workshop on
“Advanced IPv6 Security”. I think attendees as well as trainers had a real good
time during and after the workshop fiddling around with IPv6. Especially Marc
had quite some fun as he discovered that we provided “global” IPv6 Connectivity
for the conference network, and according to one of his tweets, TROOPERS12 was
the first security conference he visited, offering this kind of connectivity.