This week Chris and I participated in the RIPE 78
meeting in Reykjavík. Being part of the group was fun as always and we had quite
some interesting conversations with peers from (not only) the IPv6 community.
Big thanks to the RIPE NCC team for the smooth
organization and for taking care of us!
In this post I’ll provide some notes on talks I found particularly interesting,
plus links to our own contributions.
Chris and I will give a tutorial on the above
topic at next week’s RIPE Meeting in Reykjavík. In
this post (actually this will probably become a small series of posts) I’ll try
to summarize some thoughts on IPv6 security in enterprise environments in 2019.
We’re going to cover three main areas:
Why IPv6 Is Different, Security-wise
Traffic Filtering in IPv6 Networks
IPv6 Security in L2 Networks / First Hop Security et al.
Let’s start with the first item. In real-life scenarios the security of “a
protocol” – IPv6 can rather be considered a “protocol family” which includes
helper protocols like ICMPv6 and MLD (which in turn is implemented by means of
ICMPv6 messages) and potentially others like DHCPv6 – might depend on a number
of factors:
Last week I had the pleasure to participate at the
first RIPE IoT Roundtable Meeting
in Leeds (thanks! to
Marco Hogewoning
for organising it). It was a day with many fruitful discussions. I particularly
enjoyed Robert Kisteleki‘s talk on RIPE NCC’s own
design & (security) process considerations in the context of
RIPE Atlas (at TR17 NGI there was an
intro to Atlas,
too).
In this post I’d like to quickly lay out the main points of my own contribution
on “Balanced Security for IPv6 CPE Revisited” (the slides can be found
here).
From May 8th to 12th I was able to attend the 74th RIPE meeting in Budapest,
Hungary. Being rather new to the networking community, I enjoyed learning a lot
of different things, not only from the various interesting talks but also from
inspiring conversations with a variety of people from all areas during the
beautiful social events.
As it was the first RIPE meeting for me, I was very thankful for the “Newcomer’s
Introduction” on Monday morning, containing a RIPE and RIPE NCC 101. It was
quite helpful to get into the mindset and understand the structure of the
meeting, like the division into different working groups based on the
participants’ interests. After familiarizing myself with the concept, I chose to
attend several sessions on Address Policy, IPv6, Routing, Open Source, and DNS
working groups besides the general plenary sessions. I’ll be reviewing those
sessions here.
I’m on my way back from the
RIPE74 meeting in Budapest. It was a great event:
quite a few nice technical talks in the plenary, productive working group
meetings and some really good hallway discussions.
Big thanks to the RIPE NCC team for the smooth organization and for taking care
of us!
Here’s some stuff I found particularly interesting:
Andrew Alston’s take on “Anti-Shutdown
Policies” (slides
and video incl. extensive mic
discussion)
In November 2014, after quite some controversy in the IETF OPSEC working group
(for those interested look at the
archives),
the InformationalRFC 7404 “Using
Only Link-Local Addressing inside an IPv6 Network” was published. It is authored
by Michael Behringer and
Eric Vyncke and discusses the advantages
& disadvantages of an approach using “only link-local addresses on
infrastructure links between routers”.
So it’s (merely) about “infrastructure links” which some people call “transit
networks” or “point to point” (ptp) links. I’m aware that there might be subtle
differences between all these, depending on your specific use of the terms.
Still I assume that most readers will have an understanding of what types of
links are in focus of the RFC, and subsequently of this post.
Two weeks ago Christopher and I joined the RIPE70 meeting in Amsterdam. Being
part of the group was fun as always and we had quite some interesting
conversations with peers from the IPv6 community.
We could even contribute a bit to some discussions, with two talks. I gave one
titled “Will It Be Routed? – On IPv6 Address Space Allocation & Assignment
Approaches in Very Large Organizations” in the Address Policy Working Group
session on Wednesday. This is the abstract:
Some hours ago Iljitsch van Beijnum posted
an email
with the above subject to the RIPE Best Current Operational Practices (BCOP)
mailing list.
Therein he describes the growing issue of (IPv6 prefix) deaggregation
desires/approaches by certain organizations vs. the filtering practices of other
organizations (providers). I touched this problem, from an enterprise’s
perspective, some time ago in the
second part
of my blog post series on
IPv6 address planning.
Given we think that the discussion is heavily needed from several angles, I
had actually submitted a talk on the topic twice (for the RIPE meeting in Warsaw
in May and the upcoming one in London) which was unfortunately rejected at both
occasions.
I’m hence very happy to see that a dialogue about the inherent dilemma might be
started by Iljitsch’s mail. As a contribution to the development of a BCOP
document I will hereby publish
our draft slides
of the talk which was initially planned. Furthermore two fellow IPv6
practitioners (Hi Roland & Nico!) and I plan to release a detailed paper with
research results as for IPv6 prefix distribution at major European IXs in the
near future.