ipv6 and the enterprise (workshop) · title: ipv6 and the enterprise (workshop) author: wilhelm...

21
IPv6 and the Enterprise (Workshop) Wilhelm Boeddinghaus iubari GmbH Benedikt Stockebrand Stepladder IT Training+Consulting GmbH RIPE 75 October 2017 Dubai, United Arab Emirates Copyright c 2017 W. Boeddinghaus, B. Stockebrand 1/18

Upload: others

Post on 24-May-2020

13 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

IPv6 and the Enterprise

(Workshop)

Wilhelm Boeddinghausiubari GmbH

Benedikt StockebrandStepladder IT Training+Consulting GmbH

RIPE 75October 2017

Dubai, United Arab Emirates

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 1/18

Page 2: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

About Us

• Trainers and Consultants

• 10+ years of IPv6 experience each

• Extensive experience with IPv6 deployments

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 2/18

Page 3: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

Scope of this Talk

• Enterprise environments

• Client networks

• Large number of nodes

• Limited skills

• BYOD

• IoT

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 3/18

Page 4: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

Part I

Common Misconceptions

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 4/18

Page 5: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

Lessons Learned So Far (Or Not) Common Misconceptions

• IPv6 unavoidable

• Don’t procrastinate

• IPv6 is not “IPv4 with longer addresses”. . .

• IPv6 is a management problem

• “IPv6 Deployment” vs. IPv4 Retirement

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 5/18

Page 6: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

The “Official” TCP/IP Stack Common Misconceptions

ApplicationLayer

TransportLayer

NetworkLayer

LinkLayer

DNS SSH SMTP IMAP HTTP · · ·

TCP UDP · · ·

IP(v4)

IGMP ICMP

IPv6

MLD ICMP6

Ethernet PPP WLAN · · ·

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 6/18

Page 7: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

The “Real” TCP/IP Stack Common Misconceptions

Physical+Link Layer

Application Layer

Transport LayerNetwork Layer

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 7/18

Page 8: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

The “Really Real” TCP/IP Stack Common Misconceptions

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 8/18

Page 9: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

The “Really Real” TCP/IP Stack Common Misconceptions

Users, Developers, Admins

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 8/18

Page 10: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

The “Really Real” TCP/IP Stack Common Misconceptions

Users, Developers, Admins

(Non-technical) Management

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 8/18

Page 11: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

The “Really Real” TCP/IP Stack Common Misconceptions

Users, Developers, Admins

(Non-technical) Management

Politics

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 8/18

Page 12: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

First Things First Common Misconceptions

• Procurement

• Test/Training Environment

• Train people

• “Spy” network

• Inventarize for IPv6

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 9/18

Page 13: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

Making a Plan Common Misconceptions

• IPv6 is highly unpredictable

• Risk driven management

• Incremental deployment vs. Big Bang

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 10/18

Page 14: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

The Top Troublemakers Common Misconceptions

• Highly vertical software

• Find and fix early

• A management problem

• Really a lot of detail work

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 11/18

Page 15: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

Dealing with the Troublemakers Common Misconceptions

• Upgrade

• Replace

• Terminal servers

• Dedicated IPv4-provided subnets

• Provide IPv4 as needed (details on Wednesday)

• Avoid large scale dual-stacking

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 12/18

Page 16: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

Part II

Your Questions?

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 13/18

Page 17: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

DHCP vs. SLAAC? Your Questions?

• SLAAC for Layer 3

• Stateless DHCP for Layer 7

• RDNSS+DNSSL for Android

• Stateless DHCP for Windows before Creators Update

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 14/18

Page 18: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

Microsegmentation Your Questions?

• Do it. Seriously.

• Separate by security privileges

• Point-to-point can make sense

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 15/18

Page 19: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

Address Plan Your Questions?

• Overall goals• Simplicity• Comprehensiveness• Flexibility

• Prefixes

1. Use no more than 1/8 or 1/16 of your allocation2. Allocate aggregate prefixes by “site”3. Allocate by security profile

• Interface IDs• Suggestion: Global counter(s)• Suggestion: Separate ranges for routers and hosts• Don’t reuse

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 16/18

Page 20: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

Part III

Epilogue

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 17/18

Page 21: IPv6 and the Enterprise (Workshop) · Title: IPv6 and the Enterprise (Workshop) Author: Wilhelm Boeddinghausiubari GmbH Benedikt StockebrandStepladder IT Training+Consulting GmbH

Contacts Epilogue

Wilhelm Boeddinghaus Benedikt Stockebrand

iubari GmbH Stepladder ITTraining+Consulting GmbH

http://www.iubari.de/ http://www.stepladder-it.com/

[email protected] [email protected]

Copyright c© 2017 W. Boeddinghaus, B. Stockebrand 18/18