This is meant to be the first part of a 3-part series discussing the space &
types of IP addresses, with a particular focus on what has changed between IPv4
and IPv6. In this first post I’ll take the audience through a historical tour of
some developments within the IPv4 address space.
In a second part I’ll discuss the properties of different types of addresses
from a routing and from a security perspective, both in the IPv4 and in the IPv6
space. In the third part we’ll look at the implications of deploying IPv6 in
certain networks based on those differences, e.g. “how to handle ACLs and IP
address based log analysis approaches in a dual-stack network where systems have
one RFC 1918 IPv4 address and multiple IPv6 GUAs?” (for specific reasons the
latter two parts might be published on another medium though). In any case let’s
start with a brief history of IPv4. The goal here is to understand how we got to
the state that we have today.
In some organizations we work with a certain state of IPv6 deployment has been
reached in the interim which includes, among others, the following aspects:
the network infrastructure is IPv6-enabled (incl. interface addressing,
routing [protocols] and the like).
parts of supporting services (security functions, monitoring, system
management) include IPv6 in a proper way.
3rd party providers have been contractually obliged to deliver their services
in an “IPv6-enabled” mode (as opposed to only being “IPv6-capable” which was
the standard requirement in many RFIs during earlier years).
It might then happen that networking people (who often are the initial
motivators for deploying IPv6) in such organizations are stating, when asked
about IPv6: “it’s [mostly] done”.
Point is that, alas, this does not necessarily mean that a single service or
application is *actually using* IPv6, so while the above certainly constitutes
an achievement it might not even be halfway through.
In this post I’ll cover some properties of the Windows Server 2019 IPv6 stack.
It is an update of a similar post I wrote on the
IPv6 properties of Server 2016
a while ago.
For this reason I will mostly look at the same properties I did at the time
(read: at times without providing too much technical background information;
that can be found in the other post) and I’ve hence performed the same types of
practical tests.
This week Chris and I participated in the RIPE 78
meeting in Reykjavík. Being part of the group was fun as always and we had quite
some interesting conversations with peers from (not only) the IPv6 community.
Big thanks to the RIPE NCC team for the smooth
organization and for taking care of us!
In this post I’ll provide some notes on talks I found particularly interesting,
plus links to our own contributions.
Chris and I will give a tutorial on the above
topic at next week’s RIPE Meeting in Reykjavík. In
this post (actually this will probably become a small series of posts) I’ll try
to summarize some thoughts on IPv6 security in enterprise environments in 2019.
We’re going to cover three main areas:
Why IPv6 Is Different, Security-wise
Traffic Filtering in IPv6 Networks
IPv6 Security in L2 Networks / First Hop Security et al.
Let’s start with the first item. In real-life scenarios the security of “a
protocol” – IPv6 can rather be considered a “protocol family” which includes
helper protocols like ICMPv6 and MLD (which in turn is implemented by means of
ICMPv6 messages) and potentially others like DHCPv6 – might depend on a number
of factors:
This blogpost contains summaries of talks from this year’s
TROOPERS19 Active Directory Security Track.
Microsoft IT (Secure) Journey to IPv6-Only
Veronika McKillop, Network Architect, Cloud and Connectivity Engineering (CCE)
The speaker, Veronika McKillop, working at Microsofts network infrastructure
services, has given a talk about the process of switching a company network from
IPv4 to IPv6-only.
Within the talk the following topics were introduced: Dual Stack, Drivers for
IPv6, Status of IPv6 in Networks and Security in IPv6 Networks. The talk covers
the reasons why a company would like to switch from IPv4 to IPv6. Technics like
NAT64 and DNS64 are introduced. The requirements to software and especially
drivers to work in IPv6 environments are described. Also the problems to switch
from IPv4 to IPv6-only in heterogeneous networks are addressed.
We’re regularly asked to review IPv6 address plans from different organizations
and I’d like to share some reflections from such a process currently happening.
I’ve discussed a few aspects of IPv6 address planning before; those readers
interested please see
this post which
contains some references.
The organization in question is headquartered in Germany, has ~60K employees and
a number of subsidiaries in European countries. They belong to a “traditional
industry sector” (so they’re not an “Internet company”, even though they – as
the majority of large organizations right now – strive to be one in a few years
;-).
Starting a post, in 2019, with a mention of sth being “IPv4-only” somewhat hurts
;-), but here we go. Recently Manel Rodero
from Barcelona asked me the
following question on
Twitter:
In this post I’ll try to discuss some inherent aspects of that question and ofc
I’ll try to provide a response to it, too ;-).
Let’s first think about the main IPv6-related risks (= threats put into a
context of relevance) in an “environment [that] is only IPv4”. While some of
you might scratch your heads “what IPv6 threats could there be in an IPv4
setting?” I’m tempted to scratch my head: “what could be the reasons to run an
university network without IPv6 these days, or to use BIND?” (which I have a
strong opinion on, see here or
here). But I
disgress. More seriously the main reason for the question can be broken down to:
Some years ago Christopher wrote two posts
(2016,
2015)
about the IPv6-related characteristics of the WiFi network at Cisco Live
Europe. To somewhat continue this tradition and for mere technical interest I
had a look at some properties of this year’s setting.
There were two SSIDs of interest: a dual-stacked one (“CiscoLive2019”) and one
with v6-only plus NAT64 (“CL-NAT64”). For some background on the underlying
infrastructure components you might look at this
thread
by Nicolas Darchis from the NOC or
at this tweet
from Dominik Pickhardt. Some stats on
IPv6 usage at CLEUR can be
found here.
While thinking about the agenda of the upcoming
Troopers NGI IPv6 Track I realized that quite a lot
of IPv6-related topics have been covered in the last years by various IPv6
practitioners (like my colleague
Christopher Werny) or researchers (like my
friend Antonios Atlasis). In a kind of
shameless self plug I then decided to put together of list of IPv6 talks I
myself gave at several occasions and of publications I (co-) authored. Please
find this list below (sorted by years); you can click on the titles to access
the respective documents/sources.
I hope some of this can be of help for one or the other among you in the course
of your own IPv6 efforts.
Cheers,