SlideShare a Scribd company logo
1 of 20
Download to read offline
Federal IPv6 Working Group
Innovative IPv6 Implementation with
        Least Cost Funding
John L Lee, CTO
    Co-Chair, IPv6 Address Planning Team, ACT-IAC,
                 Federal IPv6 Task Force




         Internet Associates, LLC A Certified VOSB
                        November 13, 2012                                 1
                 •©2012 Internet Associates, LLC; All Rights Reserved..
Disclaimer



 The opinions contained in this brief are
 those of the author and do not reflect an
 official position of the United States
 Government, ACT-IAC, Internet Associates
 or any other entity
                                             2
USG IPv6 Strategy
 Integration with other CIO/IT initiatives
   Integral to Digital Government
   DNSSEC, Trusted Internet Connection (TIC)
 No or small incremental costs for v6
  deployment – this is a funded initiative
   Federal Acquisition Regulations (FAR)
   Federal Enterprise Architecture (FEA)
   Sustainment and Technology refresh dollars
 Conformance Testing
                                                 3
USG IPv6 Timeline
 1994 Forward - USG involved in Next Gen Network
 Oct. 2003 - DoD mandates IPv6
 August 2005 - Memorandum M-05-22, “Transition Planning
    for Internet Protocol Version 6 (IPv6)” (June 2008)
   June 2008 - IPv6 traffic passed on USG backbones
   May 2009 - Initial release of Roadmap Document
   Dec. 2009 - FAR IPv6 regulations go into affect
   Sept. 2010 - OMB Memo on “Transition to IPv6”
   July 2012 - Version 2.0 Roadmap Document Released
   Sept. 2012 - 35% of USG Domains
   Sept. 2014 - v6 supported on certain backbone elements
                                                         4
Federal IPv6 Task Force




                          5
 is a non-profit, public-private partnership dedicated to
  improving government through the application of
  information technology. ACT-IAC provides an objective,
  ethical and trusted forum where government and industry
  exchange information and collaborate on technology
  issues in the public sector
 Networks & Telecommunications SIG
    IPv6 Working Group
        Address Management
        Project Plan
        Security
                                                             6
FAR IPv6 Requirements
 FAR 7.105(b)(4)
(iii) For information technology acquisitions using Internet Protocol, discuss whether the requirements
documents include the Internet Protocol compliance requirements specified in 11.002(g) or a waiver of these
requirements has been granted by the agency’s Chief Information Officer.
 FAR 11.002(g)
(g) Unless the agency Chief Information Officer waives the requirement, when acquiring information technology
using Internet Protocol, the requirements documents must include reference to the appropriate technical
capabilities defined in the USGv6 Profile (NIST Special Publication 500-267) and the corresponding
declarations of conformance defined in the USGv6 Test Program. The applicability of IPv6 to agency networks,
infrastructure, and applications specific to individual acquisitions will be in accordance with standards identified
in the agency’s Enterprise Architecture (see OMB Memorandum M-05-22 dated August 2, 2005).
 FAR 12.202(e)
(e) When acquiring information technology using Internet Protocol, agencies must include the appropriate
Internet Protocol compliance requirements in accordance with 11.002(g).
 FAR 39.101(e)
(e) When acquiring information technology using Internet Protocol, agencies must include the appropriate
Internet Protocol compliance requirements in accordance with 11.002(g).
                                                                                                                   7
Federal CIO Initiatives
 Digital Government -Building a 21st Century
  Platform to Better Serve the American
  People
 IT Modernization, USG Configuration
  Baseline, HSPD-12 ( Secure ID)
 Cloud Computing: Cloud First Strategy
 Federal Data Center Consolidation Initiative
  (FDCCI)
   Server, Appliance or Virtual Machine
                                             8
Federal CIO Initiatives …
 2012 Planning Guide/Roadmap Toward
 IPv6 Adoption within the U.S. Government
   Supports a Central Addressing Authority
   Secure Network wide Access
   Automated IP Address Planning, Design,
    Management and Deployment
   Multi-vendor DNS, DHCP AND AAA
      Auto generation of A, AAAA and reverse zone RR

                                                        9
 This is not your fathers v4
 network …

 Do not apply v4 thinking and design
 constraints to v6 networks
   Ron Broersma, DREN Chief Engineer


                                        10
Network Reliability Categories
 National Command Authority
 Life Safety                FAA, Medical, Fire, Police
 Service Provider                 5,000 - 10,000
 Enterprise                         100 - 1,000
 “Home” or Subscriber                 1 - 10
 Service Provider Network Requirements
    Designed, Engineered, Secured and Tested
    Integrated, Automated systems
    Two vendor policy for devices, network services
     (DNS, DHCP, AAA) and circuits

                                                       11
Operating Support Systems                                        Network Management




     Device Inventory                                                 Device OS
     Device & Interface Config                                        Device Status
                                                                      Interface Status




                    IP Address List                         IP Address List




                                       IP Address List




                                      Identity Management
                                      Security Policy
                                      BGP & DNS SEC



                                                                   Cyber Security
                                                                                         12
Operating Support Systems                      Network Management




          Device Inventory                              Device OS
          Device & Interface Config       DNS           Device Status
                                          DHCP          Interface Status



                                       IP Address
                                       Lifecycle
                                       Management




Firewall Config                                                            Net Flow
 Firewall Rules                                                            System Events & Logs
                                                                           Security Events & Logs


                                  Identity Management
                                  Security Policy
                                  BGP & DNS SEC




                                      Cyber Security
                                                                                                    13
20 Critical Controls – Consensus Audit
                   Guidelines
 Inventory for Authorized & Unauthorized
    Devices & Software (1&2)
   Secure Configurations for Hardware & Software
    on Laptops, Workstations & Servers (3)
   Secure Configurations for Network Devices such
    as Firewalls, Routers & Switches (4)
   Boundary Defense (5)
   Maintenance, Monitoring, and Analysis of
    Security Audit Logs (6)
                                                 14
20 Critical Controls – Consensus Audit
                  Guidelines …
 Continuous Vulnerability Assessment &
    Remediation (10)
   Account Monitoring & Control (11)
   Malware Defenses (12)
   Limitation & Control of Network Ports, Protocols
    & Services (13)
   Wireless Device Control (14)
   Secure Network Engineering (16)
   Penetration Tests and Red Team Exercises (17)
                                                   15
Cyber Security Eco-System




                                                                                                                                                        16
•*IPal Technology is covered under U.S. Patents 7,127,505, 7,330,907, 7,523,189, 7,558,881, 7,739,406 and other US and International Patents Pending.
USG Stats as of Sept. 2012
 The official repository of USG domains, data.gov has
    ~1,500 domain and sub-domains.
   ~800 domains made some progress in operational
    deployment. Those domains span dozens of distinct
    enterprises, CIO shops, vendor/contractors and
    deployment environments.
   ~30% of public web .gov sites monitored are IPv6 enabled.
   Scores of commercial products have been conformance
    and interoperability tested through the USGv6 Program.
    http://www-x.antd.nist.gov/usgv6/products.html
   If you look at the historical graphs, you will see significant
    progress over the last 6 months. http://usgv6-
    deployment.antd.nist.gov/cgi-bin/generate-gov
                                                                17
Resources
 Planning Guide/Roadmap Toward IPv6
 Adoption within the U.S. Government
   https://cio.gov/wp-
    content/uploads/downloads/2012/09/2012_IPv6_Roa
    dmap_FINAL_20120712.pdf
 Digital Government Initiative
   http://www.whitehouse.gov/sites/default/files/omb/ego
    v/digital-government/digital-government.html



                                                        18
Industry Contributors
   Chris Chroniger – Chair   Acentia
   Dale Geesey               Auspex Technologies
   Kenny Burroughs           Internet Associates
   Barry Chapman             Acentia
   Jeremy Duncan             Salient Federal
   TJ Evans                  Nephos6
   Joe Klein                 QinetiQ, North America
   Tim Owen                  SMS
   Chip Popoviciu            Nephos6
   Yanick Pouffary           HP
   Yurie Rich                Nephos6
   Kristofer Smith           Auspex Technologies
   Frank Troy                Troy Networks
   Ralph Wallace             White Oak Consulting     19
Contact Information
 John L. Lee, CTO
   john@internetassociatesllc.com
    +1-678-488-6085


 Internet Associates, LLC
   +1-855-GET-IPV6
    +1-770-495-0953


                                     20

More Related Content

What's hot

Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zeroCisco Canada
 
Resume Of Ifthekharul Islam_2016_V1.5
Resume Of Ifthekharul Islam_2016_V1.5Resume Of Ifthekharul Islam_2016_V1.5
Resume Of Ifthekharul Islam_2016_V1.5Ifthekharul Islam
 
[Cisco Connect 2018 - Vietnam] Yedu hn-introducing cisco dna assurance-yedu f...
[Cisco Connect 2018 - Vietnam] Yedu hn-introducing cisco dna assurance-yedu f...[Cisco Connect 2018 - Vietnam] Yedu hn-introducing cisco dna assurance-yedu f...
[Cisco Connect 2018 - Vietnam] Yedu hn-introducing cisco dna assurance-yedu f...Nur Shiqim Chok
 
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...Cisco Canada
 
Foundry technical intro
Foundry technical introFoundry technical intro
Foundry technical introesseemme69
 
Arch Rock Overview
Arch Rock OverviewArch Rock Overview
Arch Rock Overviewpauldeng
 
LSI Corporate Presentation
LSI Corporate PresentationLSI Corporate Presentation
LSI Corporate PresentationJWSabatino
 
Cisco connect winnipeg 2018 simply powerful networking with meraki
Cisco connect winnipeg 2018   simply powerful networking with merakiCisco connect winnipeg 2018   simply powerful networking with meraki
Cisco connect winnipeg 2018 simply powerful networking with merakiCisco Canada
 
Gtb Dlp & Irm Solution Product And Deployment Overview
Gtb Dlp & Irm Solution   Product And Deployment OverviewGtb Dlp & Irm Solution   Product And Deployment Overview
Gtb Dlp & Irm Solution Product And Deployment Overviewgtbsalesindia
 
Bapinger Network Security
Bapinger Network SecurityBapinger Network Security
Bapinger Network SecurityDjadja Sardjana
 
Cisco connect winnipeg 2018 simplifying cloud adoption with cisco ucs
Cisco connect winnipeg 2018   simplifying cloud adoption with cisco ucsCisco connect winnipeg 2018   simplifying cloud adoption with cisco ucs
Cisco connect winnipeg 2018 simplifying cloud adoption with cisco ucsCisco Canada
 
Cisco Connect Toronto 2017 - Simplifying Cloud Adoption
Cisco Connect Toronto 2017 - Simplifying Cloud AdoptionCisco Connect Toronto 2017 - Simplifying Cloud Adoption
Cisco Connect Toronto 2017 - Simplifying Cloud AdoptionCisco Canada
 
GTB Technologies Datasheet 2014
GTB Technologies Datasheet 2014GTB Technologies Datasheet 2014
GTB Technologies Datasheet 2014Ravindran Vasu
 
Proxy-Oriented Data Uploading & Monitoring Remote Data Integrity in Public Cloud
Proxy-Oriented Data Uploading & Monitoring Remote Data Integrity in Public CloudProxy-Oriented Data Uploading & Monitoring Remote Data Integrity in Public Cloud
Proxy-Oriented Data Uploading & Monitoring Remote Data Integrity in Public CloudIRJET Journal
 
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...Cisco Canada
 
PCI DSS v 3.0 and Oracle Security Mapping
PCI DSS v 3.0 and Oracle Security MappingPCI DSS v 3.0 and Oracle Security Mapping
PCI DSS v 3.0 and Oracle Security MappingTroy Kitch
 
IRJET- An Approach to Authenticating Devise in IoT using Blockchain
IRJET-  	  An Approach to Authenticating Devise in IoT using BlockchainIRJET-  	  An Approach to Authenticating Devise in IoT using Blockchain
IRJET- An Approach to Authenticating Devise in IoT using BlockchainIRJET Journal
 

What's hot (20)

Cisco Connect Toronto 2018 sixty to zero
Cisco Connect Toronto 2018   sixty to zeroCisco Connect Toronto 2018   sixty to zero
Cisco Connect Toronto 2018 sixty to zero
 
Decision group company_profile_2017
Decision group company_profile_2017Decision group company_profile_2017
Decision group company_profile_2017
 
Resume Of Ifthekharul Islam_2016_V1.5
Resume Of Ifthekharul Islam_2016_V1.5Resume Of Ifthekharul Islam_2016_V1.5
Resume Of Ifthekharul Islam_2016_V1.5
 
[Cisco Connect 2018 - Vietnam] Yedu hn-introducing cisco dna assurance-yedu f...
[Cisco Connect 2018 - Vietnam] Yedu hn-introducing cisco dna assurance-yedu f...[Cisco Connect 2018 - Vietnam] Yedu hn-introducing cisco dna assurance-yedu f...
[Cisco Connect 2018 - Vietnam] Yedu hn-introducing cisco dna assurance-yedu f...
 
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...Cisco Connect Toronto 2018   DNA automation-the evolution to intent-based net...
Cisco Connect Toronto 2018 DNA automation-the evolution to intent-based net...
 
Foundry technical intro
Foundry technical introFoundry technical intro
Foundry technical intro
 
Arch Rock Overview
Arch Rock OverviewArch Rock Overview
Arch Rock Overview
 
LSI Corporate Presentation
LSI Corporate PresentationLSI Corporate Presentation
LSI Corporate Presentation
 
Sideband_SB_020316
Sideband_SB_020316Sideband_SB_020316
Sideband_SB_020316
 
Data Leakage Prevention
Data Leakage PreventionData Leakage Prevention
Data Leakage Prevention
 
Cisco connect winnipeg 2018 simply powerful networking with meraki
Cisco connect winnipeg 2018   simply powerful networking with merakiCisco connect winnipeg 2018   simply powerful networking with meraki
Cisco connect winnipeg 2018 simply powerful networking with meraki
 
Gtb Dlp & Irm Solution Product And Deployment Overview
Gtb Dlp & Irm Solution   Product And Deployment OverviewGtb Dlp & Irm Solution   Product And Deployment Overview
Gtb Dlp & Irm Solution Product And Deployment Overview
 
Bapinger Network Security
Bapinger Network SecurityBapinger Network Security
Bapinger Network Security
 
Cisco connect winnipeg 2018 simplifying cloud adoption with cisco ucs
Cisco connect winnipeg 2018   simplifying cloud adoption with cisco ucsCisco connect winnipeg 2018   simplifying cloud adoption with cisco ucs
Cisco connect winnipeg 2018 simplifying cloud adoption with cisco ucs
 
Cisco Connect Toronto 2017 - Simplifying Cloud Adoption
Cisco Connect Toronto 2017 - Simplifying Cloud AdoptionCisco Connect Toronto 2017 - Simplifying Cloud Adoption
Cisco Connect Toronto 2017 - Simplifying Cloud Adoption
 
GTB Technologies Datasheet 2014
GTB Technologies Datasheet 2014GTB Technologies Datasheet 2014
GTB Technologies Datasheet 2014
 
Proxy-Oriented Data Uploading & Monitoring Remote Data Integrity in Public Cloud
Proxy-Oriented Data Uploading & Monitoring Remote Data Integrity in Public CloudProxy-Oriented Data Uploading & Monitoring Remote Data Integrity in Public Cloud
Proxy-Oriented Data Uploading & Monitoring Remote Data Integrity in Public Cloud
 
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...
Cisco Connect Vancouver 2017 - Cloud and on premises collaboration security e...
 
PCI DSS v 3.0 and Oracle Security Mapping
PCI DSS v 3.0 and Oracle Security MappingPCI DSS v 3.0 and Oracle Security Mapping
PCI DSS v 3.0 and Oracle Security Mapping
 
IRJET- An Approach to Authenticating Devise in IoT using Blockchain
IRJET-  	  An Approach to Authenticating Devise in IoT using BlockchainIRJET-  	  An Approach to Authenticating Devise in IoT using Blockchain
IRJET- An Approach to Authenticating Devise in IoT using Blockchain
 

Similar to Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with John Leland Lee at gogoNET LIVE! 3 IPv6 Conference

Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...Cisco Russia
 
IPv6IntegrationBestPracticesfinal.pdf
IPv6IntegrationBestPracticesfinal.pdfIPv6IntegrationBestPracticesfinal.pdf
IPv6IntegrationBestPracticesfinal.pdfCPUHogg
 
Session Sponsored by Intel: Smart Cities, Infrastructure and Health powered b...
Session Sponsored by Intel: Smart Cities, Infrastructure and Health powered b...Session Sponsored by Intel: Smart Cities, Infrastructure and Health powered b...
Session Sponsored by Intel: Smart Cities, Infrastructure and Health powered b...Amazon Web Services
 
onePK The Swiss Army Knife for Network Programming
onePK The Swiss Army Knife for Network ProgrammingonePK The Swiss Army Knife for Network Programming
onePK The Swiss Army Knife for Network ProgrammingCisco DevNet
 
How a Cloud Computing Provider Reached the Holy Grail of Visibility
How a Cloud Computing Provider Reached the Holy Grail of VisibilityHow a Cloud Computing Provider Reached the Holy Grail of Visibility
How a Cloud Computing Provider Reached the Holy Grail of Visibilityeladgotfrid
 
Io t a_de_techgigwebinar_04nov2016
Io t a_de_techgigwebinar_04nov2016Io t a_de_techgigwebinar_04nov2016
Io t a_de_techgigwebinar_04nov2016Dr. Aloknath De
 
AWS re:Invent 2016: Enel E2E Smart Home Solution with Amazon Alexa (IOT308)
AWS re:Invent 2016: Enel E2E Smart Home Solution with Amazon Alexa (IOT308)AWS re:Invent 2016: Enel E2E Smart Home Solution with Amazon Alexa (IOT308)
AWS re:Invent 2016: Enel E2E Smart Home Solution with Amazon Alexa (IOT308)Amazon Web Services
 
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIsIncredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIsRobb Boyd
 
IPv6 for the Enterprise
IPv6 for the EnterpriseIPv6 for the Enterprise
IPv6 for the EnterpriseJohn Rhoton
 
Role of cloud and analytics in IoT
Role of cloud and analytics in IoTRole of cloud and analytics in IoT
Role of cloud and analytics in IoTSelvaraj Kesavan
 
IoT Panel- Cisco and Intel
IoT Panel- Cisco and Intel IoT Panel- Cisco and Intel
IoT Panel- Cisco and Intel Bessie Wang
 
Gra implementations perbix_search
Gra implementations perbix_searchGra implementations perbix_search
Gra implementations perbix_searchICJIA Webmaster
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...Cisco Canada
 
Internet of Everything - Edson Celestino.
Internet of Everything - Edson Celestino. Internet of Everything - Edson Celestino.
Internet of Everything - Edson Celestino. E-COMMERCE MX 2015
 
Security Delivery Platform: Best practices
Security Delivery Platform: Best practicesSecurity Delivery Platform: Best practices
Security Delivery Platform: Best practicesMihajlo Prerad
 
Splunk Overview
Splunk OverviewSplunk Overview
Splunk OverviewSplunk
 
Core Network Optimization: The Control Plane, Data Plane & Beyond
Core Network Optimization: The Control Plane, Data Plane & BeyondCore Network Optimization: The Control Plane, Data Plane & Beyond
Core Network Optimization: The Control Plane, Data Plane & BeyondRadisys Corporation
 

Similar to Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with John Leland Lee at gogoNET LIVE! 3 IPv6 Conference (20)

Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
Как развернуть кампусную сеть Cisco за 10 минут? Новые технологии для автомат...
 
IPv6IntegrationBestPracticesfinal.pdf
IPv6IntegrationBestPracticesfinal.pdfIPv6IntegrationBestPracticesfinal.pdf
IPv6IntegrationBestPracticesfinal.pdf
 
Session Sponsored by Intel: Smart Cities, Infrastructure and Health powered b...
Session Sponsored by Intel: Smart Cities, Infrastructure and Health powered b...Session Sponsored by Intel: Smart Cities, Infrastructure and Health powered b...
Session Sponsored by Intel: Smart Cities, Infrastructure and Health powered b...
 
onePK The Swiss Army Knife for Network Programming
onePK The Swiss Army Knife for Network ProgrammingonePK The Swiss Army Knife for Network Programming
onePK The Swiss Army Knife for Network Programming
 
How a Cloud Computing Provider Reached the Holy Grail of Visibility
How a Cloud Computing Provider Reached the Holy Grail of VisibilityHow a Cloud Computing Provider Reached the Holy Grail of Visibility
How a Cloud Computing Provider Reached the Holy Grail of Visibility
 
Io t a_de_techgigwebinar_04nov2016
Io t a_de_techgigwebinar_04nov2016Io t a_de_techgigwebinar_04nov2016
Io t a_de_techgigwebinar_04nov2016
 
AWS re:Invent 2016: Enel E2E Smart Home Solution with Amazon Alexa (IOT308)
AWS re:Invent 2016: Enel E2E Smart Home Solution with Amazon Alexa (IOT308)AWS re:Invent 2016: Enel E2E Smart Home Solution with Amazon Alexa (IOT308)
AWS re:Invent 2016: Enel E2E Smart Home Solution with Amazon Alexa (IOT308)
 
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIsIncredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
Incredible Compute Density: Cisco DNA Center Platform: Digging Deeper with APIs
 
IPv6 for the Enterprise
IPv6 for the EnterpriseIPv6 for the Enterprise
IPv6 for the Enterprise
 
Finto InfoSec ExIBM- CISSP ITIL CCSP CCIE JNCIS MCP 8.5 Yrs
Finto InfoSec ExIBM- CISSP ITIL CCSP CCIE  JNCIS MCP 8.5  YrsFinto InfoSec ExIBM- CISSP ITIL CCSP CCIE  JNCIS MCP 8.5  Yrs
Finto InfoSec ExIBM- CISSP ITIL CCSP CCIE JNCIS MCP 8.5 Yrs
 
Ipadd mngt
Ipadd mngtIpadd mngt
Ipadd mngt
 
Role of cloud and analytics in IoT
Role of cloud and analytics in IoTRole of cloud and analytics in IoT
Role of cloud and analytics in IoT
 
IoT Panel- Cisco and Intel
IoT Panel- Cisco and Intel IoT Panel- Cisco and Intel
IoT Panel- Cisco and Intel
 
Gra implementations perbix_search
Gra implementations perbix_searchGra implementations perbix_search
Gra implementations perbix_search
 
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...Cisco Connect Toronto 2018   sd-wan - delivering intent-based networking to t...
Cisco Connect Toronto 2018 sd-wan - delivering intent-based networking to t...
 
Internet of Everything - Edson Celestino.
Internet of Everything - Edson Celestino. Internet of Everything - Edson Celestino.
Internet of Everything - Edson Celestino.
 
Security Delivery Platform: Best practices
Security Delivery Platform: Best practicesSecurity Delivery Platform: Best practices
Security Delivery Platform: Best practices
 
Splunk Overview
Splunk OverviewSplunk Overview
Splunk Overview
 
MWC 2010 DPI
MWC 2010 DPIMWC 2010 DPI
MWC 2010 DPI
 
Core Network Optimization: The Control Plane, Data Plane & Beyond
Core Network Optimization: The Control Plane, Data Plane & BeyondCore Network Optimization: The Control Plane, Data Plane & Beyond
Core Network Optimization: The Control Plane, Data Plane & Beyond
 

More from gogo6

Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...
Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...
Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...gogo6
 
IoT Field Area Network Solutions & Integration of IPv6 Standards by Patrick G...
IoT Field Area Network Solutions & Integration of IPv6 Standards by Patrick G...IoT Field Area Network Solutions & Integration of IPv6 Standards by Patrick G...
IoT Field Area Network Solutions & Integration of IPv6 Standards by Patrick G...gogo6
 
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...gogo6
 
Welcome to gogoNET LIVE! 3 - Updates on the CAv6TF and NAv6TF by George Usi a...
Welcome to gogoNET LIVE! 3 - Updates on the CAv6TF and NAv6TF by George Usi a...Welcome to gogoNET LIVE! 3 - Updates on the CAv6TF and NAv6TF by George Usi a...
Welcome to gogoNET LIVE! 3 - Updates on the CAv6TF and NAv6TF by George Usi a...gogo6
 
A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...
A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...
A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...gogo6
 
Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...
Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...
Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...gogo6
 
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...gogo6
 

More from gogo6 (7)

Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...
Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...
Scaling the Web to Billions of Nodes: Towards the IPv6 “Internet of Things” b...
 
IoT Field Area Network Solutions & Integration of IPv6 Standards by Patrick G...
IoT Field Area Network Solutions & Integration of IPv6 Standards by Patrick G...IoT Field Area Network Solutions & Integration of IPv6 Standards by Patrick G...
IoT Field Area Network Solutions & Integration of IPv6 Standards by Patrick G...
 
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with ...
 
Welcome to gogoNET LIVE! 3 - Updates on the CAv6TF and NAv6TF by George Usi a...
Welcome to gogoNET LIVE! 3 - Updates on the CAv6TF and NAv6TF by George Usi a...Welcome to gogoNET LIVE! 3 - Updates on the CAv6TF and NAv6TF by George Usi a...
Welcome to gogoNET LIVE! 3 - Updates on the CAv6TF and NAv6TF by George Usi a...
 
A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...
A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...
A10 Networks: IPv6 Solutions for Enterprise by Paul Nicholson at gogoNET LIVE...
 
Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...
Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...
Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...
 
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
Troubleshooting Dual-Protocol Networks and Systems by Scott Hogg at gogoNET L...
 

Panel Discussion: Small Steps for USGv6 a giant leap for Internet-kind? with John Leland Lee at gogoNET LIVE! 3 IPv6 Conference

  • 1. Federal IPv6 Working Group Innovative IPv6 Implementation with Least Cost Funding John L Lee, CTO Co-Chair, IPv6 Address Planning Team, ACT-IAC, Federal IPv6 Task Force Internet Associates, LLC A Certified VOSB November 13, 2012 1 •©2012 Internet Associates, LLC; All Rights Reserved..
  • 2. Disclaimer  The opinions contained in this brief are those of the author and do not reflect an official position of the United States Government, ACT-IAC, Internet Associates or any other entity 2
  • 3. USG IPv6 Strategy  Integration with other CIO/IT initiatives  Integral to Digital Government  DNSSEC, Trusted Internet Connection (TIC)  No or small incremental costs for v6 deployment – this is a funded initiative  Federal Acquisition Regulations (FAR)  Federal Enterprise Architecture (FEA)  Sustainment and Technology refresh dollars  Conformance Testing 3
  • 4. USG IPv6 Timeline  1994 Forward - USG involved in Next Gen Network  Oct. 2003 - DoD mandates IPv6  August 2005 - Memorandum M-05-22, “Transition Planning for Internet Protocol Version 6 (IPv6)” (June 2008)  June 2008 - IPv6 traffic passed on USG backbones  May 2009 - Initial release of Roadmap Document  Dec. 2009 - FAR IPv6 regulations go into affect  Sept. 2010 - OMB Memo on “Transition to IPv6”  July 2012 - Version 2.0 Roadmap Document Released  Sept. 2012 - 35% of USG Domains  Sept. 2014 - v6 supported on certain backbone elements 4
  • 6.  is a non-profit, public-private partnership dedicated to improving government through the application of information technology. ACT-IAC provides an objective, ethical and trusted forum where government and industry exchange information and collaborate on technology issues in the public sector  Networks & Telecommunications SIG  IPv6 Working Group  Address Management  Project Plan  Security 6
  • 7. FAR IPv6 Requirements  FAR 7.105(b)(4) (iii) For information technology acquisitions using Internet Protocol, discuss whether the requirements documents include the Internet Protocol compliance requirements specified in 11.002(g) or a waiver of these requirements has been granted by the agency’s Chief Information Officer.  FAR 11.002(g) (g) Unless the agency Chief Information Officer waives the requirement, when acquiring information technology using Internet Protocol, the requirements documents must include reference to the appropriate technical capabilities defined in the USGv6 Profile (NIST Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program. The applicability of IPv6 to agency networks, infrastructure, and applications specific to individual acquisitions will be in accordance with standards identified in the agency’s Enterprise Architecture (see OMB Memorandum M-05-22 dated August 2, 2005).  FAR 12.202(e) (e) When acquiring information technology using Internet Protocol, agencies must include the appropriate Internet Protocol compliance requirements in accordance with 11.002(g).  FAR 39.101(e) (e) When acquiring information technology using Internet Protocol, agencies must include the appropriate Internet Protocol compliance requirements in accordance with 11.002(g). 7
  • 8. Federal CIO Initiatives  Digital Government -Building a 21st Century Platform to Better Serve the American People  IT Modernization, USG Configuration Baseline, HSPD-12 ( Secure ID)  Cloud Computing: Cloud First Strategy  Federal Data Center Consolidation Initiative (FDCCI)  Server, Appliance or Virtual Machine 8
  • 9. Federal CIO Initiatives …  2012 Planning Guide/Roadmap Toward IPv6 Adoption within the U.S. Government  Supports a Central Addressing Authority  Secure Network wide Access  Automated IP Address Planning, Design, Management and Deployment  Multi-vendor DNS, DHCP AND AAA  Auto generation of A, AAAA and reverse zone RR 9
  • 10.  This is not your fathers v4 network …  Do not apply v4 thinking and design constraints to v6 networks Ron Broersma, DREN Chief Engineer 10
  • 11. Network Reliability Categories  National Command Authority  Life Safety FAA, Medical, Fire, Police  Service Provider 5,000 - 10,000  Enterprise 100 - 1,000  “Home” or Subscriber 1 - 10  Service Provider Network Requirements  Designed, Engineered, Secured and Tested  Integrated, Automated systems  Two vendor policy for devices, network services (DNS, DHCP, AAA) and circuits 11
  • 12. Operating Support Systems Network Management Device Inventory Device OS Device & Interface Config Device Status Interface Status IP Address List IP Address List IP Address List Identity Management Security Policy BGP & DNS SEC Cyber Security 12
  • 13. Operating Support Systems Network Management Device Inventory Device OS Device & Interface Config DNS Device Status DHCP Interface Status IP Address Lifecycle Management Firewall Config Net Flow Firewall Rules System Events & Logs Security Events & Logs Identity Management Security Policy BGP & DNS SEC Cyber Security 13
  • 14. 20 Critical Controls – Consensus Audit Guidelines  Inventory for Authorized & Unauthorized Devices & Software (1&2)  Secure Configurations for Hardware & Software on Laptops, Workstations & Servers (3)  Secure Configurations for Network Devices such as Firewalls, Routers & Switches (4)  Boundary Defense (5)  Maintenance, Monitoring, and Analysis of Security Audit Logs (6) 14
  • 15. 20 Critical Controls – Consensus Audit Guidelines …  Continuous Vulnerability Assessment & Remediation (10)  Account Monitoring & Control (11)  Malware Defenses (12)  Limitation & Control of Network Ports, Protocols & Services (13)  Wireless Device Control (14)  Secure Network Engineering (16)  Penetration Tests and Red Team Exercises (17) 15
  • 16. Cyber Security Eco-System 16 •*IPal Technology is covered under U.S. Patents 7,127,505, 7,330,907, 7,523,189, 7,558,881, 7,739,406 and other US and International Patents Pending.
  • 17. USG Stats as of Sept. 2012  The official repository of USG domains, data.gov has ~1,500 domain and sub-domains.  ~800 domains made some progress in operational deployment. Those domains span dozens of distinct enterprises, CIO shops, vendor/contractors and deployment environments.  ~30% of public web .gov sites monitored are IPv6 enabled.  Scores of commercial products have been conformance and interoperability tested through the USGv6 Program. http://www-x.antd.nist.gov/usgv6/products.html  If you look at the historical graphs, you will see significant progress over the last 6 months. http://usgv6- deployment.antd.nist.gov/cgi-bin/generate-gov 17
  • 18. Resources  Planning Guide/Roadmap Toward IPv6 Adoption within the U.S. Government  https://cio.gov/wp- content/uploads/downloads/2012/09/2012_IPv6_Roa dmap_FINAL_20120712.pdf  Digital Government Initiative  http://www.whitehouse.gov/sites/default/files/omb/ego v/digital-government/digital-government.html 18
  • 19. Industry Contributors  Chris Chroniger – Chair Acentia  Dale Geesey Auspex Technologies  Kenny Burroughs Internet Associates  Barry Chapman Acentia  Jeremy Duncan Salient Federal  TJ Evans Nephos6  Joe Klein QinetiQ, North America  Tim Owen SMS  Chip Popoviciu Nephos6  Yanick Pouffary HP  Yurie Rich Nephos6  Kristofer Smith Auspex Technologies  Frank Troy Troy Networks  Ralph Wallace White Oak Consulting 19
  • 20. Contact Information  John L. Lee, CTO  john@internetassociatesllc.com +1-678-488-6085  Internet Associates, LLC  +1-855-GET-IPV6 +1-770-495-0953 20