Ipv6 Security.Pdf
Total Page:16
File Type:pdf, Size:1020Kb
IPv6 Security Scott Hogg, CCIE No. 5133 Eric Vyncke Cisco Press Cisco Press 800 East 96th Street Indianapolis, IN 46240 USA ii IPv6 Security Scott Hogg and Eric Vyncke Copyright© 2009 Cisco Systems, Inc. Published by: Cisco Press 800 East 96th Street Indianapolis, IN 46240 USA All rights reserved. No part of this book may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording, or by any information storage and retrieval system, without writ- ten permission from the publisher, except for the inclusion of brief quotations in a review. Printed in the United States of America First Printing December 2008 Library of Congress Cataloging-in-Publication Data: Hogg, Scott. IPv6 security / Scott Hogg, Eric Vyncke. p. cm. Includes bibliographical references and index. ISBN-13: 978-1-58705-594-2 (pbk.) ISBN-10: 1-58705-594-5 1. Computer networks—Security measures. 2. TCP/IP (Computer network protocol) I. Vyncke, Eric. II. Title. TK5105.59.H637 2009 005.8—dc22 2008047255 ISBN-13: 978-1-58705-594-2 ISBN-10: 1-58705-594-5 Warning and Disclaimer This book is designed to provide information about the security aspects of the IPv6 protocol. Every effort has been made to make this book as complete and as accurate as possible, but no warranty or fitness is implied. The information is provided on an “as is” basis. The authors, Cisco Press, and Cisco Systems, Inc., shall have nei- ther liability nor responsibility to any person or entity with respect to any loss or damages arising from the informa- tion contained in this book or from the use of the discs or programs that may accompany it. The opinions expressed in this book belong to the author and are not necessarily those of Cisco Systems, Inc. Trademark Acknowledgments All terms mentioned in this book that are known to be trademarks or service marks have been appropriately capital- ized. Cisco Press or Cisco Systems, Inc., cannot attest to the accuracy of this information. Use of a term in this book should not be regarded as affecting the validity of any trademark or service mark. iii Feedback Information At Cisco Press, our goal is to create in-depth technical books of the highest quality and value. Each book is crafted with care and precision, undergoing rigorous development that involves the unique expertise of members from the professional technical community. Readers’ feedback is a natural continuation of this process. If you have any comments regarding how we could improve the quality of this book, or otherwise alter it to better suit your needs, you can contact us through email at [email protected]. Please make sure to include the book title and ISBN in your message. We greatly appreciate your assistance. Corporate and Government Sales The publisher offers excellent discounts on this book when ordered in quantity for bulk purchases or special sales, which may include electronic versions and/or custom covers and content particular to your business, training goals, marketing focus, and branding interests. For more information, please contact: U.S. Corporate and Government Sales 1-800-382-3419 [email protected] For sales outside the United States please contact: International Sales [email protected] Publisher Paul Boger Associate Publisher Dave Dusthimer Cisco Press Program Manager Jeff Brady Executive Editor Brett Bartow Managing Editor Patrick Kanouse Development Editor Dayna Isley Senior Project Editor Tonya Simpson Copy Editor Written Elegance, Inc. Technical Editors Joseph Karpenko, Darrin Miller Editorial Assistant Vanessa Evans Book and Cover Designer Louisa Adair Composition Mark Shirar Indexer Bill Meyers Proofreader Leslie Joseph Americas Headquarters Asia Pacific Headquarters Europe Headquarters Cisco Systems, Inc. Cisco Systems (USA) Pte. Ltd. Cisco Systems International BV San Jose, CA Singapore Amsterdam, The Netherlands Cisco has more than 200 offices worldwide. Addresses, phone numbers, and fax numbers are listed on the Cisco Website at www.cisco.com/go/offices. CCDE, CCENT, Cisco Eos, Cisco Lumin, Cisco Nexus, Cisco StadiumVision, the Cisco logo, DCE, and Welcome to the Human Network are trademarks.; Changing the Way We Work, Live, Play, and Learn is a service mark; and Access Registrar, Aironet, AsyncOS, Bringing the Meeting To You, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, CCSP, CCVP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Collaboration Without Limitation, EtherFast, EtherSwitch, Event Center, Fast Step, Follow Me Browsing, FormShare, GigaDrive, HomeLink, Internet Quotient, IOS, iPhone, iQ Expertise, the iQ logo, iQ Net Readiness Scorecard, iQuick Study, IronPort, the IronPort logo, LightStream, Linksys, MediaTone, MeetingPlace, MGX, Networkers, Networking Academy, Network Registrar, PCNow, PIX, PowerPanels, ProConnect, ScriptShare, SenderBase, SMARTnet, Spectrum Expert, StackWise, The Fastest Way to Increase Your Internet Quotient, TransPath, WebEx, and the WebEx logo are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries. All other trademarks mentioned in this document or Website are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (0805R) iv About the Authors Scott Hogg, CCIE No. 5133, has been a network computing consultant for more than 17 years. Scott provides network engineering, security consulting, and training services, focusing on creating reliable, high-performance, secure, manageable, and cost-effective network solutions. He has a bachelor’s degree in computer science from Colorado State University and a master’s degree in telecommunications from the University of Colorado. In addition to his CCIE he has his CISSP (No. 4610) and many other vendor and industry certifications. Scott has designed, implemented, and troubleshot networks for many large enterprises, service providers, and government organizations. For the past eight years, Scott has been researching IPv6 technologies. Scott has written several white papers on IPv6 and has given numerous presentations and demonstrations of IPv6 technologies. He is also currently the chair of the Rocky Mountain IPv6 Task Force and the Director of Advanced Technology Services at Global Technology Resources, Inc. (GTRI), a Cisco Gold partner headquartered in Denver, Colorado. Eric Vyncke is a Distinguished System Engineer for Cisco working as a technical consultant for secu- rity covering Europe. His main area of expertise for 20 years has been security from Layer 2 to applica- tions. He has helped several organizations deploy IPv6 securely. For the past eight years, Eric has participated in the Internet Engineering Task Force (IETF) (he is the author of RFC 3585). Eric is a fre- quent speaker at security events (notably Cisco Live [formerly Networkers]) and is also a guest profes- sor at Belgian Universities for security seminars. He has a master’s degree in computer science engineering from the University of Liège in Belgium. He worked as a research assistant in the same uni- versity before joining Network Research Belgium, where he was the head of R&D; he then joined Sie- mens as a project manager for security projects including a proxy firewall. He coauthored the Cisco Press book LAN Switch Security: What Hackers Know About Your Switches. He is CISSP No. 75165. v About the Technical Reviewers Joseph Karpenko currently works as a senior engineer for the Security Intelligence Engineering orga- nization at Cisco. Joseph is a ten-year veteran of technology with expertise in networking, security, data center, and systems administration fields. Currently Joseph is responsible for developing security solu- tions that deter, detect, and prevent existing, current, and emerging threats and attacks. He also has been a speaker at multiple conferences presenting security topics. During his career, Joseph has worked with customers on the design and implementation of large-scale enterprise and data center network and security architectures. Prior to joining Cisco, Joseph worked as a system administrator and senior escalation engineer handling and troubleshooting complex security and network incidents. Joseph lives in Texas with his wife, daughter, and their furry four-legged family member (chocolate lab), and he enjoys fishing in his leisure time. Darrin Miller is an engineer in the security technology group at Cisco. Darrin is responsible for system-level security architecture. He has worked primarily on policy-based admission, incident response, and next-generation architectures within Cisco. Before joining the security technology group, Darrin was a security researcher with focus in the areas of identity, NAC, IPv6, SCADA, incident response, and trust models. This work has included protocol security analysis and security architectures for next-generation networks. Darrin has authored and contributed to several books and white papers on the subject of network security. Darrin has also spoken around the world at leading network security conferences on a variety of topics. Prior to his ten years at Cisco, Darrin held various positions in the network security community. vi Dedications This book is dedicated to David Hogg. I think he would be proud of me. — Scott Hogg To my family, my parents Ghislaine and Willy, my wife Isabelle, and my children Pierre and Thibault. — Eric Vyncke vii Acknowledgments I must first thank my wonderful wife Stacy and our kids, Ian and Lauren, for being supportive of daddy’s IPv6 addiction. Thanks also to my parents for buying me an Apple II computer in 1982 that started my lifelong love of learning all things digital. I would like to thank my colleagues in the Rocky Mountain IPv6 Task Force and the North American IPv6 Task Force. Thanks to Jeff Doyle for his encouragement and words of wisdom. I would like to thank Chuck Sellers from NTT America for his friendship and collaboration on MIPv6. I also would like to thank the IETF for its work on IPv6. I am privileged to be standing on the shoulders of these giants.