SlideShare a Scribd company logo
1 of 13
www.adnettelecom.ro




            Provocarile IPv6
 “Puteti face o migrare planificata si minutioasa sau o
 puteti face in graba, sub efectul panicii. Si ar trebui sa
        stiti ca panica este mult mai costisitoare”.
Martin Levy, director of IPv6 strategy for Hurricane Electric


                                          Flavius PORUMB
                                      CTO @ AdNet Telecom
www.adnettelecom.ro




   Populatia lumii                                       Deci …
   Penetrare Internet                                    IPv6 ar trebui sa fie deja
                                                          implementat pe scara
   Servicii Internet                                     larga.
   Adrese IPv4 disponibile
                                                          Totusi, nu este!




             Sunt multiple considerente ce au amanat adoptia IPv6 ..
www.adnettelecom.ro
Consideratii generale
despre tranzitia la IPv6 (1)
• African Network Information
   Centre (AfriNIC)
• American Registry for Internet
   Numbers (ARIN)
 (United States, Canada, Antarctica,
anumite parti din Caraibe)
• Asia-Pacific Network Information
   Centre (APNIC)
(Asia, Australia, Noua Zeelanda, si
tarile vecine)
• Latin America and Caribbean
   Network Information Centre
   (LACNIC)
(pentru America Latina si parti din
Caraibe)
• Réseaux IP Européens Network
   Coordination Centre (RIPE NCC)
(pentru Europa, Rusia, Orientul
Mijlociu si Asia Centrala)
www.adnettelecom.ro
Consideratii generale
despre tranzitia la IPv6 (2)

• Putina istorie telco: Premizele bune nu sunt o garantie a succesului unei tranzitii,
asa cum premizele slabe nu inseamna ca gradul de adoptare nu va fii unul important
CUM VA ADMINISTRA INDUSTRIA ACEASTA TRANZITIE DE LA IPv4 la IPv6? VA FII UN SUCCES?
VOM PASTRA INTERNETUL CA O RETEA UNICA, COERENTA?
• Tranzitiile anterioare in telecomunicatii (FDM ->TDM-> IP etc.) au avut in mare majoritate
logica de business sau functionala

In acest caz insa ..      IPv6 nu a fost proiectat
                              sa suporte IPv4


      Nu exista un plan/strategie comun/a de adoptare
      Nu exista constrangeri/motivari comune
      Nu exista business-case pentru tranzitii agresive (no D-Day, Y2K)
www.adnettelecom.ro


    BENEFICII
                                             PROVOCARI
• Spatiu de adrese suficient
• Autoconfigurare                            • Tranzitia la IPv6 presupune investitii de
• Mobilitate                                 capital (echipamente, training)
• Securitate inclusa in protocol             • Potentiale brese importante de securitate
• Comunicatii end-to-end                     • Poate presupune schimbari in modelele de
• Extensibilitate la noi capabilitati,       business
stimuleaza inovatia in numeroase             • Perioada de tranzitie se poate prelungi pe
sectoare                                     termen lung prin diverse modalitati de a face
• Noi oportunitati de afaceri                fata lipsei resurselor IPv4
• “Internet of Things”                       • Marirea considerabila a tabelei globale de
• Imbunatatiri in automatizarea              rutare, daca asignarile nu se fac cu atentie
proceselor, cresterea productivitatii si a   • Mentalitati
eficientei                                   • “no killer app”
• Reducere strategica de costuri
www.adnettelecom.ro
Fazele (probabile) ale
  tranzitiei globale

•   Clienti dual-stack si continut IPv6
•   Clienti IPv6-only si NAT64
•   Aplicatii IPv6-only
•   IPv4 va iesi din uz
www.adnettelecom.ro
Tranzitie IPv6 (1)
De ce este mai scump sa amanati?

  • Evitarea cresterii costurilor ICT
  – la urmatorul ciclu de upgrade retea cereti partenerilor
  paritatea capabilitatilor IPv4/IPv6
  (ISP, vendorii de echipamente, furnizorii de aplicatii)

  • Minimizare riscuri
  Curba de invatare nu va fi scurta, daca incepeti sa planificati din    NU EXISTA UN PLAN B!
  timp personalul va avea timp sa castige expertiza necesara

  • Content pe IPv6
  .. sau pierdeti clienti si comunicarea cu parteneri (LTE, Asia, etc)

  • Avantaj competitiv
  Internetul nu mai este provider-driven, ci user-driven
Tranzitie IPv6 (2)                                                            www.adnettelecom.ro




     Specialistii in securitate nu sunt unitari in         TIPS:
parerile despre abordarea tranzitiei la IPv6: •        Migrare website pe IPv6
                                                   •   Audit firewall/IPS/IDS/DMZ, aplicatii
1. Blocare totala trafic IPv6                      •   Conditii tehnice si comerciale ISP & furnizori
    pana la finalizare upgrade firewall-IPS-IDS        eq. ICT & aplicatii dpdv adoptie IPv6
(pt. a permite detectie &/ blocare trafic IPv6 •       Obtineti spatiul de adrese IPv6
nativ sau tunelat)                                     (NB: PI -multihoming)
                                                   •   Training - dezvoltatori de aplicatii si personal
2. Audit & Implementare rapida IPv6                    suport retea
(aplicand aceeasi politica de securitate ca si •       Incepeti sa elaborati strategia de tranzitie!
pentru IPv4)
Tranzitie IPv6 (3)                                                      www.adnettelecom.ro
  Focus: Provocari de securitate
 50% din retele au echipamente cu IPv6 activat




                                                                                            Brese de securitate importante
 ~300.000.000 echipamente cu IPv6 activat
Exemple
 Trafic IPv6 neautorizat/nemonitorizat (rogue IPv6 traffic) - Echipamentele
   (telco,firewall/IPS/IDS/shaper) asigura traficul, dar nu il inspecteaza.
 Capacitatea de auto-configurare duce la aparitia unei vulnerabilitati importante –
   rogue IPv6 device, respectiv un router ce asigneaza adrese IPv6 in retea, iar traficul
   IPv6 sa fie interceptat – MITM (Man In The Middle)
 Manipularea antetului de rutare => saturarea unor segmente de retea (DoS)
 Mentalitati, lipsa expertizei operationale, si greselile de implementare
 Lipsa unei organizatii care sa stabileasca bune practici de tranzitie

 De numarul mare de adrese IPv6 vor beneficia si criminalii informatici
       Schimbare frecventa a adreselor => dificultatea identificarii
       Blacklisting ingreunat - 90% din filtre se bazeaza pe aceasta metoda
 Inexistenta paritate capabilitati IPv4/IPv6 la vendorii de echipamente
Tranzitie IPv6 (4)                                  www.adnettelecom.ro


                     Business-case: Beneficii, Costuri, Riscuri
                        Echipa proiect – “this is no one man show”



                     Audit retea, servicii, echipamente, sisteme, aplicatii
                         Elaborare design pentru tranzitie
                             Elaborarea planului de implementare



                                            Metodologii tranzitie
                                            • Core to Edge *
                                            • Edge to Core
                                            • IPv6 Islands
www.adnettelecom.ro

Dezvoltari IPv6 la nivel global



         •   Japonia si Corea de Sud
         •   China si India
         •   SUA
         •   Europa
www.adnettelecom.ro
Slovenia, un exemplu
   de bune practici



go6 – initiativa slovena pentru realizarea unui profil
european IPv6 uniform pentru achizitia de
echipamente si servicii ICT
“Requirements For IPv6 in ICT Equipment” (RIPE 554).
http://www.ripe.net/ripe/docs/current-ripe-documents/ripe-554

Documentul include recomandari de cerinte ale guvernelor
europene pentru conformitatea echipamentelor cu cerintele IPv6,
precum si nivelul de expertiza al integratorilor de sisteme.
www.adnettelecom.ro




         MULŢUMESC!
            IPv6 – the new normal



                  IPv6 Challenges
                 Flavius PORUMB
   flavius.porumb@adnettelecom.ro

Lansarea mondiala IPv6, Romania
                   2012 June 06th

More Related Content

Similar to IPv6 challenges

Vincentiu Cuc - Platforma IT IMI
Vincentiu Cuc - Platforma IT IMIVincentiu Cuc - Platforma IT IMI
Vincentiu Cuc - Platforma IT IMIIMI PQ NET Romania
 
Bit Software - 21 aprilie 2011
Bit Software - 21 aprilie 2011Bit Software - 21 aprilie 2011
Bit Software - 21 aprilie 2011Agora Group
 
Class IT - 9febr2012
Class IT - 9febr2012Class IT - 9febr2012
Class IT - 9febr2012Agora Group
 
Bit+software+ +open+source+-+27mai2010
Bit+software+ +open+source+-+27mai2010Bit+software+ +open+source+-+27mai2010
Bit+software+ +open+source+-+27mai2010Agora Group
 
Spearhead Systems
Spearhead SystemsSpearhead Systems
Spearhead SystemsMarius Pana
 
Spearhead Systems S.R.L.
Spearhead Systems S.R.L.Spearhead Systems S.R.L.
Spearhead Systems S.R.L.Marius Pana
 
Catalin paunescu star_storage_cloud_security_2012_ro
Catalin paunescu star_storage_cloud_security_2012_roCatalin paunescu star_storage_cloud_security_2012_ro
Catalin paunescu star_storage_cloud_security_2012_roE-Government Center Moldova
 
Alternative Open Source pentru mediul de afaceri-19mar2010
Alternative Open Source pentru mediul de afaceri-19mar2010Alternative Open Source pentru mediul de afaceri-19mar2010
Alternative Open Source pentru mediul de afaceri-19mar2010Agora Group
 
Prezentare Distinct Nbb Cluster V1
Prezentare Distinct Nbb Cluster V1Prezentare Distinct Nbb Cluster V1
Prezentare Distinct Nbb Cluster V1Adrian Dragomir
 
Windows Azure AppFabric - Service Bus, Caching
Windows Azure AppFabric - Service Bus, CachingWindows Azure AppFabric - Service Bus, Caching
Windows Azure AppFabric - Service Bus, CachingMihai Dan Nadas
 
Cloud computing caracteristici si modele v greavu
Cloud computing caracteristici si modele   v greavuCloud computing caracteristici si modele   v greavu
Cloud computing caracteristici si modele v greavuMalairauValeria
 
Content Management - Alexandru Lapusan
Content Management - Alexandru LapusanContent Management - Alexandru Lapusan
Content Management - Alexandru LapusanIDG Romania
 
Liviu Tanase - Prezentare FH10
Liviu Tanase - Prezentare FH10Liviu Tanase - Prezentare FH10
Liviu Tanase - Prezentare FH10Lorand R. Minyo
 
Remus Pereni - Remus Pereni - JavaScript, from dark ages to renaissance, the ...
Remus Pereni - Remus Pereni - JavaScript, from dark ages to renaissance, the ...Remus Pereni - Remus Pereni - JavaScript, from dark ages to renaissance, the ...
Remus Pereni - Remus Pereni - JavaScript, from dark ages to renaissance, the ...Codecamp Romania
 
Valeriu plamandeala platforma_tehnologica_comuna1
Valeriu plamandeala platforma_tehnologica_comuna1Valeriu plamandeala platforma_tehnologica_comuna1
Valeriu plamandeala platforma_tehnologica_comuna1E-Government Center Moldova
 
Star storage 18nov2010
Star storage 18nov2010Star storage 18nov2010
Star storage 18nov2010Agora Group
 
Softline - 10martie2011
Softline - 10martie2011Softline - 10martie2011
Softline - 10martie2011Agora Group
 
Computer Networks. P2P
Computer Networks. P2PComputer Networks. P2P
Computer Networks. P2PSabin Buraga
 

Similar to IPv6 challenges (20)

Vincentiu Cuc - Platforma IT IMI
Vincentiu Cuc - Platforma IT IMIVincentiu Cuc - Platforma IT IMI
Vincentiu Cuc - Platforma IT IMI
 
Bit Software - 21 aprilie 2011
Bit Software - 21 aprilie 2011Bit Software - 21 aprilie 2011
Bit Software - 21 aprilie 2011
 
Class IT - 9febr2012
Class IT - 9febr2012Class IT - 9febr2012
Class IT - 9febr2012
 
Bit+software+ +open+source+-+27mai2010
Bit+software+ +open+source+-+27mai2010Bit+software+ +open+source+-+27mai2010
Bit+software+ +open+source+-+27mai2010
 
Spearhead Systems
Spearhead SystemsSpearhead Systems
Spearhead Systems
 
Spearhead Systems S.R.L.
Spearhead Systems S.R.L.Spearhead Systems S.R.L.
Spearhead Systems S.R.L.
 
Catalin paunescu star_storage_cloud_security_2012_ro
Catalin paunescu star_storage_cloud_security_2012_roCatalin paunescu star_storage_cloud_security_2012_ro
Catalin paunescu star_storage_cloud_security_2012_ro
 
Alternative Open Source pentru mediul de afaceri-19mar2010
Alternative Open Source pentru mediul de afaceri-19mar2010Alternative Open Source pentru mediul de afaceri-19mar2010
Alternative Open Source pentru mediul de afaceri-19mar2010
 
Prezentare Distinct Nbb Cluster V1
Prezentare Distinct Nbb Cluster V1Prezentare Distinct Nbb Cluster V1
Prezentare Distinct Nbb Cluster V1
 
Windows Azure AppFabric - Service Bus, Caching
Windows Azure AppFabric - Service Bus, CachingWindows Azure AppFabric - Service Bus, Caching
Windows Azure AppFabric - Service Bus, Caching
 
Cloud computing caracteristici si modele v greavu
Cloud computing caracteristici si modele   v greavuCloud computing caracteristici si modele   v greavu
Cloud computing caracteristici si modele v greavu
 
Prezentare
PrezentarePrezentare
Prezentare
 
Content Management - Alexandru Lapusan
Content Management - Alexandru LapusanContent Management - Alexandru Lapusan
Content Management - Alexandru Lapusan
 
Liviu Tanase - Prezentare FH10
Liviu Tanase - Prezentare FH10Liviu Tanase - Prezentare FH10
Liviu Tanase - Prezentare FH10
 
Remus Pereni - Remus Pereni - JavaScript, from dark ages to renaissance, the ...
Remus Pereni - Remus Pereni - JavaScript, from dark ages to renaissance, the ...Remus Pereni - Remus Pereni - JavaScript, from dark ages to renaissance, the ...
Remus Pereni - Remus Pereni - JavaScript, from dark ages to renaissance, the ...
 
Valeriu plamandeala platforma_tehnologica_comuna1
Valeriu plamandeala platforma_tehnologica_comuna1Valeriu plamandeala platforma_tehnologica_comuna1
Valeriu plamandeala platforma_tehnologica_comuna1
 
Star storage 18nov2010
Star storage 18nov2010Star storage 18nov2010
Star storage 18nov2010
 
2014_Prezentare_PhD_AB_v03
2014_Prezentare_PhD_AB_v032014_Prezentare_PhD_AB_v03
2014_Prezentare_PhD_AB_v03
 
Softline - 10martie2011
Softline - 10martie2011Softline - 10martie2011
Softline - 10martie2011
 
Computer Networks. P2P
Computer Networks. P2PComputer Networks. P2P
Computer Networks. P2P
 

IPv6 challenges

  • 1. www.adnettelecom.ro Provocarile IPv6 “Puteti face o migrare planificata si minutioasa sau o puteti face in graba, sub efectul panicii. Si ar trebui sa stiti ca panica este mult mai costisitoare”. Martin Levy, director of IPv6 strategy for Hurricane Electric Flavius PORUMB CTO @ AdNet Telecom
  • 2. www.adnettelecom.ro  Populatia lumii Deci …  Penetrare Internet IPv6 ar trebui sa fie deja implementat pe scara  Servicii Internet larga.  Adrese IPv4 disponibile Totusi, nu este! Sunt multiple considerente ce au amanat adoptia IPv6 ..
  • 3. www.adnettelecom.ro Consideratii generale despre tranzitia la IPv6 (1) • African Network Information Centre (AfriNIC) • American Registry for Internet Numbers (ARIN) (United States, Canada, Antarctica, anumite parti din Caraibe) • Asia-Pacific Network Information Centre (APNIC) (Asia, Australia, Noua Zeelanda, si tarile vecine) • Latin America and Caribbean Network Information Centre (LACNIC) (pentru America Latina si parti din Caraibe) • Réseaux IP Européens Network Coordination Centre (RIPE NCC) (pentru Europa, Rusia, Orientul Mijlociu si Asia Centrala)
  • 4. www.adnettelecom.ro Consideratii generale despre tranzitia la IPv6 (2) • Putina istorie telco: Premizele bune nu sunt o garantie a succesului unei tranzitii, asa cum premizele slabe nu inseamna ca gradul de adoptare nu va fii unul important CUM VA ADMINISTRA INDUSTRIA ACEASTA TRANZITIE DE LA IPv4 la IPv6? VA FII UN SUCCES? VOM PASTRA INTERNETUL CA O RETEA UNICA, COERENTA? • Tranzitiile anterioare in telecomunicatii (FDM ->TDM-> IP etc.) au avut in mare majoritate logica de business sau functionala In acest caz insa .. IPv6 nu a fost proiectat sa suporte IPv4  Nu exista un plan/strategie comun/a de adoptare  Nu exista constrangeri/motivari comune  Nu exista business-case pentru tranzitii agresive (no D-Day, Y2K)
  • 5. www.adnettelecom.ro BENEFICII PROVOCARI • Spatiu de adrese suficient • Autoconfigurare • Tranzitia la IPv6 presupune investitii de • Mobilitate capital (echipamente, training) • Securitate inclusa in protocol • Potentiale brese importante de securitate • Comunicatii end-to-end • Poate presupune schimbari in modelele de • Extensibilitate la noi capabilitati, business stimuleaza inovatia in numeroase • Perioada de tranzitie se poate prelungi pe sectoare termen lung prin diverse modalitati de a face • Noi oportunitati de afaceri fata lipsei resurselor IPv4 • “Internet of Things” • Marirea considerabila a tabelei globale de • Imbunatatiri in automatizarea rutare, daca asignarile nu se fac cu atentie proceselor, cresterea productivitatii si a • Mentalitati eficientei • “no killer app” • Reducere strategica de costuri
  • 6. www.adnettelecom.ro Fazele (probabile) ale tranzitiei globale • Clienti dual-stack si continut IPv6 • Clienti IPv6-only si NAT64 • Aplicatii IPv6-only • IPv4 va iesi din uz
  • 7. www.adnettelecom.ro Tranzitie IPv6 (1) De ce este mai scump sa amanati? • Evitarea cresterii costurilor ICT – la urmatorul ciclu de upgrade retea cereti partenerilor paritatea capabilitatilor IPv4/IPv6 (ISP, vendorii de echipamente, furnizorii de aplicatii) • Minimizare riscuri Curba de invatare nu va fi scurta, daca incepeti sa planificati din NU EXISTA UN PLAN B! timp personalul va avea timp sa castige expertiza necesara • Content pe IPv6 .. sau pierdeti clienti si comunicarea cu parteneri (LTE, Asia, etc) • Avantaj competitiv Internetul nu mai este provider-driven, ci user-driven
  • 8. Tranzitie IPv6 (2) www.adnettelecom.ro Specialistii in securitate nu sunt unitari in TIPS: parerile despre abordarea tranzitiei la IPv6: • Migrare website pe IPv6 • Audit firewall/IPS/IDS/DMZ, aplicatii 1. Blocare totala trafic IPv6 • Conditii tehnice si comerciale ISP & furnizori pana la finalizare upgrade firewall-IPS-IDS eq. ICT & aplicatii dpdv adoptie IPv6 (pt. a permite detectie &/ blocare trafic IPv6 • Obtineti spatiul de adrese IPv6 nativ sau tunelat) (NB: PI -multihoming) • Training - dezvoltatori de aplicatii si personal 2. Audit & Implementare rapida IPv6 suport retea (aplicand aceeasi politica de securitate ca si • Incepeti sa elaborati strategia de tranzitie! pentru IPv4)
  • 9. Tranzitie IPv6 (3) www.adnettelecom.ro Focus: Provocari de securitate  50% din retele au echipamente cu IPv6 activat Brese de securitate importante  ~300.000.000 echipamente cu IPv6 activat Exemple  Trafic IPv6 neautorizat/nemonitorizat (rogue IPv6 traffic) - Echipamentele (telco,firewall/IPS/IDS/shaper) asigura traficul, dar nu il inspecteaza.  Capacitatea de auto-configurare duce la aparitia unei vulnerabilitati importante – rogue IPv6 device, respectiv un router ce asigneaza adrese IPv6 in retea, iar traficul IPv6 sa fie interceptat – MITM (Man In The Middle)  Manipularea antetului de rutare => saturarea unor segmente de retea (DoS)  Mentalitati, lipsa expertizei operationale, si greselile de implementare  Lipsa unei organizatii care sa stabileasca bune practici de tranzitie  De numarul mare de adrese IPv6 vor beneficia si criminalii informatici Schimbare frecventa a adreselor => dificultatea identificarii Blacklisting ingreunat - 90% din filtre se bazeaza pe aceasta metoda  Inexistenta paritate capabilitati IPv4/IPv6 la vendorii de echipamente
  • 10. Tranzitie IPv6 (4) www.adnettelecom.ro Business-case: Beneficii, Costuri, Riscuri Echipa proiect – “this is no one man show” Audit retea, servicii, echipamente, sisteme, aplicatii Elaborare design pentru tranzitie Elaborarea planului de implementare Metodologii tranzitie • Core to Edge * • Edge to Core • IPv6 Islands
  • 11. www.adnettelecom.ro Dezvoltari IPv6 la nivel global • Japonia si Corea de Sud • China si India • SUA • Europa
  • 12. www.adnettelecom.ro Slovenia, un exemplu de bune practici go6 – initiativa slovena pentru realizarea unui profil european IPv6 uniform pentru achizitia de echipamente si servicii ICT “Requirements For IPv6 in ICT Equipment” (RIPE 554). http://www.ripe.net/ripe/docs/current-ripe-documents/ripe-554 Documentul include recomandari de cerinte ale guvernelor europene pentru conformitatea echipamentelor cu cerintele IPv6, precum si nivelul de expertiza al integratorilor de sisteme.
  • 13. www.adnettelecom.ro MULŢUMESC! IPv6 – the new normal IPv6 Challenges Flavius PORUMB flavius.porumb@adnettelecom.ro Lansarea mondiala IPv6, Romania 2012 June 06th

Editor's Notes

  1. Buna ziua, Ma numesc Flavius Porumb, sunt director tehnic la AdNet Telecom.Catevacuvintedespre AdNet Telecom, partener al evenimentului de astaziorganizat de Internet Society.AdNet este un furnizoralternativ de telecomunicatii – asiguraclientilorsai business acces Internet, servicii de comunicatiiunificate, transport de date national si international.AdNet oferadeasemeneaservicii IPTV, opereazapropriul datacenter siestedistribuitorpentrumarciconsacrate de echipamente ICT.Ceeace face insacompanianoastraunicaintrefurnizorii de telecomunicatiiesteserviciul de consultantatehnica, prin care putemsatisfacecerintelecomplexe de comunicatiisi IT ale clientilornostri.AdNet Telecom se pozitioneazacapartener al propriilorclienti, ceeaceimplica o concentrare a atentieicompanieinoastreasupraprovocarilor cu care se confruntaacestia din punct de vedere al comunicatiilorsi al securitatiidatelor.OK – As dorisavarog, pentru a vacunoastemai bine si a stabilicoordonatelediscutiei de azisa ma ajutatiprinridicareamainii:Cati din ceiprezentisuntactivimplicati in dezvoltareastrategiei IPv6 ale companieiundelucrati?Cat de familiarisunteti cu concepteletehnice ale protocoalelor IPv4/ IPv6?Va spun cevanotiunile de NAT / DHCP / CIDR? Ok, multumesc.Sa revenim la prezentare: Temaprezentarii de astaziestelegata de o scurtaintroducere in provocariletranzitiei la IPv6. 
  2. Vom intra in continuare direct in temadiscutiei de azi.…Dupa cum vedetipremizeleadoptieiIPv6 sugeraucavorasigura un succesgarantatnoului protocol, implementarilesuntinsarelativputine. In niciuncaz nu putemvorbidespreimplementaripescaralarga, decat cu uneleexceptii, notabiletotusi.Care sunttotusiconsiderentele care au dus la o rata de adoptiemodestapana in acest moment?----NEXT SLIDE
  3. Multdezbatutaepuizare a adreselor IPv4 ale Regional Internet Registries arataca in acestgrafic.Conform statisticilor de utilizare din ultimiiani, datele estimate de epuizare ale adreselor IPv4 de catre RIRs ar fi:ARIN – 2013LACNIC – 2014AfriNIC- 2014APNIC – epuizataRIPE – 2012---- NEXT SLIDE
  4. Industriatelecomunicatiiloreste in viatanoastra de aproape 200 de ani:1830 – primeleteste ale telegrafului1870 – inventareatelefonuluiPana in ziua de azi, au fostenorm de multedezvoltari ale industriei, care ne-au schimbatviataintr-o multitudine de privinte.Dar, nu toatealegeriletehnologicefacute de-a lungultimpului, au insemnat un pas major inainte:Nu se poatenumi un succesgreu de egalatdezvoltareatehnologiei ISDNSi nicigraba de dezvoltare a uneitehnologii broadband cum a fost ATMMai multdecatatat, multe din succeselerecente au fost o surpriza pentru cei din industrie, la vremealansarii:SMS-ul, cu modalitateaincomoda de scrieresilimitareanumarului de caractere a parut la lansare un serviciusortiteseculuisi …totusisute de miloane de oameniilfolosesc in mod regulat.Internetul a reprezentat o surprizasimilara. Totul a pornit de la experimenteleunorretele de cercetare, iarsuprizaadoptieiincredibil de rapidesi la o scalaatat de mare a reprezentat o surpriza de proportii pentru toatalumea.Cevreausa spun estecaindustria face alegerigresite cu aceeasiusurinta cu care face uneleexceptionale. Ceeace ma aduce la intrebarea:CUM VA ADMINISTRA INDUSTRIA ACEASTA TRANZITIE DE LA IPv4 la IPv6? VA FI UN SUCCES?TRANZITIA TEHNOLOGICA:Candpriviminapoi la tranzitiile care au avutloc in indistriatelecomunicatiilor, toate par extrem de logice. Scalarearetelelortelefonice la sfarsitulsecolului XIX reprezentadoar o problema de logistica “SA PUNEM MAI MULTE SIRME PE STALPI” Limita de scalabilitate era data de reziztentarespectivilorstalpi.INOVATIA / TRANZITIA tehnologicaulterioara a constat in multiplexareamaimultorcircuitedivizate in frecventa (FDM) peaceeasisirma.TRANZITIA tehnologicaulterioara a fost de trecere de la stream-ul analogic la datastream-ul digital, deciinlocuireamultiplexarii in frecventa cu multiplexarea in timp.DIN NOU< candprivim in retrospectiva, toatetranzitiile par extreme de logice.Chiarsitranzitia de la o retea cu comutare de circuite, la una cu comutare de pachete, pare foartelogica, deoareceesteevidentautilizareamultmaibuna a resurselor – MAI RAPID SI MAI IEFTIN – un motiv excellent pentru tranzitie.ESTE SI TRANZITIA DE LA IPv4 la IPv6 O ASTFEL DE TRANZITIE ?INEVITABILA ESTE CLAR CA ESTE, insaprimullucru, care este in defavoareauneitranzitiifirestiesteca IPv6 nu a fostproiectatsasuporte automat si IPv4Este deci evident catranzitiavapresupunerularea in parallel a celor 2 protocoale, adica o faza “DUAL STACK”.Lipsasuportului IPv4 nu a fostproiectata, probabil pentru cacei de la IETF au consideratcaindustriava face pasi de adoptiemultmairepedesi nu se vaajunge in faza de acum, candresursele IPv4 suntfoarteputinesiCEL MAI PROBABIL tranzitiavapresupune in aceastafazaintermediarainstalareaunor echipamente MIDDLEWARE, care safacatranslatiaadreselor IPv6 in adrese IPv4 (Carrier Grade NAT). Astaprobabilvainsemnasimutarea CDN-urilor in acesteretele de acces.AMENINTARI PENTRU TRANZITIENu exista un plan comun de adoptie la nivelmondialsau regional sinici national decat cu catevamici, darnotabile, exceptii.Resursele Regional Internet Registries nu se vortermina in acelasitimp, ceeaceinseamna, capelangacompetitivitatea care exista in industrie, NU AVEM UN SCOP COMUN Mareaintrebare care apare in urmaacestoramenintari, estedacavompastratelulcomun de a pastraInternetulca o “singura retea coerenta”. NB “Tezaurizarea” adreselor IPv4 – oarecumnaturalaatuncicand o resursadispare, proces care a inceputdejaintr-un ritmnesanatos, va face ca tot acestproces de tranzitie sa fie cu atatmaidificilsimaiputinpredictibil.
  5. IPv6 ofertavaloareafacerii din maimultepuncte de vedere.Din perspectiva COSTURILOR anumitecaracteristici ale IPv6 pot reduce costurile IT operationale ale organizatiei:- Autoconfigurareaimbunatatesteproceseleoperationalesireducerecosturile de mentenanta- Abundentaadreselor face inutilasiexistentaechipamentelorceasigurautranslatareaadreselor din arhitecturareteleiDin perspectiva VENITURILOR sidatoritaabundenteiadreselor, IPv6 permite o varietate de servicii siproduseinovative.PROTECTIA INVESTITIEI: datoritatrendurilormajoritatii content-providerilorsi Internet Service Providerilor, IPv6 vine si cu promisiuneaunuiciclu de viatamai lung, decatcheltuielice au in vederedoartehnologia IPv4. Din acestpunct de vedere un alt beneficiu important ilreprezintaimbunatatireaproceselor de business din perspectivaglobalizarii, ingreunate de arhitecturaceincludea NAT.INTEGRARE SISTEME: suportulnativ pentru mobilitatepermiteintegrareafacila a fortei de munca mobile.EXTENSIBILITATEA la noicapabilitati vine odata cu structuraextensibila a header-ului IPv6“INTERNET OF THINGS”: Una din propunerile de valoarecelemaiimportante ale IPv6 esterolulsau de a facilita emergent acestui concept – Internet of Things, care reprezintainterconectareatuturorobiectelorcomune din viatanoastra, cevor fi dotate cu inteligentaminiaturala (de la frigidere, pana la RFID in corpuluman). Deja cred caativazutdemonstratii ale frigiderului intelligent care comandaproduselesaajunga exact cand se epuizeaza, pebazaunorsenzorisi a comportamentuluiDvs de consum. Este ceeaceestenumit in industriecomunicatie de tip machine-to-machine. Futurologiispeculeazachiarcaaceastaetapa de dezvoltare din evolutiaInternetuluipoatereprezentaceamaiimportantaevolutietehnologica a umanitatii de la RevolutiaIndustriala.“No Killer App” - «The killer application of IPv6 is the survival of the openInternet as we know it.» - Lorenzo Colitti, Google
  6. Evitareaplanificariitranzitiei la IPv6 poateinsemnacrestereacosturilor ICT (vetiaveanevoie de tot felul de artificiitehnicepentru a depasiproblemaepuizariiadreselor, in contextul in care cumpararea de noiadrese IPv4 vadeveni tot maiscumpa, poateimplicacumpararea de noi echipamente – dublare NAT, samd)Operatoriimobilivor face primiitranzitia la IPv6 si nu vavorcereeisapuneticontentulsipe IPv6 catavremeclientiiloradolescenti pot accesaYoutubesi Facebook de pe device-urile mobile, inseamnacaInternetul “merge”. ContentulDvsinsa nu vaputea fi gasit/accesat.Dacavretisaputeti fi gasiti de clientii care migreazape IPv6 sau care primesc de la furnizorullordoaradrese IPv6 (clientiinoilor ISP, LTE)Companiile care castiga din activitatile online si pentru care o pierdere de catevaprocente a numarului de utilizatoriinseamnapierdere de profit, au fostcele care au creatstrategii de tranzitie incainainte de apropiereaepuizariiresurselor IPv4 Mari portiuni din Internet vordeveniinaccesibileodata cu epuizarearesurselor IPv4 sitrecerea la solutii IPv6-only (NAT64 oricat de bine ar fi proiectat, nefiindimplementat/testatextensiv, vorexistasurprize)Cearinsemnaca Facebook sau Google salansezeaplicaticevor fi disponibiledoar pentru clientii cu IPv6?Odataceclientiivorfolosi in mod extensiv IPv6, vorincepesa ignore contentulpe care ilgaseauprin NAT64
  7. Nu existamomentan o congruenta de opiniidespre cum trebuieabordatatranzitia la nivel Enterprise dpdv al securitatii, suntcelputin 2 curente de opinie.Fiind un adept al securitatiifaracompromisuri, recomandarea mea estevarianta 1, respectivcea de blocaretotala in reteapana la finalizareaunui audit extensivsi un eventual upgrade al echipamentelor de tip firewall/IPS/IDS.Ceamai mare ingrijorarelegata de securitateesteaceeacamulte echipamente din retea au capabilitati IPv6 activate, care le permit saforwardezetraficul IPv6 farasaildetectezesauinspecteze. Microsoft Windows Vista/Windows-7/Mac OS/ Google OS etc.In plus, majoritateasistemelor care nu au capabilitati IPv6 au capabilitatea de a incapsulapachete IPv6 cu header IPv4. Astainseamnacaheaderulpoate fi citit, darpachetul nu poate fi inspectat.Rezolvarea vine prinimplementarea dual-stack in retea, care permitedetectareasiinspectareatraficului IPv6.Responsabiliitehnicitrebuiedecisa se asigureca pot inspectapachetele IPv6, in cazcontrar pot forwardatraficmalitios.Chiarsiintr-o arhitectura dual-stack, trebuieasigurataparitateacapabilitatilorechipamentelor de analiza.Vesteabunaestecatranzitiavaduraanibuni, asaincattehnologia (hardware, software, etc), respectivfurnizorii de HW si SW voraveapresiunisuficientesa se maturizeze.
  8. 1. Business Case – continuitateaafacerii, explozianumarului de echipamentelorconectate la reteaua IP – mobile workforce, politiciguvrnamentale, etc.a. Beneficii – autoconfigurarea – simplificareaactivitatiloroperationale, oportunitati de a mentinesau de a lansanoi servicii, reduceri de costuri (in lipsaechipamentelor care ofereaua NAT), imbunatatireaperformanteiretelei, avantajestrategice, etc.b. Costuri – planificare, testare, implementare, upgrade-uri de infrastructura – a se incerca a face schimbarea la sfarsitulciclului de viata al actualelor echipamente cenecesitainlocuirea, software, aplicatii, training personal de suport, costurioperationaleulterioaretranzitiei, c. Riscuri: de business – putemobtinebeneficiile, de naturatehnica – in special riscurile de securitatesaulegala – pentru riscuri legate de confidentialitateadatelorutilizatorilor. Pentru fiecare din riscurileasociate, trebuiedocumentateactiunile de mitigare.2. Echipa de proiect – pentru a asigurasuccesultranzitieiestenevoie de o echipa cu rolurisiresponsabilitaticlare – “No one-man-show project”.3. Audit retea, servicii, echipamente, sisteme, aplicatii4. Elaborarea strategiei de tranzitie – utilizare IP-uri, forecast utilizare, PI sau PA, Mecanisme de tranzitie: Dual Stack, Tunele, Translatare, Securitate, Management retea etc.5. Analiza de impact. Buget. – Contactarevendori pentru platformelesiserviciilecenecesitatranzitia la IPv6, Resursenecesare (schimbare echipamente, training, buget) etc6. Dezvoltare plan de implementare – Listaproiectelor cu dependinteleintreele, mediusiimplementari de test, implementareatranzitiei, etc7. Training: constientizare (pentru totiangajatii), arhitectura, operational sisecuritate retea pentru departamentultehnic, etc.METODOLOGIIThere are three approaches for deploying IPv6 in a network:• Core to Edge: IPv6 is implemented fi rst in the routers forming the core of the network, usually using dual stacked interfaces, and progressivelyexpanded toward the edge of the network. This methodology has the advantage of implementing fi rst where it is easiest, as most core routersoftware either already supports IPv6 or can support it with a simple upgrade. This gains you more time to address the more diffi cult securityand management implementations as the core is being converted. Core to edge also tends to be the safest approach, allowing operations andengineering personnel time to become acquainted with the protocol before it reaches the users.• Edge to Core: IPv6 is implemented first at the edge of the network andthen expanded toward the core. Manual tunnels such as GRE or MPLSare used to connect edge devices across the core during the interim. This approach is advantageous when IPv6 must be turned up relatively quicklyfor a customer requiring it or when a network must otherwise demonstrate early IPv6 capability. It is also valuable when the core consists of legacyrouters that either cannot support IPv6 but can support a tunneling technology or that can only be upgraded with difficulty.• IPv6 Islands: Certain segments throughout the network, ranging from individual devices to complete sites, are converted. The islands can beinterconnected with manual or automatic tunnels, or a combination of the two. As the implementation project progresses, the IPv6-capableislands grow until they begin to merge, and toward the end of the project there are IPv4-only islands in the midst of an IPv6-capable ocean. Thisapproach is useful when the network’s existing IPv6 capabilities arescattered or when IPv6 must be quickly added to specialized systemsthroughout the network.
  9. Japan and South KoreaJapan was the first country to move forward with a concerted, governmentsupportedIPv6 initiative (the e-Japan Initiative). Innovative research continuesto be conducted by Japanese organizations such as the WIDE Project; amultitude of IPv6 protocol stacks for operating systems, IPv6 enabled systems,and IPv6 applications have come out of Japan. TAHI is one of the most widelyused IPv6 conformance and interoperability test suites. The IPv6 Ready logoprogram is managed from Japan. And NTT/Verio is far in advance of othertelecoms in the deployment of IPv6.The driver for Japan’s early enthusiasm was and continues to be the consumerelectronics industries on which represents such a large portion of the Japaneseeconomy. The makers of everything from game systems to mobile handsets tocameras understood the value of having their products connect to the Internet,and understood too that IPv4 did not have the address capacity to support thenumbers of network-enabled devices they envisioned. IPv6 was recognized bythe Japanese electronics industry, renowned for looking well beyond the nexttwo or three years, as vital to its continued growth and innovation.South Korea, whose economy was also powered by huge consumer electronicsmanufacturers, was not far behind Japan in its push for IPv6 adoption. LikeJapan, the South Korean government provided leadership and fi nancialincentives to early adopters. Taiwan, while not as far along as Japan and SouthKorea, is also motivated to support IPv6 because of its electronic industries.China and IndiaChina has a government-led and funded IPv6 deployment mandate called theChina Next-Generation Internet (CNGI) Project. And while China, like Japan andKorea, has a burgeoning electronics industry, their motivation for IPv6 comesmore from the size of their population and their dynamic economy. As wealth risesin China, more and more people are getting online both with PCs and with mobiledevices. At the end of 2008, there are approximately 654 million IPv4 addressesremaining; there are 1.3 billion people in the People’s Republic of China. Thereare not enough IPv4 addresses left to give even one address to every Chinesecitizen. IPv6 is the only way to bring the Internet to the Chinese population.China highlighted its progress with IPv6 at the 2008 Olympics. Lighting controlsystems and security cameras throughout the Olympic venues operated overIPv6, and IPv6-enabled sensors in taxis helped ease traffi c congestion.Close behind China in population size is India. And while the Indian economyis not yet expanding as fast as China’s, and has begun its expansionmore recently, it is growing. And while IPv6 deployment is not yet being asaggressively pushed as it is in China, the motivations for IPv6 in India are thesame as China’s and will soon be on the rise.United StatesWhile governments in Japan, South Korea, and China have spurred IPv6deployment through direct initiatives and funding, the United States governmentis pushing IPv6 though a different means. Rather than issuing policy directionsto service providers and network equipment vendors, it has issued mandatesthat government agencies themselves will adopt IPv6 and have made IPv6support a requirement for selling IP equipment and services to the government.These mandates began with the Department of Defense in 2003 and thenspread to other agencies through directives from the Office of Managementand Budget. Because the agencies of the US government collectively representan enormous customer base, service providers and vendors are scrambling tomeet federal IPv6 guidelines in order to protect existing business.Unlike Asian countries, the US government mandates are not primarily basedon anticipated IP address shortages. The Department of Defense, for example,has a huge reserve of IPv4 addresses. Instead, several expected improvementsin the protocol are driving federal interest such as superior IPv6 mobilecapabilities, better multicast features, and IPv6 plug-and-play addressing thatwill greatly improve peer-to-peer network models and make mobile ad-hocnetworks practical.The government is not alone in driving IPv6 adoption in the United States,however. Most of the world’s Tier 1 service providers are US-based, such asAT&T, Level 3, Global Crossing, Sprint, Qwest, and Verizon Business. Theseproviders, forming much of the “core” of the Internet, are looking closely atthe IPv4 depletion rates and understand the need to deploy IPv6 in order tocontinue expanding their business. All of them, accordingly, are either activelydeploying IPv6 or intend to begin deployment projects in the near future.US Internet application providers are also preparing for IPv6. For example,Google is currently implementing IPv6 to insure that their services are ready forthe growing number of IPv6 Internet users.EuropeMore IPv6 address allocations have been made to Europe than to any otherregion of the world. Most of this has to do with the number of individualEuropean countries active in the IPv6 arena, compared to the number ofcountries in other regions of the world pursuing IPv6. And while there arenumerous research and development projects happening throughout Europeancountries, there are also common motivations for IPv6 that can be attributed tothat region.A major driver for IPv6 in Europe is mobile telephony and European telcos’strong investments in 3G technology. Leadership in the adoption of IPv6has similarities to the government leadership in some Asian countries: TheEuropean Union staunchly supports IPv6 as a vehicle toward competitive growthand is funding over 30 research and development projects throughout itsmember countries. With its i2010 initiative, the EU plans for 25% of EuropeanInternet users to access the Internet and their most important content viaIPv6 by 2010. The EU is also focusing on the top 100 European websites,encouraging them to become IPv6 accessible.The EU also has a strategy similar to that of the US government, promotingthe adoption of IPv6 by encouraging its member states to include the protocolin their own network purchasing requirements. The EU is also making IPv6 arequirement for its own networks.Developing NationsWith new IPv4 addresses expected to become unavailable around 2011 – 2012,IPv6 is particularly important to developing nations who see demands for IPnetworks within their borders at or after that time. Internet access in thesecountries is expected to be primarily through mobile handsets rather thantraditional fi xed, PC-based networks. Therefore the issues of mobility, and themeans by which IPv6 provides superior capabilities to mobile networks, are ofgreat interest in such economies.