SlideShare a Scribd company logo
1 of 17
Download to read offline
Life without IPv4



                                                                        Tore Anderson
                                                           CG Security and Networking
                                                                         Redpill Linpro
                                                   IPv6 Forum Norway, Oslo, May 2011
PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
We'll see Norwegian end users without
their own IPv4 addresses appear soon
 •   This is an inevitable consequence of IPv4 depletion, and the
     primary driving force for IPv6 adoption
 •   In other countries this is already happening, especially in the
     Asia-Pacific region
 •   Let's find out how these users will perceive the internet by
     putting ourselves in their shoes




     PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
Please try to connect to the wireless
network «telenor_ipv6_only» now




   PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
Supported operating systems
•   Microsoft Windows (Vista and newer):

     •   Full support - should work right away

•   Apple iPhone & iPad (with latest firmware 4.3):

     •   Full support - should work right away

     •   Turn off cellular data in order to get the IPv6-only experience

•   Nokia (Symbian):

     •   Full support - should work right away
•   Linux (recent Fedora and Ubuntu):

     •   Works, but requires changes to default connection settings:

          •   Turn off «Require IPv4 addressing for this connection to complete»

          •   Set «IPv6 mode» to «Automatic»

     •   Fedora also requires an firewall opening for the DHCPv6 client (546/udp)

          PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
Unsupported operating systems

•   Microsoft Windows XP

     •   Can not perform DNS queries over IPv6

     •   Also, IPv6 is off by default

•   Apple Mac OS X

     •   Unable to learn the IPv6 DNS server addresses

     •   Will likely be fixed in version 10.7 «Lion» later this year

•   Google Android

     •   Unable to successfully connect to a network without IPv4 service

•   All of the above will be able to successfully use IPv6 on a dual-stacked
    network

     •   Typically IPv4 will be used for DNS lookups (even for IPv6-enabled names)

           PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
Confirming network connectivity
                       http://aaaa.test-ipv6.com




PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
Stuff that works:
•       http://www.ipv6forum.no
•       http://www.vg.no
•       A-pressen's sites: http://www.ba.no, http://www.nordlys.no, 50+ others
•       http://www.redpill-linpro.com
•       http://www.google.com, http://www.youtube.com
•       http://www.venstre.no
•       There may be links and features that don't work - IPv6-only functionality
        is generally not tested very thoroughly

                             What doesn't work?
    •    Pretty much everything else...
    •    An end user without IPv4 is unlikely to be very happy


           PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
End users will expect and need some
     form of [indirect] IPv4 connectivity:


                               Direct IPv6 connectivity


                           ISP access network                                       The public
                                  IPv6-only,                                         Internet
                       or dual-stack with private IPv4



                                   Translating
                                  router/proxy
                                                                     Translated/indirect
IPv6 or private IPv4                                                  IPv4 connectivity

        PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
There's more than one way to do it
                                              •   NAT64+DNS64, DS-Lite, NAT444,
                                                  A+P, ....
                                              •   All of them facilitate rationing of
                                                  IPv4 addresses

                                                    •   Several subscribers may
                                                        share a single address

                                                    •   Allows an ISP to grow its
                                                        customer base post IPv4
                                                        depletion

                                                    •   But there's a price: loss of
                                                        functionality and
                                                        performance


  PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
For a demo of NAT64/DNS64, please
    try to connect to the wireless
   network «nat64_demo» now




  PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
DNS64 operation:


1) What is the IPv6 address
of www.ipv4-only.no?
                                               DNS64
                                              resolver

                                                                                          The public
                              IPv6-only ISP access network                              IPv4 internet



                                                                   NAT64
                                                                 translating
                                                                    router




•   The end user's computer asks the ISP's DNS resolver to resolve a IPv4-
    only hostname to a IPv6 address
              PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
DNS64 operation:
                                                                         2) What are the addresses (IPv4
                                                                         and IPv6) for www.ipv4-only.no?




1) What is the IPv6 address                                              3) No IPv6 is available,
of www.ipv4-only.no?
                                               DNS64
                                                                         IPv4 address is 1.2.3.4
                                              resolver

                                                                                          The public
                              IPv6-only ISP access network                              IPv4 internet



                                                                   NAT64
                                                                 translating
                                                                    router




•   The resolver finds only an IPv4 address published for www.ipv4-only.no

              PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
DNS64 operation:
                                                                         2) What are the addresses (IPv4
                                                                         and IPv6) for www.ipv4-only.no?




1) What is the IPv6 address                                              3) No IPv6 is available,
of www.ipv4-only.no?
                                               DNS64
                                                                         IPv4 address is 1.2.3.4
                                              resolver

                                                                                          The public
                              IPv6-only ISP access network                              IPv4 internet

                4) The IPv6 address for
                www.ipv4-only.no is NAT64::1.2.3.4
                                                                   NAT64
                                                                 translating
                                                                    router




•   The resolver fakes an IPv6 address - embeds the real IPv4 address
    inside the answer returned to the client

              PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
NAT64 operation:



                                           DNS64
                                          resolver

                                                                                      The public
                         IPv6-only ISP access network                               IPv4 internet



                                                               NAT64
                                                             translating
                                                                router
                1) Connect to NAT64::1.2.3.4 port 80



•   The end user establishes an outbound connection to the fake IPv6
    address, ignorant of the fact that is indeed a fake.
•   The ISP proceeds to route these fake addresses to the NAT64 router
          PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
NAT64 operation:



                                            DNS64
                                           resolver

                                                                                       The public
                          IPv6-only ISP access network                               IPv4 internet



                                                                NAT64
                                                              translating
                                                                 router          2) Connect to 1.2.3.4 port 80
                 1) Connect to NAT64::1.2.3.4 port 80



•   The NAT64 box extract the original IPv4 address from the fake IPv6
    address and translates the original IPv6 packets to IPv4, which are
    then transmitted to the original destination (and vice verca)

           PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
What works?
•   The web, e-mail, and other client->server protocols that use hostnames



                  Then what's the problem?
•   Many protocols and services fail to work through NAT64

     •   Skype

     •   BitTorrent

     •   IP telephony (SIP)

     •   Online gaming (Playstation, Xbox, ...)
•   If your neighbour behaves badly, you'll be blacklisted as well
•   ISP-level NAT will be a performance bottleneck



         PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
In summary

•   Many of tomorrow's Internet users will have to make do without IPv4
•   They will likely have to access IPv4 services through a translator
•   Translated connectivity will have less performance and functionality
    than today's IPv4 connectivity or tomorrow's IPv6 connectivity
     •   Owners of online services therefore need to deploy IPv6 in order
         to maintain the best performance and user experience available

•   Questions?

•   Feel free to contact me:
     ➔   tore.anderson@redpill-linpro.com
     ➔   @toreanderson
     ➔   +47 95 93 12 12
     ➔   http://fud.no/talks


          PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING

More Related Content

Viewers also liked

IP Security in Network Security NS6
IP Security in Network Security NS6IP Security in Network Security NS6
IP Security in Network Security NS6
koolkampus
 

Viewers also liked (15)

IP Security
IP SecurityIP Security
IP Security
 
International Journal of Wireless Network Security vol 2 issue 1
International Journal of Wireless Network Security vol 2 issue 1International Journal of Wireless Network Security vol 2 issue 1
International Journal of Wireless Network Security vol 2 issue 1
 
My ppt..priya
My ppt..priyaMy ppt..priya
My ppt..priya
 
I P S P O O F I N G
I P  S P O O F I N GI P  S P O O F I N G
I P S P O O F I N G
 
Ip security
Ip security Ip security
Ip security
 
ip security
ip securityip security
ip security
 
Ipsec
IpsecIpsec
Ipsec
 
Spoofing Techniques
Spoofing TechniquesSpoofing Techniques
Spoofing Techniques
 
IPV4 Frame Format
IPV4 Frame FormatIPV4 Frame Format
IPV4 Frame Format
 
IP Spoofing
IP SpoofingIP Spoofing
IP Spoofing
 
IP Security
IP SecurityIP Security
IP Security
 
IP Security in Network Security NS6
IP Security in Network Security NS6IP Security in Network Security NS6
IP Security in Network Security NS6
 
Ip Spoofing
Ip SpoofingIp Spoofing
Ip Spoofing
 
Ipv4 ppt
Ipv4 pptIpv4 ppt
Ipv4 ppt
 
Ipv4
Ipv4Ipv4
Ipv4
 

Similar to Life Without IPv4: Tore Anderson, IPv6 guru, Redpill Linpro

Ipv6 Technical White Paper Wp111504
Ipv6 Technical White Paper Wp111504Ipv6 Technical White Paper Wp111504
Ipv6 Technical White Paper Wp111504
Erik Ginalick
 
Ipv Technical White Paper Wp111504
Ipv Technical White Paper Wp111504Ipv Technical White Paper Wp111504
Ipv Technical White Paper Wp111504
Erik Ginalick
 

Similar to Life Without IPv4: Tore Anderson, IPv6 guru, Redpill Linpro (20)

4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet
 
IPv6 Security - Workshop mit Live Demo
IPv6 Security - Workshop mit Live DemoIPv6 Security - Workshop mit Live Demo
IPv6 Security - Workshop mit Live Demo
 
IPv6 on the Interop Network
IPv6 on the Interop NetworkIPv6 on the Interop Network
IPv6 on the Interop Network
 
Microsoft IT's IPv6 Killer App
Microsoft IT's IPv6 Killer AppMicrosoft IT's IPv6 Killer App
Microsoft IT's IPv6 Killer App
 
Enabling IPv6 Services Transparently
Enabling IPv6 Services TransparentlyEnabling IPv6 Services Transparently
Enabling IPv6 Services Transparently
 
IPv6 in Cellular Networks
IPv6 in Cellular NetworksIPv6 in Cellular Networks
IPv6 in Cellular Networks
 
Ventajas de IPv6
Ventajas de IPv6Ventajas de IPv6
Ventajas de IPv6
 
ARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities ReportARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities Report
 
IPv6
IPv6IPv6
IPv6
 
IPv6 in cellular networks - Jordi Palet
IPv6 in cellular networks - Jordi PaletIPv6 in cellular networks - Jordi Palet
IPv6 in cellular networks - Jordi Palet
 
IPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-onIPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-on
 
Can NAT 64 Solve IPv4 Exhaustion | IPv4 Addresses | Address Space
Can NAT 64 Solve IPv4 Exhaustion | IPv4 Addresses | Address SpaceCan NAT 64 Solve IPv4 Exhaustion | IPv4 Addresses | Address Space
Can NAT 64 Solve IPv4 Exhaustion | IPv4 Addresses | Address Space
 
Ipv6 Technical White Paper Wp111504
Ipv6 Technical White Paper Wp111504Ipv6 Technical White Paper Wp111504
Ipv6 Technical White Paper Wp111504
 
Ipv Technical White Paper Wp111504
Ipv Technical White Paper Wp111504Ipv Technical White Paper Wp111504
Ipv Technical White Paper Wp111504
 
IPv6
IPv6IPv6
IPv6
 
An IPv6 Primer
An IPv6 PrimerAn IPv6 Primer
An IPv6 Primer
 
IPv6 experience from a large enterprise - Networkshop44
IPv6 experience from a large enterprise - Networkshop44IPv6 experience from a large enterprise - Networkshop44
IPv6 experience from a large enterprise - Networkshop44
 
Tutorial: IPv6-only transition with demo
Tutorial: IPv6-only transition with demoTutorial: IPv6-only transition with demo
Tutorial: IPv6-only transition with demo
 
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration Engineering
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration EngineeringCAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration Engineering
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration Engineering
 
Norway - IPv6 World Leader: Tore Anderson, IPv6 guru, Redpill Linpro
Norway - IPv6 World Leader: Tore Anderson, IPv6 guru, Redpill LinproNorway - IPv6 World Leader: Tore Anderson, IPv6 guru, Redpill Linpro
Norway - IPv6 World Leader: Tore Anderson, IPv6 guru, Redpill Linpro
 

More from IPv6no

I pv6 forum_certification_conor_20120424
I pv6 forum_certification_conor_20120424I pv6 forum_certification_conor_20120424
I pv6 forum_certification_conor_20120424
IPv6no
 
Steinar ipv6forum 20111121v2
Steinar ipv6forum 20111121v2Steinar ipv6forum 20111121v2
Steinar ipv6forum 20111121v2
IPv6no
 
Uwe Germany ipv6-strategy-public
Uwe Germany ipv6-strategy-publicUwe Germany ipv6-strategy-public
Uwe Germany ipv6-strategy-public
IPv6no
 
Geir Making the leap to ipv6 final
Geir Making the leap to ipv6 finalGeir Making the leap to ipv6 final
Geir Making the leap to ipv6 final
IPv6no
 
Ole - Ipv4onlifesupport
Ole - Ipv4onlifesupportOle - Ipv4onlifesupport
Ole - Ipv4onlifesupport
IPv6no
 
Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501
IPv6no
 
Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501
IPv6no
 
Ole Ipv4onlifesupport
Ole Ipv4onlifesupport Ole Ipv4onlifesupport
Ole Ipv4onlifesupport
IPv6no
 
Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011
IPv6no
 
Tore K IPv6 and Altibox
Tore K IPv6 and AltiboxTore K IPv6 and Altibox
Tore K IPv6 and Altibox
IPv6no
 
Nathalie - Stavanger
Nathalie - StavangerNathalie - Stavanger
Nathalie - Stavanger
IPv6no
 
Cameron - TMO IPv6 Norway Meeting
Cameron - TMO  IPv6 Norway MeetingCameron - TMO  IPv6 Norway Meeting
Cameron - TMO IPv6 Norway Meeting
IPv6no
 
11-Sigurd_Thunem-IPv6_through_moderniation
11-Sigurd_Thunem-IPv6_through_moderniation11-Sigurd_Thunem-IPv6_through_moderniation
11-Sigurd_Thunem-IPv6_through_moderniation
IPv6no
 
17-Pete_Vickers-IPv6-in-the-Mobile-Net
17-Pete_Vickers-IPv6-in-the-Mobile-Net17-Pete_Vickers-IPv6-in-the-Mobile-Net
17-Pete_Vickers-IPv6-in-the-Mobile-Net
IPv6no
 

More from IPv6no (20)

I pv6 forum_certification_conor_20120424
I pv6 forum_certification_conor_20120424I pv6 forum_certification_conor_20120424
I pv6 forum_certification_conor_20120424
 
Steinar ipv6forum 20111121v2
Steinar ipv6forum 20111121v2Steinar ipv6forum 20111121v2
Steinar ipv6forum 20111121v2
 
Uwe Germany ipv6-strategy-public
Uwe Germany ipv6-strategy-publicUwe Germany ipv6-strategy-public
Uwe Germany ipv6-strategy-public
 
Geir Making the leap to ipv6 final
Geir Making the leap to ipv6 finalGeir Making the leap to ipv6 final
Geir Making the leap to ipv6 final
 
Ole - Ipv4onlifesupport
Ole - Ipv4onlifesupportOle - Ipv4onlifesupport
Ole - Ipv4onlifesupport
 
Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501
 
Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501Jan zorz procurement-ripe-501
Jan zorz procurement-ripe-501
 
Ole Ipv4onlifesupport
Ole Ipv4onlifesupport Ole Ipv4onlifesupport
Ole Ipv4onlifesupport
 
Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011
 
Tore K IPv6 and Altibox
Tore K IPv6 and AltiboxTore K IPv6 and Altibox
Tore K IPv6 and Altibox
 
Nathalie - Stavanger
Nathalie - StavangerNathalie - Stavanger
Nathalie - Stavanger
 
Cameron - TMO IPv6 Norway Meeting
Cameron - TMO  IPv6 Norway MeetingCameron - TMO  IPv6 Norway Meeting
Cameron - TMO IPv6 Norway Meeting
 
11-Sigurd_Thunem-IPv6_through_moderniation
11-Sigurd_Thunem-IPv6_through_moderniation11-Sigurd_Thunem-IPv6_through_moderniation
11-Sigurd_Thunem-IPv6_through_moderniation
 
Google and IPv6: Steinar H. Gunderson, Software engineer, Google
Google and IPv6: Steinar H. Gunderson, Software engineer, GoogleGoogle and IPv6: Steinar H. Gunderson, Software engineer, Google
Google and IPv6: Steinar H. Gunderson, Software engineer, Google
 
50 billion connected wireless devices... IPv6, anyone?: Fredrik Garneij, Syst...
50 billion connected wireless devices... IPv6, anyone?: Fredrik Garneij, Syst...50 billion connected wireless devices... IPv6, anyone?: Fredrik Garneij, Syst...
50 billion connected wireless devices... IPv6, anyone?: Fredrik Garneij, Syst...
 
IPv6 Seen From Statoil: Knut Sebastian Tungland, Chief Engineer Information T...
IPv6 Seen From Statoil: Knut Sebastian Tungland, Chief Engineer Information T...IPv6 Seen From Statoil: Knut Sebastian Tungland, Chief Engineer Information T...
IPv6 Seen From Statoil: Knut Sebastian Tungland, Chief Engineer Information T...
 
17-Pete_Vickers-IPv6-in-the-Mobile-Net
17-Pete_Vickers-IPv6-in-the-Mobile-Net17-Pete_Vickers-IPv6-in-the-Mobile-Net
17-Pete_Vickers-IPv6-in-the-Mobile-Net
 
IPv6, DLD og NAT: Steinar Haug, IPv6 guru, Ventelo
IPv6, DLD og NAT: Steinar Haug, IPv6 guru, VenteloIPv6, DLD og NAT: Steinar Haug, IPv6 guru, Ventelo
IPv6, DLD og NAT: Steinar Haug, IPv6 guru, Ventelo
 
Mobile Broadband and IPv6 in Slovenia: Jan Zorz, Co-Founder Go6 Institute og ...
Mobile Broadband and IPv6 in Slovenia: Jan Zorz, Co-Founder Go6 Institute og ...Mobile Broadband and IPv6 in Slovenia: Jan Zorz, Co-Founder Go6 Institute og ...
Mobile Broadband and IPv6 in Slovenia: Jan Zorz, Co-Founder Go6 Institute og ...
 
IPv6 - The Time Is Now: Latif Ladid, President, IPv6 forum
IPv6 - The Time Is Now: Latif Ladid, President, IPv6 forumIPv6 - The Time Is Now: Latif Ladid, President, IPv6 forum
IPv6 - The Time Is Now: Latif Ladid, President, IPv6 forum
 

Recently uploaded

Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
Apidays Singapore 2024 - Scalable LLM APIs for AI and Generative AI Applicati...
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 

Life Without IPv4: Tore Anderson, IPv6 guru, Redpill Linpro

  • 1. Life without IPv4 Tore Anderson CG Security and Networking Redpill Linpro IPv6 Forum Norway, Oslo, May 2011 PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 2. We'll see Norwegian end users without their own IPv4 addresses appear soon • This is an inevitable consequence of IPv4 depletion, and the primary driving force for IPv6 adoption • In other countries this is already happening, especially in the Asia-Pacific region • Let's find out how these users will perceive the internet by putting ourselves in their shoes PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 3. Please try to connect to the wireless network «telenor_ipv6_only» now PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 4. Supported operating systems • Microsoft Windows (Vista and newer): • Full support - should work right away • Apple iPhone & iPad (with latest firmware 4.3): • Full support - should work right away • Turn off cellular data in order to get the IPv6-only experience • Nokia (Symbian): • Full support - should work right away • Linux (recent Fedora and Ubuntu): • Works, but requires changes to default connection settings: • Turn off «Require IPv4 addressing for this connection to complete» • Set «IPv6 mode» to «Automatic» • Fedora also requires an firewall opening for the DHCPv6 client (546/udp) PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 5. Unsupported operating systems • Microsoft Windows XP • Can not perform DNS queries over IPv6 • Also, IPv6 is off by default • Apple Mac OS X • Unable to learn the IPv6 DNS server addresses • Will likely be fixed in version 10.7 «Lion» later this year • Google Android • Unable to successfully connect to a network without IPv4 service • All of the above will be able to successfully use IPv6 on a dual-stacked network • Typically IPv4 will be used for DNS lookups (even for IPv6-enabled names) PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 6. Confirming network connectivity http://aaaa.test-ipv6.com PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 7. Stuff that works: • http://www.ipv6forum.no • http://www.vg.no • A-pressen's sites: http://www.ba.no, http://www.nordlys.no, 50+ others • http://www.redpill-linpro.com • http://www.google.com, http://www.youtube.com • http://www.venstre.no • There may be links and features that don't work - IPv6-only functionality is generally not tested very thoroughly What doesn't work? • Pretty much everything else... • An end user without IPv4 is unlikely to be very happy PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 8. End users will expect and need some form of [indirect] IPv4 connectivity: Direct IPv6 connectivity ISP access network The public IPv6-only, Internet or dual-stack with private IPv4 Translating router/proxy Translated/indirect IPv6 or private IPv4 IPv4 connectivity PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 9. There's more than one way to do it • NAT64+DNS64, DS-Lite, NAT444, A+P, .... • All of them facilitate rationing of IPv4 addresses • Several subscribers may share a single address • Allows an ISP to grow its customer base post IPv4 depletion • But there's a price: loss of functionality and performance PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 10. For a demo of NAT64/DNS64, please try to connect to the wireless network «nat64_demo» now PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 11. DNS64 operation: 1) What is the IPv6 address of www.ipv4-only.no? DNS64 resolver The public IPv6-only ISP access network IPv4 internet NAT64 translating router • The end user's computer asks the ISP's DNS resolver to resolve a IPv4- only hostname to a IPv6 address PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 12. DNS64 operation: 2) What are the addresses (IPv4 and IPv6) for www.ipv4-only.no? 1) What is the IPv6 address 3) No IPv6 is available, of www.ipv4-only.no? DNS64 IPv4 address is 1.2.3.4 resolver The public IPv6-only ISP access network IPv4 internet NAT64 translating router • The resolver finds only an IPv4 address published for www.ipv4-only.no PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 13. DNS64 operation: 2) What are the addresses (IPv4 and IPv6) for www.ipv4-only.no? 1) What is the IPv6 address 3) No IPv6 is available, of www.ipv4-only.no? DNS64 IPv4 address is 1.2.3.4 resolver The public IPv6-only ISP access network IPv4 internet 4) The IPv6 address for www.ipv4-only.no is NAT64::1.2.3.4 NAT64 translating router • The resolver fakes an IPv6 address - embeds the real IPv4 address inside the answer returned to the client PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 14. NAT64 operation: DNS64 resolver The public IPv6-only ISP access network IPv4 internet NAT64 translating router 1) Connect to NAT64::1.2.3.4 port 80 • The end user establishes an outbound connection to the fake IPv6 address, ignorant of the fact that is indeed a fake. • The ISP proceeds to route these fake addresses to the NAT64 router PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 15. NAT64 operation: DNS64 resolver The public IPv6-only ISP access network IPv4 internet NAT64 translating router 2) Connect to 1.2.3.4 port 80 1) Connect to NAT64::1.2.3.4 port 80 • The NAT64 box extract the original IPv4 address from the fake IPv6 address and translates the original IPv6 packets to IPv4, which are then transmitted to the original destination (and vice verca) PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 16. What works? • The web, e-mail, and other client->server protocols that use hostnames Then what's the problem? • Many protocols and services fail to work through NAT64 • Skype • BitTorrent • IP telephony (SIP) • Online gaming (Playstation, Xbox, ...) • If your neighbour behaves badly, you'll be blacklisted as well • ISP-level NAT will be a performance bottleneck PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING
  • 17. In summary • Many of tomorrow's Internet users will have to make do without IPv4 • They will likely have to access IPv4 services through a translator • Translated connectivity will have less performance and functionality than today's IPv4 connectivity or tomorrow's IPv6 connectivity • Owners of online services therefore need to deploy IPv6 in order to maintain the best performance and user experience available • Questions? • Feel free to contact me: ➔ tore.anderson@redpill-linpro.com ➔ @toreanderson ➔ +47 95 93 12 12 ➔ http://fud.no/talks PRODUCTS • CONSULTING • APPLICATION MANAGEMENT • IT OPERATIONS • SUPPORT • TRAINING