SlideShare a Scribd company logo
1 of 22
Download to read offline
Presenting speaker
Benjamin T.P. Tan
Network Security
IPv4 + IPv6
Benjamin T.P. Tan
Managing Director
SuperInternet
by
Presenting speaker
Benjamin T.P. Tan
Overview
• Confidentiality? Integrity? Availability!
• IPv6 Issues (Compared with IPv4)
• Physical Security of the Network
Assumptions:
• Generally familiar with
– Network Security
– Telecommunications Infrastructure
• Technical Management
• We only have 45 mins
Presenting speaker
Benjamin T.P. Tan
Neglected Areas
• Not the usual Topics: IPSec, VPNs, SSL VPNs, PKI,
Firewalls, IDS/IPS
– Confidentiality on the Network
• Many available solutions
• Data Integrity on the Network
– Several issues solved by end-to-end crypto
(Application) IF implemented. Else Network
HELPS!
– Somewhat known solutions: DHCP Snooping, ARP
inspection, L3 Micro segmentation
– Routing Subversion
• Network Availability
– DoS at all levels
– Physical Infrastructure Weaknesses
• New-Old Issues: IPv6 vs IPv4 and back again.
Presenting speaker
Benjamin T.P. Tan
IPv6 – Dual Stack
• 2 protocols on the same wire
• VLANs still segregate
• BUT IPv4 Subnets DO NOT
New-Old Problems:
• IPv6 Global Unicast Addresses
– PUBLIC IP on the machine!
– IF configured route-able then node is fully
exposed to the Internet
Presenting speaker
Benjamin T.P. Tan
IPv4 DHCP Issues
• Flashback before IPv6
• IP Address Conflicts?!
• Rogue DHCP Servers
– APs on your LAN?!
• Users Setting Static IPs
– Desktop Lockdown?
• DHCP Snooping and IP Source Guard
ip source binding mac-address Vlan vlan-id ip-address
interface interface-name
(Conf-if) ip verify source vlan dhcp-snooping port-
security
Presenting speaker
Benjamin T.P. Tan
IPv6 – Dual Stack (Cont’d)
• Autoconfiguration
– As If a DHCP server were running (but
Stateless)
– Only Router needs to be configured
• Public Address on Router? (ref. prev. slide!)
Do you have a shadow network running?
Presenting speaker
Benjamin T.P. Tan
• Flashback: IPv4 - Router Unresponsive due to
Attack
• Data Plane can handle load, but Control Plane
cannot
• Sluggish response
• Policy-Map on Control-Plane
Control Plane Policing
Presenting speaker
Benjamin T.P. Tan
Dual Stack Resource Contention
• Performace:
– IPv6 in H/W or S/W?
– Tunnels in H/W or S/W?
– What about v4?
• Flooding v6 results in v4 outage as well
• Control Plane Resource Issues
• QoS? Will IPv6 bypass QoS rules?
Presenting speaker
Benjamin T.P. Tan
Flat Networks
• Network may already been segregated by VLANs,
Subnets and Firewall rules between segments.
Good for IPv4 – BUT… (see next slide)
• Non Dual Stack on same interface/wire.
– BUT implemented as 1 Large VLAN ?!
• IPv6 address space allows for large flat networks
• Risks of large flat networks
– Same as IPv4: Layer 2 Attacks!
(Ref earlier notes about shadow networks even if
separate VLAN)
Aside: MPLS L2 VPNs
Presenting speaker
Benjamin T.P. Tan
ISATAP
• Intra-Site Automatic Tunnel Addressing Protocol
• Summary:
– lookup IPv4 DNS for isatap.domain.name
– Establish Tunnel to ISATAP server
– Get IPv6 address
• All Peers on Same Tunnel are Peers!
• What if Enterprise security model is based on
VLAN-Subnet segregation?!
• New-Old Problem: Tunnels inside and outside the
organization.
– Tunnelled Packets bypass all FW/IPS rules.
Presenting speaker
Benjamin T.P. Tan
IPv6 Firewalls / IDS,IPS
• Does your Firewall support IPv6?
• For ALL features that you need?
• IDS/IPS ? Or will you do without?
• Is IPv6 implemented as a tunnel over IPv4 which
goes Through the Firewalls?!
Note from previous slides: IPv6 address is usually a
Globally Routable IP! (“Public Address”)
Presenting speaker
Benjamin T.P. Tan
Routing Protocol Security
• Dynamic Routing Issues
• BGP MD5
• OSPF Area Authentication
• Default Interface passive
• Bad Routes by real neighbours
• Does your Infrastructure support OSPFv3? MP-
BGP? Else Static Routes? Redistributed?
Is the Dynamic Routing Protocol used in your
network secured?
Presenting speaker
Benjamin T.P. Tan
Miscellaneous IPv6 Issues
• EUI-64:
– GUID leakage
– Vendor leakage
– Organization Size?
• ICMPv6
– Firewall “defaults” changed
• L2: Neighbour Discovery / SEcure ND
– Router/Neighbour Solicitation (“ARP”)
– SEND only in Win2008 and Win7 (not in Vista)
– Overheads!
Presenting speaker
Benjamin T.P. Tan
IPv6 IPSec
• IPSec is ALWAYS in the IPv6 Stack
• Should you turn it on?
• What are we trading for what?
– No more MITM, Replay, sniffing, etc
– Firewall? IDS / IPS?
– QoS?
• Vendor Play?!?
Presenting speaker
Benjamin T.P. Tan
Section Summary
• Watch out for weaknesses opened by transitional
mechanisms.
– E.g. Dual Stacks, ISATAP, Tunnels.
• Ensure that your existing policy can be mapped to
IPv6 and that feature parity is available.
– E.g. Firewall, IPS/IDS
• Several Issues are not new. Already in IPv4. IPv6
does not solve these issues.
– E.g. Dynamic Routing Protocol security
… on to more things not solved by IPv6…
Presenting speaker
Benjamin T.P. Tan
Data Centers
• E.g. Singapore: 1Net, Equinix, GlobalSwitch
• Co-Lo
• [Easy] Access
• TATP?!
• “Everyone” is there
• Peering
Presenting speaker
Benjamin T.P. Tan
Cable Landing Stations
• E.g. Singapore: Tuas, Changi, Bedok
Presenting speaker
Benjamin T.P. Tan
MDF Rooms and Risers
• Cables within Buildings
• Who has Access to the MDF Room?
• Access to Risers?
• ALL Communications go through the MDF Room
Presenting speaker
Benjamin T.P. Tan
Lead-In pipes
• Telecommunications Links
• Buildings to Telecom Exchanges
• Plans generally available!
Presenting speaker
Benjamin T.P. Tan
Low Tech Attacks
• Electrical Overload to Ethernet switch
– Capacitive discharge from Ethernet ports
– (MDF/Riser to Router)
• Is fiber more resilient?
– Fiber fuse
• Critical Infrastructure in Car Parks...
– [salt] Water?
– Carbon Particles?
– SMOKE!
• Ref back -> DataCenters, MDF
Presenting speaker
Benjamin T.P. Tan
Presenting speaker
Benjamin T.P. Tan
CLAYTON JONES

More Related Content

Similar to Network Security IPv4 plus IPv6.pdf

12.00 - Dr. Tim Chown - University of Southampton
12.00 - Dr. Tim Chown - University of Southampton12.00 - Dr. Tim Chown - University of Southampton
12.00 - Dr. Tim Chown - University of SouthamptonIPv6 Summit 2010
 
【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering community
【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering community【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering community
【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering communityシスコシステムズ合同会社
 
ARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities ReportARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities ReportARIN
 
Integrate Kubernetes into CORD(Central Office Re-architected as a Datacenter)
Integrate Kubernetes into CORD(Central Office Re-architected as a Datacenter)Integrate Kubernetes into CORD(Central Office Re-architected as a Datacenter)
Integrate Kubernetes into CORD(Central Office Re-architected as a Datacenter)inwin stack
 
Bh fed-03-kaminsky
Bh fed-03-kaminskyBh fed-03-kaminsky
Bh fed-03-kaminskyDan Kaminsky
 
fgont-h2hc-2020-ipv6-security.pdf
fgont-h2hc-2020-ipv6-security.pdffgont-h2hc-2020-ipv6-security.pdf
fgont-h2hc-2020-ipv6-security.pdfFernandoGont
 
2018 FRSecure CISSP Mentor Program- Session 7
2018 FRSecure CISSP Mentor Program- Session 72018 FRSecure CISSP Mentor Program- Session 7
2018 FRSecure CISSP Mentor Program- Session 7FRSecure
 
IPv6 - A Real World Deployment for Mobiles
IPv6 - A Real World Deployment for MobilesIPv6 - A Real World Deployment for Mobiles
IPv6 - A Real World Deployment for MobilesAPNIC
 
IPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-onIPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-onAPNIC
 
Georgi Geshev, warranty void if label removed
Georgi Geshev,   warranty void if label removedGeorgi Geshev,   warranty void if label removed
Georgi Geshev, warranty void if label removedPacSecJP
 
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration Engineering
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration EngineeringCAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration Engineering
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration EngineeringChristian Elsen
 
TCP/IP Geeks Stockholm :: Introduction to IPv6
TCP/IP Geeks Stockholm :: Introduction to IPv6TCP/IP Geeks Stockholm :: Introduction to IPv6
TCP/IP Geeks Stockholm :: Introduction to IPv6Olle E Johansson
 
IPv6 at Home
IPv6 at HomeIPv6 at Home
IPv6 at HomeRIPE NCC
 

Similar to Network Security IPv4 plus IPv6.pdf (20)

12.00 - Dr. Tim Chown - University of Southampton
12.00 - Dr. Tim Chown - University of Southampton12.00 - Dr. Tim Chown - University of Southampton
12.00 - Dr. Tim Chown - University of Southampton
 
【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering community
【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering community【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering community
【EPN Seminar Nov.10. 2015】 Key note – Open innovation and Engineering community
 
ARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities ReportARIN 36 IETF IPv6 Activities Report
ARIN 36 IETF IPv6 Activities Report
 
Integrate Kubernetes into CORD(Central Office Re-architected as a Datacenter)
Integrate Kubernetes into CORD(Central Office Re-architected as a Datacenter)Integrate Kubernetes into CORD(Central Office Re-architected as a Datacenter)
Integrate Kubernetes into CORD(Central Office Re-architected as a Datacenter)
 
02 ipv6-cpe-panel security
02 ipv6-cpe-panel security02 ipv6-cpe-panel security
02 ipv6-cpe-panel security
 
Bh fed-03-kaminsky
Bh fed-03-kaminskyBh fed-03-kaminsky
Bh fed-03-kaminsky
 
fgont-h2hc-2020-ipv6-security.pdf
fgont-h2hc-2020-ipv6-security.pdffgont-h2hc-2020-ipv6-security.pdf
fgont-h2hc-2020-ipv6-security.pdf
 
IPv6 Transition Considerations for ISPs
IPv6 Transition Considerations for ISPsIPv6 Transition Considerations for ISPs
IPv6 Transition Considerations for ISPs
 
2018 FRSecure CISSP Mentor Program- Session 7
2018 FRSecure CISSP Mentor Program- Session 72018 FRSecure CISSP Mentor Program- Session 7
2018 FRSecure CISSP Mentor Program- Session 7
 
IPv6 - A Real World Deployment for Mobiles
IPv6 - A Real World Deployment for MobilesIPv6 - A Real World Deployment for Mobiles
IPv6 - A Real World Deployment for Mobiles
 
AF-23- IPv6 Security_Final
AF-23- IPv6 Security_FinalAF-23- IPv6 Security_Final
AF-23- IPv6 Security_Final
 
Phifer 3 30_04
Phifer 3 30_04Phifer 3 30_04
Phifer 3 30_04
 
IPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-onIPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-on
 
Georgi Geshev, warranty void if label removed
Georgi Geshev,   warranty void if label removedGeorgi Geshev,   warranty void if label removed
Georgi Geshev, warranty void if label removed
 
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration Engineering
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration EngineeringCAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration Engineering
CAv6TF Meeting - 2014-05-27 - IPv6@ VMware Integration Engineering
 
TCP/IP Geeks Stockholm :: Introduction to IPv6
TCP/IP Geeks Stockholm :: Introduction to IPv6TCP/IP Geeks Stockholm :: Introduction to IPv6
TCP/IP Geeks Stockholm :: Introduction to IPv6
 
IPv6 at Home
IPv6 at HomeIPv6 at Home
IPv6 at Home
 
66 pf sensetutorial
66 pf sensetutorial66 pf sensetutorial
66 pf sensetutorial
 
66_pfSenseTutorial
66_pfSenseTutorial66_pfSenseTutorial
66_pfSenseTutorial
 
66_pfSenseTutorial
66_pfSenseTutorial66_pfSenseTutorial
66_pfSenseTutorial
 

Recently uploaded

A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphNeo4j
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 

Recently uploaded (20)

A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge GraphSIEMENS: RAPUNZEL – A Tale About Knowledge Graph
SIEMENS: RAPUNZEL – A Tale About Knowledge Graph
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 

Network Security IPv4 plus IPv6.pdf

  • 1. Presenting speaker Benjamin T.P. Tan Network Security IPv4 + IPv6 Benjamin T.P. Tan Managing Director SuperInternet by
  • 2. Presenting speaker Benjamin T.P. Tan Overview • Confidentiality? Integrity? Availability! • IPv6 Issues (Compared with IPv4) • Physical Security of the Network Assumptions: • Generally familiar with – Network Security – Telecommunications Infrastructure • Technical Management • We only have 45 mins
  • 3. Presenting speaker Benjamin T.P. Tan Neglected Areas • Not the usual Topics: IPSec, VPNs, SSL VPNs, PKI, Firewalls, IDS/IPS – Confidentiality on the Network • Many available solutions • Data Integrity on the Network – Several issues solved by end-to-end crypto (Application) IF implemented. Else Network HELPS! – Somewhat known solutions: DHCP Snooping, ARP inspection, L3 Micro segmentation – Routing Subversion • Network Availability – DoS at all levels – Physical Infrastructure Weaknesses • New-Old Issues: IPv6 vs IPv4 and back again.
  • 4. Presenting speaker Benjamin T.P. Tan IPv6 – Dual Stack • 2 protocols on the same wire • VLANs still segregate • BUT IPv4 Subnets DO NOT New-Old Problems: • IPv6 Global Unicast Addresses – PUBLIC IP on the machine! – IF configured route-able then node is fully exposed to the Internet
  • 5. Presenting speaker Benjamin T.P. Tan IPv4 DHCP Issues • Flashback before IPv6 • IP Address Conflicts?! • Rogue DHCP Servers – APs on your LAN?! • Users Setting Static IPs – Desktop Lockdown? • DHCP Snooping and IP Source Guard ip source binding mac-address Vlan vlan-id ip-address interface interface-name (Conf-if) ip verify source vlan dhcp-snooping port- security
  • 6. Presenting speaker Benjamin T.P. Tan IPv6 – Dual Stack (Cont’d) • Autoconfiguration – As If a DHCP server were running (but Stateless) – Only Router needs to be configured • Public Address on Router? (ref. prev. slide!) Do you have a shadow network running?
  • 7. Presenting speaker Benjamin T.P. Tan • Flashback: IPv4 - Router Unresponsive due to Attack • Data Plane can handle load, but Control Plane cannot • Sluggish response • Policy-Map on Control-Plane Control Plane Policing
  • 8. Presenting speaker Benjamin T.P. Tan Dual Stack Resource Contention • Performace: – IPv6 in H/W or S/W? – Tunnels in H/W or S/W? – What about v4? • Flooding v6 results in v4 outage as well • Control Plane Resource Issues • QoS? Will IPv6 bypass QoS rules?
  • 9. Presenting speaker Benjamin T.P. Tan Flat Networks • Network may already been segregated by VLANs, Subnets and Firewall rules between segments. Good for IPv4 – BUT… (see next slide) • Non Dual Stack on same interface/wire. – BUT implemented as 1 Large VLAN ?! • IPv6 address space allows for large flat networks • Risks of large flat networks – Same as IPv4: Layer 2 Attacks! (Ref earlier notes about shadow networks even if separate VLAN) Aside: MPLS L2 VPNs
  • 10. Presenting speaker Benjamin T.P. Tan ISATAP • Intra-Site Automatic Tunnel Addressing Protocol • Summary: – lookup IPv4 DNS for isatap.domain.name – Establish Tunnel to ISATAP server – Get IPv6 address • All Peers on Same Tunnel are Peers! • What if Enterprise security model is based on VLAN-Subnet segregation?! • New-Old Problem: Tunnels inside and outside the organization. – Tunnelled Packets bypass all FW/IPS rules.
  • 11. Presenting speaker Benjamin T.P. Tan IPv6 Firewalls / IDS,IPS • Does your Firewall support IPv6? • For ALL features that you need? • IDS/IPS ? Or will you do without? • Is IPv6 implemented as a tunnel over IPv4 which goes Through the Firewalls?! Note from previous slides: IPv6 address is usually a Globally Routable IP! (“Public Address”)
  • 12. Presenting speaker Benjamin T.P. Tan Routing Protocol Security • Dynamic Routing Issues • BGP MD5 • OSPF Area Authentication • Default Interface passive • Bad Routes by real neighbours • Does your Infrastructure support OSPFv3? MP- BGP? Else Static Routes? Redistributed? Is the Dynamic Routing Protocol used in your network secured?
  • 13. Presenting speaker Benjamin T.P. Tan Miscellaneous IPv6 Issues • EUI-64: – GUID leakage – Vendor leakage – Organization Size? • ICMPv6 – Firewall “defaults” changed • L2: Neighbour Discovery / SEcure ND – Router/Neighbour Solicitation (“ARP”) – SEND only in Win2008 and Win7 (not in Vista) – Overheads!
  • 14. Presenting speaker Benjamin T.P. Tan IPv6 IPSec • IPSec is ALWAYS in the IPv6 Stack • Should you turn it on? • What are we trading for what? – No more MITM, Replay, sniffing, etc – Firewall? IDS / IPS? – QoS? • Vendor Play?!?
  • 15. Presenting speaker Benjamin T.P. Tan Section Summary • Watch out for weaknesses opened by transitional mechanisms. – E.g. Dual Stacks, ISATAP, Tunnels. • Ensure that your existing policy can be mapped to IPv6 and that feature parity is available. – E.g. Firewall, IPS/IDS • Several Issues are not new. Already in IPv4. IPv6 does not solve these issues. – E.g. Dynamic Routing Protocol security … on to more things not solved by IPv6…
  • 16. Presenting speaker Benjamin T.P. Tan Data Centers • E.g. Singapore: 1Net, Equinix, GlobalSwitch • Co-Lo • [Easy] Access • TATP?! • “Everyone” is there • Peering
  • 17. Presenting speaker Benjamin T.P. Tan Cable Landing Stations • E.g. Singapore: Tuas, Changi, Bedok
  • 18. Presenting speaker Benjamin T.P. Tan MDF Rooms and Risers • Cables within Buildings • Who has Access to the MDF Room? • Access to Risers? • ALL Communications go through the MDF Room
  • 19. Presenting speaker Benjamin T.P. Tan Lead-In pipes • Telecommunications Links • Buildings to Telecom Exchanges • Plans generally available!
  • 20. Presenting speaker Benjamin T.P. Tan Low Tech Attacks • Electrical Overload to Ethernet switch – Capacitive discharge from Ethernet ports – (MDF/Riser to Router) • Is fiber more resilient? – Fiber fuse • Critical Infrastructure in Car Parks... – [salt] Water? – Carbon Particles? – SMOKE! • Ref back -> DataCenters, MDF
  • 22. Presenting speaker Benjamin T.P. Tan CLAYTON JONES