SlideShare a Scribd company logo
IPv4 Highway




Fortinet
IPv6 Security



June 8th, 2011
Rainer Baeder




 Fortinet Confidential
Drivers for IPv6

    • Basic Demand Drivers
      • More network appliances but lack of IPv4 addresses to support
      • Control OpEx for network and IT
      • Elimination of complex NAT networks
      • Strong intrinsic security
      • Better support for mobility applications
      • Greater flexibility and simplicity


    • New Opportunities to Improve Business Performance Business
      process improvements
      • New business opportunities
      • More addresses for objects – enhanced automation and productivity
      • Machine-to-Machine (M2M) telematics / *Internet of Things*
      • IPv6 connection to anything


2
IPv6 – its time for preparing the step




                        ... and basically – we run out
                              of IPv4 addresses

                        to stay competitive, we must
                            open the door for IPv6
                             and use its foremost


        Snapshot
      June 3rd 2011
Migration Complexities
Deployment Considerations

    • Compatibility issues between IPv4 and IPv6
    • Vendor interoperability issues with IPv6
    • Potential security issues
    • Network management considerations
    • Existing hardware may not handle IPv6 traffic efficiently
    • Router memory and CPU limitations may preclude IPv6
      deployment
    • Technology refresh cycles can be exploited to deploy IPv6
      capabilities
    • Global public routing practices continue to evolve



4
The most important targets of IPv6

• Larger IP address space
  • IP Adresses are 128 bits (instead of 32 bits)
• Advanced header structure
  • Improved processing capability thru Subsegmenting of essential
    and optional headerfields (in ExtensionHeaders)
• Different IPv6 Addresses
  • Public IPv4 addresses correspond with Global Unicast Addresses
  • Private IPv4 addresses correspond with Site Local Unicast
    Addresses
  • Special Address types for usage of IPv4 and IPv6 in parallel
• Support of autoconfiguration
  • Should follow Plug-and-Play principle
• Improved security
  • 2 additional ExtensionHeaders are foreseen (Encapsulation
    Security Payload Header und Authentication Header)
  • Both can be used in IPv4 as well
Principle Design Consideration

    • “Dual stack when you can – Tunnel when you must –
      Translate when no other option works”
    • Create a virtual team of IT representatives from every       L9
                                                                Religious
      area of IT to ensure coverage for OS, Apps, Network          L8
      and Operations/Management                                  Political
                                                                   L7
    • Now is your time to build a network your way – don’t     Application

      carry the IPv4 mindset forward with IPv6 unless it           L6
                                                               Presentation
      makes sense                                                  L5
                                                                 Session
    • Design Consistency with IPv4                                 L4
                                                                Transport
    • Design should work across all WAN clouds, LAN,               L3
      Enterprises, Data Center, Campus, etc                      Network
                                                                   L2
    • Deploy it – at least in a lab – IPv6 won’t bite           Data Link
                                                                  L1
    • Consider the human factor, keep it simple!                Physical


6
IPv6 Transition Methodologies


      MPLS-Based                            IP-Tunnel                       NAT-Based
       Solutions                           Approaches                       Solutions




                              Configured           Configured     IPv4 to IPv4            IPv4 to IPv6
    6PE                6VPE
                               Tunnels              Tunnels       (Mitigation)          (Interworking)



                               GRE                       6to4     NAT44                      NAT464


                              L2TP                       6RD      NAT444                     NAT64

          Dual Stack
                               GFP                      ISATAP    DS-Lite                   NAT-TCP


                                IP                      Teredo                              NAT-UDP


                                                        DS-Lite                             NAT-ICMP




7
IPv6 Protocol Vulnerability

    • IPv6 Header                 • Extension Header
      • Header Manipulation         • EHeader Filtering
      • Protocol Fuzzing            • EHeader Fuzzing
    • ICMPv6                        • Router Header Attacks
      • ICMPv6 Filtering            • Fragmentation Header
      • ICMPv6 Attacks              • Unknown Header
    • Node Survey                   • Protocol Layer Header
      • Scanning                  • Higher Layer Spoofing
      • Improved/Smart Scanning     • Generic Malware
      • Multicast techiques       • Router Protocol Security
      • Sniffing                  • Flooding / (d)DoS and Packet
                                  • Multicast



8
IPv6 Address Types – well-known Multicast

       • Interface-local scope                                        • Link-local scope
             • FF01::1 all-nodes                                        • FF02::1 all-nodes
             • FF01::2 all-routers                                      • FF02::2 all-routers
       • Site-local scope                                               • FF02::5 OSPFIGP
             • FF05::1:3 all-routers                                    • FF02::9 RIP-routers
             • FF05::1:3 all DHCP servers                               • FF02::B Mobile Agents
                                                                        • FF02::6A all snoopers
                                                                        • FF02::1:2 all DHCP agents

                              •   FF01::101 / all-NTP Server on the same node as sender
                              •   FF02::101 / all-NTP Server on the same link as sender
                              •   FF05::101 / all-NTP Server on the same site as sender
                              •   FF0E::101 / all-NTP Server in the internet

Global Unicast Addresses correspond with Public IPv4 addresses
Site Local Unicast Addresses correspond with Private IPv4 addresses



   9
IPv6 Firewalling

     • IPv6 Addressing                      •   DHCPv6 Threats
         • Unallocated Addresses            •   Endpoint Security
     •   IPv6 Headers allowance             •   IPv6, IPSec and Firewalls
     •   L2 FW                              •   Management
     •   IPv6 and NAT                       •   Routing Security
     •   Neigbor Discovery allowance            • RIPng, OSPFv3
         (NDP)                              •   QoS Threats
        • Duplicate Address Detection Issue •   Tunneled Traffic Inspection
        • Redirect Issue
                                            •   Unwanted Tunnels
     • SEcure Neigbor Discovery
                                            •   Mobile IPv6 (MIPv6)
       (SEND)




10
Fortinet IPv6 Strategy


• Feature Parity on all function with
  IPv4 and IPv6 on higher layers
  • Application unaware weather it runs on
    IPv4 or IPv6

• IPv6 Firewalling 3+ years
  integrated
• Stepwise extension to a complete
  functionality on IPv6
  • Almost completed now
Today implemented for IPv4 & IPv6

     • Stateful Firewalling and Routing
       • Serviceobjects (eg ICMPv6), IPv6 Addressobjects
     • Dynamic Routing, OSPF / RIP / BGP
     • AntiVirus Scanning
       • http(s), ftp, smtp(s), imap(s), pop3(s), Instant-Messaging, nntp
     • Intrusion Prevention
       • Signature based IPS/IDS and DoS-Protection
     • URL Filtering
     • Data Leak Prevention
     • Management of the device via IPv6
       • eg SSH or https via IPv6 for devicemanagement




12
Today implemented for IPv4 & IPv6

     • Bandwidth Management
         • Shaping, QoS
     •   IPSec (IKEv1 & IKEv2)
     •   DNS (AAAA Record)
     •   IPv4 over IPv6 Tunneling
     •   IPv6 over IPv4 Tunneling (eg Tunnelbroker like SixXS)
     •   SIP ALG (Application Gateway)
         • Carrier-grade SIP-ALG. SIP-Fuzzing Protection, Pinholing, Rate-Control
           etc.
     • Application Control
     • Logging and Reporting of Datatraffic, Reporting on FortiAnalyzer




13
Protection on all Layers - UTM


•    Combined Methods on different layers
•    Allow, but don’t trust all application
•    Content of the application
•    Support for IPv4 und IPv6




14
Forehand Planning is the key


     • Vision for the business or the adoption driver
     • IPv6 Training
     • IP architecture that supports the vision -> IPv6 addressing
       scheme + design
     • Evaluate infrastructure readiness to support the IPv6
       implementation of the architecture
     • Drive requirements and define purchasing strategy
     • Align with other initiatives to accelerate readiness
     • Define timeline



       Overnight Adoption is Limiting and Expensive

15
Thank You.

More Related Content

What's hot

What's hot (20)

Introduction of ipv6
Introduction of ipv6Introduction of ipv6
Introduction of ipv6
 
IPv6 transition and coexistance - Jordi Palet
IPv6 transition and coexistance - Jordi PaletIPv6 transition and coexistance - Jordi Palet
IPv6 transition and coexistance - Jordi Palet
 
IPv6 translation methods
IPv6 translation methodsIPv6 translation methods
IPv6 translation methods
 
IPv6 deployment planning Jordi Palet
IPv6 deployment planning Jordi PaletIPv6 deployment planning Jordi Palet
IPv6 deployment planning Jordi Palet
 
IPv6 in 2G and 3G Networks
IPv6 in 2G and 3G NetworksIPv6 in 2G and 3G Networks
IPv6 in 2G and 3G Networks
 
Simplified IPv6 Subnetting. Understanding What’s What.
Simplified IPv6 Subnetting. Understanding What’s What.Simplified IPv6 Subnetting. Understanding What’s What.
Simplified IPv6 Subnetting. Understanding What’s What.
 
Jan Zorz - IPv6 and mobile emergency response teams
Jan Zorz - IPv6 and mobile emergency response teamsJan Zorz - IPv6 and mobile emergency response teams
Jan Zorz - IPv6 and mobile emergency response teams
 
Getting started with IPv6
Getting started with IPv6Getting started with IPv6
Getting started with IPv6
 
APNIC Update
APNIC Update APNIC Update
APNIC Update
 
IPv6 How To Set Up a Linux IPv6 Lan
IPv6 How To Set Up  a Linux IPv6 LanIPv6 How To Set Up  a Linux IPv6 Lan
IPv6 How To Set Up a Linux IPv6 Lan
 
IPv6 Transition & Deployment, including IPv6-only in cellular and broadband
IPv6 Transition & Deployment, including IPv6-only in cellular and broadbandIPv6 Transition & Deployment, including IPv6-only in cellular and broadband
IPv6 Transition & Deployment, including IPv6-only in cellular and broadband
 
Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...
Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...
Deploying IPv6 in Cisco's Labs by Robert Beckett at gogoNET LIVE! 3 IPv6 Conf...
 
Gabriel Paues - IPv6 address planning + making the case for WHY
Gabriel Paues - IPv6 address planning + making the case for WHYGabriel Paues - IPv6 address planning + making the case for WHY
Gabriel Paues - IPv6 address planning + making the case for WHY
 
IPv6 in Cellular Networks
IPv6 in Cellular NetworksIPv6 in Cellular Networks
IPv6 in Cellular Networks
 
IPv6
IPv6IPv6
IPv6
 
AusNOG 2014 - Network Virtualisation: The Killer App for IPv6?
AusNOG 2014 - Network Virtualisation: The Killer App for IPv6?AusNOG 2014 - Network Virtualisation: The Killer App for IPv6?
AusNOG 2014 - Network Virtualisation: The Killer App for IPv6?
 
AusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other Observations
AusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other ObservationsAusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other Observations
AusNOG 2011 - Residential IPv6 CPE - What Not to Do and Other Observations
 
IPv6 Autoconfig
IPv6 AutoconfigIPv6 Autoconfig
IPv6 Autoconfig
 
Addressing IPv6
Addressing IPv6Addressing IPv6
Addressing IPv6
 
Fedv6tf-fhs
Fedv6tf-fhsFedv6tf-fhs
Fedv6tf-fhs
 

Viewers also liked

Viewers also liked (10)

IPV6 SIMPLE SECURITY CAPABILITIES
IPV6 SIMPLE SECURITY CAPABILITIESIPV6 SIMPLE SECURITY CAPABILITIES
IPV6 SIMPLE SECURITY CAPABILITIES
 
IPv6 Security
IPv6 SecurityIPv6 Security
IPv6 Security
 
IPv6 Security
IPv6 SecurityIPv6 Security
IPv6 Security
 
The IPv6 Snort Plugin (at Troopers 14 IPv6 Security Summit)
The IPv6 Snort Plugin (at Troopers 14 IPv6 Security Summit)The IPv6 Snort Plugin (at Troopers 14 IPv6 Security Summit)
The IPv6 Snort Plugin (at Troopers 14 IPv6 Security Summit)
 
IPv6 Security - Where is the Challenge?
IPv6 Security - Where is the Challenge?IPv6 Security - Where is the Challenge?
IPv6 Security - Where is the Challenge?
 
A very good introduction to IPv6
A very good introduction to IPv6A very good introduction to IPv6
A very good introduction to IPv6
 
Ipv6 Security with Mikrotik RouterOS by Wardner Maia
Ipv6 Security with Mikrotik RouterOS by Wardner MaiaIpv6 Security with Mikrotik RouterOS by Wardner Maia
Ipv6 Security with Mikrotik RouterOS by Wardner Maia
 
Survey on IPv6 security issues
Survey on IPv6 security issuesSurvey on IPv6 security issues
Survey on IPv6 security issues
 
IPv6 Deployment, Lao ICT Expo 2016
IPv6 Deployment, Lao ICT Expo 2016IPv6 Deployment, Lao ICT Expo 2016
IPv6 Deployment, Lao ICT Expo 2016
 
Ipv6 course
Ipv6  courseIpv6  course
Ipv6 course
 

Similar to 4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet

IP Multicasting - An Overview
IP Multicasting - An OverviewIP Multicasting - An Overview
IP Multicasting - An Overview
h_marvin
 
Ipv6 Technical White Paper Wp111504
Ipv6 Technical White Paper Wp111504Ipv6 Technical White Paper Wp111504
Ipv6 Technical White Paper Wp111504
Erik Ginalick
 
Ipv Technical White Paper Wp111504
Ipv Technical White Paper Wp111504Ipv Technical White Paper Wp111504
Ipv Technical White Paper Wp111504
Erik Ginalick
 
Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011
IPv6no
 

Similar to 4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet (20)

IPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-onIPv4aaS tutorial and hands-on
IPv4aaS tutorial and hands-on
 
Tutorial: IPv6-only transition with demo
Tutorial: IPv6-only transition with demoTutorial: IPv6-only transition with demo
Tutorial: IPv6-only transition with demo
 
Presd1 09
Presd1 09Presd1 09
Presd1 09
 
I Pv6 Enabling Menog 0.4
I Pv6 Enabling Menog 0.4I Pv6 Enabling Menog 0.4
I Pv6 Enabling Menog 0.4
 
Fernando Gont - The Hack Summit 2021 - State of the Art in IPv6 Security
Fernando Gont - The Hack Summit 2021 - State of the Art in IPv6 SecurityFernando Gont - The Hack Summit 2021 - State of the Art in IPv6 Security
Fernando Gont - The Hack Summit 2021 - State of the Art in IPv6 Security
 
IPV6 - Threats and Countermeasures / Crash Course
IPV6 - Threats and Countermeasures / Crash CourseIPV6 - Threats and Countermeasures / Crash Course
IPV6 - Threats and Countermeasures / Crash Course
 
Mobile ipv6
Mobile ipv6Mobile ipv6
Mobile ipv6
 
Life Without IPv4: Tore Anderson, IPv6 guru, Redpill Linpro
Life Without IPv4: Tore Anderson, IPv6 guru, Redpill LinproLife Without IPv4: Tore Anderson, IPv6 guru, Redpill Linpro
Life Without IPv4: Tore Anderson, IPv6 guru, Redpill Linpro
 
The State of 3G/GPRS IPv6 Deployment
The State of 3G/GPRS IPv6 DeploymentThe State of 3G/GPRS IPv6 Deployment
The State of 3G/GPRS IPv6 Deployment
 
Ipv6
Ipv6Ipv6
Ipv6
 
fgont-h2hc-2020-ipv6-security.pdf
fgont-h2hc-2020-ipv6-security.pdffgont-h2hc-2020-ipv6-security.pdf
fgont-h2hc-2020-ipv6-security.pdf
 
Routing
RoutingRouting
Routing
 
Robert Raszuk - Technologies for IPv4/IPv6 coexistance
Robert Raszuk - Technologies for IPv4/IPv6 coexistanceRobert Raszuk - Technologies for IPv4/IPv6 coexistance
Robert Raszuk - Technologies for IPv4/IPv6 coexistance
 
ipv4 to 6
ipv4 to 6ipv4 to 6
ipv4 to 6
 
IP Multicasting - An Overview
IP Multicasting - An OverviewIP Multicasting - An Overview
IP Multicasting - An Overview
 
Is IPv6 Security Still an Afterthought?
Is IPv6 Security Still an Afterthought?Is IPv6 Security Still an Afterthought?
Is IPv6 Security Still an Afterthought?
 
Ipv6 Technical White Paper Wp111504
Ipv6 Technical White Paper Wp111504Ipv6 Technical White Paper Wp111504
Ipv6 Technical White Paper Wp111504
 
Ipv Technical White Paper Wp111504
Ipv Technical White Paper Wp111504Ipv Technical White Paper Wp111504
Ipv Technical White Paper Wp111504
 
Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011Ron Broersma dren-stavanger-22 nov2011
Ron Broersma dren-stavanger-22 nov2011
 
6. IPv6 Internetzugang für Privatkunden: Die Lösung von Swisscom - Martin Gysi
6. IPv6 Internetzugang für Privatkunden: Die Lösung von Swisscom - Martin Gysi6. IPv6 Internetzugang für Privatkunden: Die Lösung von Swisscom - Martin Gysi
6. IPv6 Internetzugang für Privatkunden: Die Lösung von Swisscom - Martin Gysi
 

More from Digicomp Academy AG

Becoming Agile von Christian Botta – Personal Swiss Vortrag 2019
Becoming Agile von Christian Botta – Personal Swiss Vortrag 2019Becoming Agile von Christian Botta – Personal Swiss Vortrag 2019
Becoming Agile von Christian Botta – Personal Swiss Vortrag 2019
Digicomp Academy AG
 

More from Digicomp Academy AG (20)

Becoming Agile von Christian Botta – Personal Swiss Vortrag 2019
Becoming Agile von Christian Botta – Personal Swiss Vortrag 2019Becoming Agile von Christian Botta – Personal Swiss Vortrag 2019
Becoming Agile von Christian Botta – Personal Swiss Vortrag 2019
 
Swiss IPv6 Council – Case Study - Deployment von IPv6 in einer Container Plat...
Swiss IPv6 Council – Case Study - Deployment von IPv6 in einer Container Plat...Swiss IPv6 Council – Case Study - Deployment von IPv6 in einer Container Plat...
Swiss IPv6 Council – Case Study - Deployment von IPv6 in einer Container Plat...
 
Innovation durch kollaboration gennex 2018
Innovation durch kollaboration gennex 2018Innovation durch kollaboration gennex 2018
Innovation durch kollaboration gennex 2018
 
Roger basler meetup_digitale-geschaeftsmodelle-entwickeln_handout
Roger basler meetup_digitale-geschaeftsmodelle-entwickeln_handoutRoger basler meetup_digitale-geschaeftsmodelle-entwickeln_handout
Roger basler meetup_digitale-geschaeftsmodelle-entwickeln_handout
 
Roger basler meetup_21082018_work-smarter-not-harder_handout
Roger basler meetup_21082018_work-smarter-not-harder_handoutRoger basler meetup_21082018_work-smarter-not-harder_handout
Roger basler meetup_21082018_work-smarter-not-harder_handout
 
Xing expertendialog zu nudge unit x
Xing expertendialog zu nudge unit xXing expertendialog zu nudge unit x
Xing expertendialog zu nudge unit x
 
Responsive Organisation auf Basis der Holacracy – nur ein Hype oder die Zukunft?
Responsive Organisation auf Basis der Holacracy – nur ein Hype oder die Zukunft?Responsive Organisation auf Basis der Holacracy – nur ein Hype oder die Zukunft?
Responsive Organisation auf Basis der Holacracy – nur ein Hype oder die Zukunft?
 
IPv6 Security Talk mit Joe Klein
IPv6 Security Talk mit Joe KleinIPv6 Security Talk mit Joe Klein
IPv6 Security Talk mit Joe Klein
 
Agiles Management - Wie geht das?
Agiles Management - Wie geht das?Agiles Management - Wie geht das?
Agiles Management - Wie geht das?
 
Gewinnen Sie Menschen und Ziele - Referat von Andi Odermatt
Gewinnen Sie Menschen und Ziele - Referat von Andi OdermattGewinnen Sie Menschen und Ziele - Referat von Andi Odermatt
Gewinnen Sie Menschen und Ziele - Referat von Andi Odermatt
 
Querdenken mit Kreativitätsmethoden – XING Expertendialog
Querdenken mit Kreativitätsmethoden – XING ExpertendialogQuerdenken mit Kreativitätsmethoden – XING Expertendialog
Querdenken mit Kreativitätsmethoden – XING Expertendialog
 
Xing LearningZ: Digitale Geschäftsmodelle entwickeln
Xing LearningZ: Digitale Geschäftsmodelle entwickelnXing LearningZ: Digitale Geschäftsmodelle entwickeln
Xing LearningZ: Digitale Geschäftsmodelle entwickeln
 
Swiss IPv6 Council: The Cisco-Journey to an IPv6-only Building
Swiss IPv6 Council: The Cisco-Journey to an IPv6-only BuildingSwiss IPv6 Council: The Cisco-Journey to an IPv6-only Building
Swiss IPv6 Council: The Cisco-Journey to an IPv6-only Building
 
UX – Schlüssel zum Erfolg im Digital Business
UX – Schlüssel zum Erfolg im Digital BusinessUX – Schlüssel zum Erfolg im Digital Business
UX – Schlüssel zum Erfolg im Digital Business
 
Minenfeld IPv6
Minenfeld IPv6Minenfeld IPv6
Minenfeld IPv6
 
Was ist design thinking
Was ist design thinkingWas ist design thinking
Was ist design thinking
 
Die IPv6 Journey der ETH Zürich
Die IPv6 Journey der ETH Zürich Die IPv6 Journey der ETH Zürich
Die IPv6 Journey der ETH Zürich
 
Xing LearningZ: Die 10 + 1 Trends im (E-)Commerce
Xing LearningZ: Die 10 + 1 Trends im (E-)CommerceXing LearningZ: Die 10 + 1 Trends im (E-)Commerce
Xing LearningZ: Die 10 + 1 Trends im (E-)Commerce
 
Zahlen Battle: klassische werbung vs.online-werbung-somexcloud
Zahlen Battle: klassische werbung vs.online-werbung-somexcloudZahlen Battle: klassische werbung vs.online-werbung-somexcloud
Zahlen Battle: klassische werbung vs.online-werbung-somexcloud
 
General data protection regulation-slides
General data protection regulation-slidesGeneral data protection regulation-slides
General data protection regulation-slides
 

4. IPv6 Security - Workshop mit Live Demo - Marco Senn Fortinet

  • 1. IPv4 Highway Fortinet IPv6 Security June 8th, 2011 Rainer Baeder Fortinet Confidential
  • 2. Drivers for IPv6 • Basic Demand Drivers • More network appliances but lack of IPv4 addresses to support • Control OpEx for network and IT • Elimination of complex NAT networks • Strong intrinsic security • Better support for mobility applications • Greater flexibility and simplicity • New Opportunities to Improve Business Performance Business process improvements • New business opportunities • More addresses for objects – enhanced automation and productivity • Machine-to-Machine (M2M) telematics / *Internet of Things* • IPv6 connection to anything 2
  • 3. IPv6 – its time for preparing the step ... and basically – we run out of IPv4 addresses to stay competitive, we must open the door for IPv6 and use its foremost Snapshot June 3rd 2011
  • 4. Migration Complexities Deployment Considerations • Compatibility issues between IPv4 and IPv6 • Vendor interoperability issues with IPv6 • Potential security issues • Network management considerations • Existing hardware may not handle IPv6 traffic efficiently • Router memory and CPU limitations may preclude IPv6 deployment • Technology refresh cycles can be exploited to deploy IPv6 capabilities • Global public routing practices continue to evolve 4
  • 5. The most important targets of IPv6 • Larger IP address space • IP Adresses are 128 bits (instead of 32 bits) • Advanced header structure • Improved processing capability thru Subsegmenting of essential and optional headerfields (in ExtensionHeaders) • Different IPv6 Addresses • Public IPv4 addresses correspond with Global Unicast Addresses • Private IPv4 addresses correspond with Site Local Unicast Addresses • Special Address types for usage of IPv4 and IPv6 in parallel • Support of autoconfiguration • Should follow Plug-and-Play principle • Improved security • 2 additional ExtensionHeaders are foreseen (Encapsulation Security Payload Header und Authentication Header) • Both can be used in IPv4 as well
  • 6. Principle Design Consideration • “Dual stack when you can – Tunnel when you must – Translate when no other option works” • Create a virtual team of IT representatives from every L9 Religious area of IT to ensure coverage for OS, Apps, Network L8 and Operations/Management Political L7 • Now is your time to build a network your way – don’t Application carry the IPv4 mindset forward with IPv6 unless it L6 Presentation makes sense L5 Session • Design Consistency with IPv4 L4 Transport • Design should work across all WAN clouds, LAN, L3 Enterprises, Data Center, Campus, etc Network L2 • Deploy it – at least in a lab – IPv6 won’t bite Data Link L1 • Consider the human factor, keep it simple! Physical 6
  • 7. IPv6 Transition Methodologies MPLS-Based IP-Tunnel NAT-Based Solutions Approaches Solutions Configured Configured IPv4 to IPv4 IPv4 to IPv6 6PE 6VPE Tunnels Tunnels (Mitigation) (Interworking) GRE 6to4 NAT44 NAT464 L2TP 6RD NAT444 NAT64 Dual Stack GFP ISATAP DS-Lite NAT-TCP IP Teredo NAT-UDP DS-Lite NAT-ICMP 7
  • 8. IPv6 Protocol Vulnerability • IPv6 Header • Extension Header • Header Manipulation • EHeader Filtering • Protocol Fuzzing • EHeader Fuzzing • ICMPv6 • Router Header Attacks • ICMPv6 Filtering • Fragmentation Header • ICMPv6 Attacks • Unknown Header • Node Survey • Protocol Layer Header • Scanning • Higher Layer Spoofing • Improved/Smart Scanning • Generic Malware • Multicast techiques • Router Protocol Security • Sniffing • Flooding / (d)DoS and Packet • Multicast 8
  • 9. IPv6 Address Types – well-known Multicast • Interface-local scope • Link-local scope • FF01::1 all-nodes • FF02::1 all-nodes • FF01::2 all-routers • FF02::2 all-routers • Site-local scope • FF02::5 OSPFIGP • FF05::1:3 all-routers • FF02::9 RIP-routers • FF05::1:3 all DHCP servers • FF02::B Mobile Agents • FF02::6A all snoopers • FF02::1:2 all DHCP agents • FF01::101 / all-NTP Server on the same node as sender • FF02::101 / all-NTP Server on the same link as sender • FF05::101 / all-NTP Server on the same site as sender • FF0E::101 / all-NTP Server in the internet Global Unicast Addresses correspond with Public IPv4 addresses Site Local Unicast Addresses correspond with Private IPv4 addresses 9
  • 10. IPv6 Firewalling • IPv6 Addressing • DHCPv6 Threats • Unallocated Addresses • Endpoint Security • IPv6 Headers allowance • IPv6, IPSec and Firewalls • L2 FW • Management • IPv6 and NAT • Routing Security • Neigbor Discovery allowance • RIPng, OSPFv3 (NDP) • QoS Threats • Duplicate Address Detection Issue • Tunneled Traffic Inspection • Redirect Issue • Unwanted Tunnels • SEcure Neigbor Discovery • Mobile IPv6 (MIPv6) (SEND) 10
  • 11. Fortinet IPv6 Strategy • Feature Parity on all function with IPv4 and IPv6 on higher layers • Application unaware weather it runs on IPv4 or IPv6 • IPv6 Firewalling 3+ years integrated • Stepwise extension to a complete functionality on IPv6 • Almost completed now
  • 12. Today implemented for IPv4 & IPv6 • Stateful Firewalling and Routing • Serviceobjects (eg ICMPv6), IPv6 Addressobjects • Dynamic Routing, OSPF / RIP / BGP • AntiVirus Scanning • http(s), ftp, smtp(s), imap(s), pop3(s), Instant-Messaging, nntp • Intrusion Prevention • Signature based IPS/IDS and DoS-Protection • URL Filtering • Data Leak Prevention • Management of the device via IPv6 • eg SSH or https via IPv6 for devicemanagement 12
  • 13. Today implemented for IPv4 & IPv6 • Bandwidth Management • Shaping, QoS • IPSec (IKEv1 & IKEv2) • DNS (AAAA Record) • IPv4 over IPv6 Tunneling • IPv6 over IPv4 Tunneling (eg Tunnelbroker like SixXS) • SIP ALG (Application Gateway) • Carrier-grade SIP-ALG. SIP-Fuzzing Protection, Pinholing, Rate-Control etc. • Application Control • Logging and Reporting of Datatraffic, Reporting on FortiAnalyzer 13
  • 14. Protection on all Layers - UTM • Combined Methods on different layers • Allow, but don’t trust all application • Content of the application • Support for IPv4 und IPv6 14
  • 15. Forehand Planning is the key • Vision for the business or the adoption driver • IPv6 Training • IP architecture that supports the vision -> IPv6 addressing scheme + design • Evaluate infrastructure readiness to support the IPv6 implementation of the architecture • Drive requirements and define purchasing strategy • Align with other initiatives to accelerate readiness • Define timeline Overnight Adoption is Limiting and Expensive 15