+ All Categories
Home > Documents > IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on...

IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on...

Date post: 22-Mar-2020
Category:
Upload: others
View: 1 times
Download: 0 times
Share this document with a friend
17
Waliur Rahman Managing Principal, Global Solutions April, 2011 IPv6 Enablement for Enterprises
Transcript
Page 1: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Waliur RahmanManaging Principal, Global Solutions

April, 2011

IPv6 Enablement for Enterprises

Page 2: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

PROPRIETARY STATEMENT

This document and any attached materials are the sole property of Verizon and are not to be used

by you other than to evaluate Verizon’s service.

This document and any attached materials are not to be disseminated, distributed, or otherwise

conveyed throughout your organization to employees without a need for this information or to any

third parties without the express written permission of Verizon.

The Verizon and Verizon Business names and logos and all other names, logos, and slogans identifying Verizon’s products and services are trademarks and service marks or

registered trademarks and service marks of Verizon Trademark Services LLC or its affiliates in the United States and/or other countries. Microsoft and Windows Vista are either

registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. All other trademarks and service marks are the property of their

respective owners.

2

Page 3: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Verizon IPv6 Transition Solutions

Migration Complexities

Enterprise Drivers for IPv6

What We’ll Cover

3

Page 4: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Enterprise Drivers for IPv6 Basic Demand Drivers

• More network appliances but lack of IPv4 addresses to support

• Mandates for U.S. Government Agencies

• Control OpEx for network and IT

• Elimination of complex NAT networks

• Strong intrinsic security

• Better support for mobility applications

• Greater flexibility and simplicity

• Business process improvements

4

Page 5: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Enterprise Drivers for IPv6 New Opportunities to Improve Business Performance

• New business opportunities

• More addresses for objects –enhanced automation and productivity

• Machine-to-Machine (M2M) telematics

• IPv6 connection to anything

5

Page 6: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Migration Complexities Deployment Considerations

• Compatibility issues between IPv4 and IPv6

• Vendor interoperability issues with IPv6

• Potential security issues

• Network management considerations

• Existing hardware may not handle IPv6 traffic efficiently

• Router memory and CPU limitations may preclude IPv6 deployment

• Technology refresh cycles can be exploited to deploy IPv6 capabilities

• Global public routing practices continue to evolve

6

Page 7: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Migration Complexities Identify Dependencies on IPv4

• DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

• Operational support systems/operations and maintenance systems

• Performance measurement and reporting

• Fault management tools and trouble ticketing systems

• IPv4/IPv6 address management tools

• Staff training – call centers, store fronts, IT, NOC, etc.

• Firewalls, IDSs, IGP protocol Security

• Deployment of automated IPv6 address management systems

7

Page 8: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

• Security organizations need to be early adopters

• Increase the level of security controls during initial IPv6 deployment

• Monitor for false router advertisements in the corporate network, use authentication

• Filtering considerations and strategies must be developed

• Enforce multicast scope limits at appropriate network and sub-network boundaries

Migration Complexities Suggested Risk Mitigation Strategies

8

Page 9: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Verizon IPv6 Transition MethodologiesIPv6 Transition Planning Considerations

Security Security

SystemsSystems

Requirements Requirements

Analysis and Gap Analysis and Gap

AssessmentAssessment

Planning Planning

and Designand Design

IPAM & DNS IPAM & DNS

InfrastructureInfrastructure

Network Logic Network Logic

EnhancementsEnhancements

IP Appliances and IP Appliances and

Utility SystemsUtility Systems

IPv6 Transition

Business Logic Business Logic

EnhancementsEnhancements

Competency Competency

DevelopmentDevelopment

Time phased, iterative Time phased, iterative endeavor, involving: endeavor, involving:

–– Requirements and gap Requirements and gap assessment assessment

–– Systematic planning Systematic planning and design and design

–– Methodological Methodological implementationimplementation

IPv6 transition is a IPv6 transition is a process, not an eventprocess, not an event

ImplementationImplementation

Front and BackFront and Back--

Office IT SystemsOffice IT Systems

Safeguard business Safeguard business continuity during the continuity during the

transition processtransition process9

Page 10: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Verizon IPv6 Transition MethodologiesA Proven Approach, Built on Core Principles

10

A smooth transition to IPv6 requires clearly set expectations, A smooth transition to IPv6 requires clearly set expectations, sound planning, and an established approachsound planning, and an established approach

Phases

• Verizon’s IPv6 migration strategy consists of multiple phases:– IPv6 Preliminary Assessment– IPv6 Impact Assessment & Compliance Gap Analysis– IPv6 Transition Planning– IPv6 Transition Implementation

• All four phases key to planning and implementing a successful migration

• Main focus is to assist with migration from IPv4 networks to dual-stack IPv4/IPv6 infrastructure

Page 11: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Preliminary Assessment

• Educational services on IPv6 transition– Presentations covering industry trends– Case studies including lessons learned and caveats

• Situational analysis and requirements elicitation– Review of overall market-specific business context and drivers for IPv6– Preliminary assessment of existing network infrastructure: architecture,

deployed components and systems– Preliminary assessment of business logic systems, applications, and services – Review of IT and network operations management– Review of security management

• Development of strategic IPv6 roadmaps

Verizon IPv6 Transition Methodologies, (cont’d)

A strategic, intelligent approach to IPv6 transition should be designed A strategic, intelligent approach to IPv6 transition should be designed to maintain performance and avoid potential challengesto maintain performance and avoid potential challenges

Page 12: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Verizon IPv6 Transition Methodologies, (cont’d)

Impact Assessment and Compliance Gap Analysis

• Detailed assessment of network capabilities and systems– Hardware, software, associated management tools

• Identification of business and technical drivers for IPv6 transition

• Detailed assessments and compliance analysis– Site survey, network logic, business logic, security management and compliance,

evolution plans

• Education and competency development– Benefits, industry directions, standards, compliance, vendor roadmaps

• Training, reports on IPv6 readiness findings, detailed transition roadmaps

An inAn in--depth understanding of your networks, systems, and depth understanding of your networks, systems, and processes is necessary processes is necessary –– and their associated requirements and risksand their associated requirements and risks

Page 13: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Verizon IPv6 Transition Methodologies, (cont’d)

IPv6 Transition Planning

• A comprehensive, enterprise-wide migration strategy that will:– Provide vertical-specific industry analysis and best practices

– Identify technologies and develop a target compliant architecture

– Develop a POC lab simulation environment prior to migration

– Define IP addressing framework, automated tools, management processes

– Develop detailed project management plan

– Develop detailed pre and post-migration test plans and success criteria

– Recommend migration paths for non compliant network devices

– Develop the detailed implementation plan and related documents

– Provide education, coaching, and training

13

Realize immediate benefits of IPv6 by leveraging Realize immediate benefits of IPv6 by leveraging a proven transition strategya proven transition strategy

Page 14: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Verizon IPv6 Transition MethodologiesIPv4 to IPv6 Transition Technology Considerations

14

MPLS-Based Solutions

IP-Tunnel Approaches

NAT-Based Solutions

6PE 6VPE

L2TP

GFP

GRE

Configured Tunnels

Automatic Tunnels

IP

6RD

ISATAP

6to4

Teredo

IPv4 to IPv4(Mitigation)

IPv4 to IPv6(Interworking)

NAT444

NAT44 NAT464

NAT64

NAT-TCP

NAT-UDP

NAT-ICMP

DS-Lite

DS-Lite

These approaches are not mutually exclusive and can be deployed concurrentlyThese approaches are not mutually exclusive and can be deployed concurrently

Page 15: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Verizon IPv6 Transition Methodologies, (cont’d)

IPv6 Transition Implementation

• Physical and logical implementations of the developed IPv6 transition plan

• Detailed project management of every aspect of implementation and management

– Physical installations– Device configurations (network core, edge, LAN devices, servers, OS, etc)– Execute pre and post-test plans– Documentation

»Design and configurations, procedures

– Fine-tune network, server HW/OS

15

IPv6 implementation should help enterprises leverage new technology IPv6 implementation should help enterprises leverage new technology and networking capabilities and drive flexibility and performanceand networking capabilities and drive flexibility and performance

Page 16: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Verizon Has Been There.Our IPv6 Experience

16

Page 17: IPv6 Enablement for Enterprises · 2012-12-14 · Migration Complexities Identify Dependencies on IPv4 • DNS – Inserting AAAA records in DNS for resources without IPv6 connectivity

Questions?

17


Recommended