IPv6-strategic-planning-framework

20
IPv6 Strategic Planning Details YOUR ORG ID

Transcript of IPv6-strategic-planning-framework

Page 1: IPv6-strategic-planning-framework

IPv6 Strategic Planning Details

YOUR ORG ID

Page 2: IPv6-strategic-planning-framework

Architectural Model

Planning and coordination is required from many across the organization, including …

Network engineers & operators Security engineers Application developers Desktop / Server engineers Web hosting / content developers Business development managers …

Page 3: IPv6-strategic-planning-framework

Create a project team & plan Identify business value, requirements & impacts Assess equipment & applications for IPv6 Begin training & develop training plan Develop the architectural solution Obtain a prefix and build the address plan Define an exception process for legacy systems Update the security policy Deploy IPv6 trials in the network Test and monitor your deployment

IPv6 Planning Steps

Page 4: IPv6-strategic-planning-framework

Project Manager (PM) Executive Sponsor Team Member Team Member Team Member Across IT

Security Server Admins Desktop Support Application Developers

IPv6 Project Team

Page 5: IPv6-strategic-planning-framework

Create Executive Briefing Assign key IT resources, Project Manager (PM)

Build the team Document the process

Aligned to overall IT strategy Develop timeline

Define measurable Align to lifecycle management

Include IPv6 as part of upcoming projects Vendor selection, RFP’s, cloud, SDN, etc..

IPv6 Project Plan

Page 6: IPv6-strategic-planning-framework

The adoption of IPv6 worldwide provides a practically unlimited number of device addresses

Globalization has necessitated the need to communicate with customers and branch offices in regions that had only IPv6 accessibility

ARIN, the North American address authority has exhausted its public IPv4 address allocation

As IPv6 is adopted worldwide, Public Internet resources will be transitioning to IPv6

Ability to provide IPv6 support to current and potential I-NET customers

Benefits of IPv6

Page 7: IPv6-strategic-planning-framework

"You don’t need a business case for IPv6. It’s a business continuity solution.” – IPspace.net

Communications with agencies and partners using IPv6 security framework

Our Internet providers and peers currently support IPv6 IPv6 features more efficient routing and improved data

transmission speeds Our network infrastructure is IPv6 ready

Benefits of IPv6 Cont.

Page 8: IPv6-strategic-planning-framework

8

Must be low-cost and low-risk Must co-exist with existing IPv4 infrastructure Must allow access to public IPv4 Internet Must be incrementally deployable Must understand the cost of adding a new services Must not impact existing services. Nobody should know the integration occurred

Requirements for any IPv6 Transition Strategy

Page 9: IPv6-strategic-planning-framework

Need of large volume of devices that have to be readdressed Need of security rules and functions to be addressed (IPv6 maturity in

security products) Requirement of Staff with technical knowledge of IPv6 Possibility of attack as the attackers might have more expertise with IPv6

than an organization in the early stages of deployment. Need of good understanding of addressing impact on hardware requirement Requirement of Audit of any associated services and devices that may be

impacted by IPv6 transition. Difficulty in detecting and managing unknown or unauthorized IPv6 assets

on existing IPv4 production networks.

Challenges in migration from IPv4 to IPv6

Page 10: IPv6-strategic-planning-framework

A key and mandatory step to evaluate the impact of IPv6 integration May be split in several phases

Infrastructure – networking devices and services systems Applications, servers, storage, services, clients Hardware type, memory size, interfaces, CPU load… Software version, features enabled, license type… Known limitations, best practices, etc…

Defined set of features per device’s category for a specific environment Break down into “places in the network” for a more accurate assessment

Core, data center, Internet edge, WAN, wired access, wireless access Cost analysis and time lines

Readiness Assessment

10

Page 11: IPv6-strategic-planning-framework

Core & Distribution Access Layer ISP Applications Host OS’s Security devices (FW, IPS, SEIM)

IPv6 Assessment Results

Page 12: IPv6-strategic-planning-framework

Pre architecture deployment team training Onsite Online Confernece, Cisco Live, Task Force

Security team Application developers Expertise garnered by the initial deployment team is spread

throughout the organization Server Admin’s, desktop support, operations

IPv6 Training Plan

Page 13: IPv6-strategic-planning-framework

PI vs. PA, spanning RIR geography Infrastructure addressing Dual Stack Network, subnet planning ULA vs. Global Host assignment (SLAAC or DHCPv6) Multi home, multi provider (BGP)

IPv6 Architectural Strategy

Page 14: IPv6-strategic-planning-framework

Windows XP Mainframe Printers

Exception Plan for Legacy Devices

Page 15: IPv6-strategic-planning-framework

Do you support dual stack peering? Do you have a separate (SLA) for IPv6? Do you support BGP peering over IPv6? Do you have a FULL IPV6 route table? What is the maximum prefix length?

What about DNS…

Checking in with the ISP

Page 16: IPv6-strategic-planning-framework

Similarities to IPv4 ICMPv6 (PTB, NA, NS) Extension Headers Bogons BCP38, RFC2827 Access layer (Wired & Wireless)

Update to Security Policy

Page 17: IPv6-strategic-planning-framework

Internal phase Core, Distribution Access (Wired, Wireless) WAN Data Center

External Phase Carrier, provider capabilities Web, Mail, DNS, SLB Security (FW, IPS, Edge Router)

IPv6 Deployment Phases

Page 18: IPv6-strategic-planning-framework

Security Event Incident Management (SEIM) NOC, network management tools Configuration management database Handheld Testing tools (LanDroid, IPv6 toolkit) Wireshark IPAM, DHCPv6, Radius logs Server logs

Testing & Monitoring IPv6

Page 19: IPv6-strategic-planning-framework

Legacy IP as a service Removing support for legacy IP More test and monitor

Sunsetting IPv4

Page 20: IPv6-strategic-planning-framework

CISCO

IPv6 is there already, are [email protected]

@bckcntryskr tjmartin2020