Before and After Ipv4 Address Exhaustion”
Total Page:16
File Type:pdf, Size:1020Kb
IPv6 deployment cases Matsuzaki ‘maz’ Yoshinobu <[email protected]> 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 1 IPv4 Address Exhaustion • more users and devices, but not enough IPv4 • Remaining IPv4 Address Space Drops Below 5% – as of 18/Oct/2010 – http://www.nro.net/media/remaining-ipv4- address-below-5.html 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 2 One Internet • it’s one of the greatest value of the internet – people connected • keep connected – even “Before and After IPv4 Address Exhaustion” • And we believe our customers need IPv6 to connect each other 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 3 myself and IIJ network • myself – senior engineer at IIJ • IPv4 and IPv6 network, DNS, security and so on – APOPS co-chair, APNIC IPv6 Tech sig chair • IIJ – pure IP network – IIJ/AS2497 maintains its IP backbone in Japan and United States. 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 4 IIJ’s IPv6 services • 1st stage (1999-) – connectivity • including cache dns • 2nd stage – applications • web, mail, dns, ntp • 3rd stage (now) – expanding services 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 5 business model for connectivity • IIJ sells bandwidth – Customers can select protocol(s) which should be forwarded on the link • IPv4 only • IPv4/IPv6 dual stack • IPv6 only – Or, customer can ask IPv6 over IPv4 tunnel for free. 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 6 brief backbone topology • dual stack as possible San Jose Osaka#1 IX Tokyo#1 IX IX IX New York IX Palo Alto Nagoya Ashburn IX Tokyo#2 Osaka#2 IX IX Los Angeles 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 7 routing protocols IPv4 IPv6 • OSPFv2 • OSPFv3 – mostly area 0 – area 0 only – md5 authentication – ipsec authentication • BGP4 • BGP4+ – peer through ipv4 – peer through ipv6 global – route-reflector – route-reflector (same as IPv4) – md5 authentication – md5 authentication 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 8 OSPFv3 link cost • We set the same link cost value as IPv4’s. – The network topology is almost same. – working fine • When we were using RIPng as IGP (we had no choice at that time ), these were so much trouble. 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 9 addressing • /128 for loopback interfaces • /64 for links – /127 is used on several inter-router links • static /48 for customer sites – still considering the size – possible sizes are: /48, /52, /56, /60, /64 • dynamic /64 for dynamic tunnel users – via PPTP tunnel 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 10 IPv6 experiences • can clear away fear for IPv6 – it works! • can improve awareness of IPv6 – production level services • can convince your customers – how we did, problems we met, solutions we did 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 11 iij.ad.jp DNS iij.ad.jp. IN NS dns0.iij.ad.jp. iij.ad.jp. IN NS dns1.iij.ad.jp. dns0.iij.ad.jp. IN A 210.138.174.16 dns0.iij.ad.jp. IN AAAA 2001:240:bb41:8002::1:16 dns1.iij.ad.jp. IN A 210.138.175.5 dns1.iij.ad.jp. IN AAAA 2001:240:bb4c:8000::1:5 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 12 iij.ad.jp SMTP iij.ad.jp. IN MX 10 omgi.iij.ad.jp. omgi.iij.ad.jp. IN A 202.232.30.70 omgi.iij.ad.jp. IN A 202.232.30.144 omgi.iij.ad.jp. IN AAAA 2001:240:11e:6300::1:70 omgi.iij.ad.jp. IN AAAA 2001:240:11e:6000::1:144 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 13 iij.ad.jp WEB www.iij.ad.jp. IN A 210.130.137.80 www.iij.ad.jp. IN AAAA 2001:240:bb42:b000::1:80 www-v4.iij.ad.jp. IN A 210.130.137.80 www-v6.iij.ad.jp. IN AAAA 2001:240:bb42:b000::1:80 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 14 iij.ad.jp WEB Router Router IPv4/IPv6 - www.iij.ad.jp global -www.iij.com HTTP/SSL www www Apache 予備 (Reverse proxy) Apache IPv4 HTTP private Deploy CMS WEB CGI gateway Apache Apache IPv4 private 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 15 IIJ office datacenter The Internet Server Server Dual stack IPv6 Global Routers IPv4 c7401 cat4500 IPv4 FW IPv6 FW FW-1 FW-1 Juniper SSG Juniper SSG internal servers Server Server Internal Routers c7600 c7600 Core Core Switch Switch 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 16 demands for IPv6 services • power users • huge enterprises • governments • ISPs • contents providers 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 17 demands for IPv6 information • System Integrators • ISPs • vendors – home gateways – network equipments • academies 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 18 publication • IIJ publishes IPv6 deployment status of its services on www site. – http://www.iij.ad.jp/service/IPv6schedule/ • This helps our customers to plan their IPv6 deployment. 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 19 consumer service in japan The Internet ISP ISP ISP ISP CATV CATV 3G Access Network ADSL, FTTH 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 20 The Access Network • NTT’s NGN is the biggest in Japan. – FLET’s service • It will support IPv6 Internet services about Apr/2011 – ISP can start IPv6 services for consumers 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 21 A CATV group established Docsis lab 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 22 Asia Pacific region • Asia Pacific IPv6 Task Force – http://www.ap-ipv6tf.org/ 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 23 end-user environments analysis • We gathered data from our cache DNS – AAAA query rate monitor root-servers dns query dns reply end-users cache DNS authoritative DNS 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 24 stacked query/sec graph 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 25 observed querying end-hosts 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 26 ratio of AAAA capable source 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 27 Again, One Internet • it’s one of the greatest value of the internet – people connected • And we believe our customers need IPv6 to connect each other 2010/10/21 Copyright (c) 2010 Internet Initiative Japan Inc. 28.