Professional Documents
Culture Documents
Technologies
Yasuo Kashimura
Senior Manager, Japan, APAC IPCC
Alcatel-lucent
Agenda
2. 2. IPv4 continuity
2 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
1
Current status of IPv4 / IPv6 internet
3 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
IANA IPv4 address pool has been sold out !!
http://www.icann.org/en/news/releases/release-03feb11-en.pdf
IPv4 address exhaustion has become REAL.. People needs go to IPv6 anyway..
4 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
IPv4 Address Exhaust and IPv6 Deployment
IPv6 transition (dual-stack)
Internet growth
Original Expectation
IPv6 deployment
IPv4 Pool Size
IPv6 transition t
IPv4 Pool Size
IPv6 deployment
2010 2012
t
IPv6 Transition (dual-stack, NAT, tunneling)
Geoff Huston
http://www.potaroo.net/ispcol/2009-09/v6trans.html
2010 t
5 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Transition to IPv6 : Two Approaches we need to consider..
6 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Transition to IPv6 : applicable technologies
Translation
DS-Lite,
A+P
Tunneling
7 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Methods
Dual-Stack Lite
IPv4 IPv6 IPv4 Internet
SAM, 4RD
NAT64 Stateful
IPv6 IPv6 IPv4 Internet NAT64 Stateless
IVI
6to4
IPv6 IPv4 IPv6 Internet
6RD
8 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
2
IPv4 continuity
9 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
IPv4
Continuity
Large Scale NAT(LSN)
Private IPv4
network 1/2stack
BNG
7750-SR
Private
LSN IPv4
Private IPv4 IPv4 Internet
network Network 7750-SR
Server
IPv6
Network
Private IPv4 1/2stack
network
BNG IPv6 Internet
Border
7750-SR Router
IPv4 Priv. IPv4 Public IPv4
Priv. IPv4 NAT44 NAT44 LSN
Continuity
ROUTED ROUTED
IPv6 2stack IPv6
IPv6
Router
Route IPv6 Dual-Stack
Migration ROUTED ROUTED
CGN (aka. large scale NAT or NAT444) is the most traditional approach to IPv4
continuity
Use of RFC1918 may collide with the addresses used within the subscriber LAN
IPv6 services can be offered in parallel to the NATed IPv4 service through dual-stack
BNGs.
No new feature required on CPE.
10 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
IPv4
Continuity
L2-aware NAT
Private IPv4
Network IPoE
BNG+ IPv4
PPPoE
Private IPv4 NAT44 Internet
Network 7750-SR
Server
L2TP
Private IPv4
Network IPv4
11 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
L2-aware NAT (cont’d)
BNG
Session1
169.168.1.1
NAT IPv4
Customer
Gateway Internet
12 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
3
IPv4 continuity over IPv6 Network
13 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
IPv4 IPv6
Continuity Migration
DS-Lite ( Dual stack Lite)
draft-ietf-softwire-dual-stack-lite
Dual-Stack Lite Broadband Deployments Following IPv4 Exhaustion
Carry IPv4 packet over IPv6 tunnel(IPv4-in-IPv6), on “IPv6 ONLY” Access Network
=> Reduce Management/Operational cost
Provide IPv4-to-IPv4 NAPT on AFTR(Concentrator)
=> Global IPv4 address saving by sharing the address in multiple users.
CPE needs update for feature adding
IPv4 IPv4 private IPv4 global
Continuity
IPv4-in-IPv6
14 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
DS-Lite Control plane sequence example
RS DHCPv6
Relay Configured
RA (default-gw only / No SLAAC) Tunnel-End-Point
2001:688:1f94:a::1
SOLICIT IA-PD | DNS
Relay-forw SOLICIT
IA-PD | DNS
Relay-reply ADVERTISE
ADVERTISE
IA-PD/64 | DNS 2000:1::40 | OPTION-99
IA-PD /64 | DNS 2000:1::40 /|OPTION-99
REQUEST
Relay-forw REQUEST
Relay-reply REPLY
REPLY
IA-PD /64 | DNS 2000:1::40 /|OPTION-99
Option-99 contains Tunnel-End-Point
2001:688:1f94:a::1
15 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
DS-Lite Packet Flow
Tunnel
Tunnel IPv4-in-IPv6
Priv. IPv4 IPV4 Global
RFC1918, 192.0.0.0/29 tunneled NAT44
Routing
DS-Lite
AFTR
IPv4 Server
Decap
IPv4 IPv4 IPv6 IPv4
v4NAPT
16 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
IPv4 IPv6
Continuity Migration
DS-Lite + A+P
draft-ietf-softwire-dual-stack-lite
draft-ymbk-aplusp
The A+P Approach to the IPv4 Address Shortage
Carry IPv4 packet over IPv6 tunnel(IPv4-in-IPv6), on “IPv6 ONLY” Access Network
CPE learns Global address/port-range, and CPE perform IPv4-IPv4 NAPT.
NAPT function can be distributed to CPE side, more scalable than DS-Lite. Minimal
state core.
More Flexible, more close to End-to-End transparency (but still limited)
IPv4 IPv4 private IPv4 global
Continuity
IPv4-in-IPv6
A+P
Dual NAT IPv6-only
BNG AFTR/
Stack
A+P router
IPv4
A+P
Internet
Dual NAT
Stack
A+P
NAT
Dual IPv6 Internet
Stack IPv6 only Dual-stack
IPv6
Access Core
Migration IPv6
17 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
DS-Lite + A+P Packet Flow
Tunnel
Tunnel IPv4-in-IPv6
Priv. IPv4 IPV4 Global
RFC1918, 192.0.0.0/29 tunneled Routing
NAT44
DS-Lite
A+P
Assigned port-range IPv4 Server
IP=12.0.0.3
Port=10000-11000
Decap
IPv4 IPv4 IPv6 IPv4
draft-despres-softwire-mesh-sam-01
draft-despres-softwire-4rd
SAM CE IPv4
Dual IPv6 Internet
Server
Stack network
IPv4 over IPv6
SAM Border IPv6 Internet
Relay
IPv4 IPv6
Private 4 NAT44 IPv6 Tunnel Route Public 4
19 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
SAM Address mapping format
C s 8 F h
64 64
Parameters:
F, C, s, h
F XXXXX XXXXXX
SAM interior ID
32
constant
prefix
20 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
SAM Address mapping format example
2001:a:5000:0:ff00:0:0:22
2001:a::/32 | s=4, h=8
198.0.0/20 4
C s 8 F h
64 64
2001:a: 5 0 0x22
IPv6 C XXXXX 0 0xFF F 0 XXXXXX
Parameters:
F, C, s, h
0 5 0x22
F XXXXX XXXXXX
SAM interior ID
198.0.0 0 5. 0x22
IPv4 C F XXXXX 0 XXXXXX
32
198.0.5.34(0x22)
21 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
RFC 5747
4over6 Transit Solution Using IP Encapsulation and MP-BGP Extensions
4o6 CE IPv4
Public IPv4 IPv6 Internet
Server
Network network
IPv4 over IPv6
4over6 IPv6 Internet
GW
BGP SAFI
- IPv4 prefix
- IPv6 address
IPv4 IPv6
Public 4 Route IPv6 Tunnel Route Public 4
Not Addressing IPv4 continuity. Just for IPv6 deployment in stateless tunnelling
User’s IPv4 prefix and IPv6 address(tunnel destination address for that IPv4
prefix) information are advertised via BGP as newly defined SAFI.
4over6 GW router must cache IPv4-prefix=IPv6-address mapping, and IPv4 traffic
is encapsulated by IPv6 header.
IPv4:IPv6 mapping advertiser(BGP speaker) can be another BGP router/server,
not CPE.
22 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
4
Rapid IPv6 deployment
23 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
RFC 5969 - IPv6 Rapid Deployment on IPv4 Infrastructures (6rd)
6rd CE
IPv6
Network
IPv6
IPv6 IPv4 Internet
Network
Network Server
6rd Border
Relay
IPv6 CGN
Network
IPv6 IPv4
6 Route 6to4 tunnel Route 6
6RD IPv6 address format: SP’s IPv6 prefix IPv4GA SubnetID InterfaceID
Addresses operators who want to quickly offer an IPv6 service over a non-IPv6 capable
network
Use 6to4 tunnel technique with specifying ISP’s IPv6 prefix. Stateless Tunneling
6rd border relay decapsulates IPv6 packet and routes in natively towards IPv6 Internet
6rd prefix and BR address can be obtained by DHCP option
IPv4 address required for 6to4 tunnel, CGN is optional.
24 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
6RD Packet Flow example
Decap
IPv6 IPv6 IPv4 IPv6
Dst-IPv6=v6Globalx Dst-IPv4=192.0.2.254 Dst-IPv6=v6Globalx
Src-IPv6= Src-IPv6=192.0.2.1 Src-IPv6=
2001:db8:c000:0201::xxxx Dst-IPv6=v6Global 2001:db8:c000:0201::xxxx
Src-IPv6=
2001:db8:c000:0201::xxxx
6RD Border can know destination IPv4 address for the packet from IPv6 internet to user,
by IPv6 destination address of the packet because user’s IPv4 address is embedded into it.
25 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
5
Wider IPv6 deployment
26 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
NAT64 (+ DNS64) IPv6
Migration
(draft-ietf-behave-v6v4-xlate-stateful/RFC6146)
Large Scale
IPv6 NAT
network
IPv4
Internet Server
IPv6 IPv6
network
network
IPv6
IPv6
network Internet
6 Route 6 NAT64 4
27 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
NAT64 (+ DNS64)
(draft-ietf-behave-v6v4-xlate-stateful)
DNS Query
DNS Query Pref64=2001:db8:8000::/64
AAAA example.com
AAAA example.com
DNS Response
NXDOMAIN
DNS Query
A example.com
28 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
IVI Translation
draft-xli-behave-ivi-07
IVI DNS
IPv4 IPv6
network network
IVI Xlate
v4 Xlate v6
29 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
5
Solution Comparison
30 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Summary of IPv4 continuation/IPv6 transition technologies
deployed IPv4
in parallel address.
32 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Consideration for technology implementation
33 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Appendix:
Multi-ServiceProvider Issue in IPv6
34 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
IPv6 Multi-SP Issues
xSP1’s dns server
BNG
WAN1
LAN
Router
switch
WAN2
35 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Problem: Source Address Selection
Wrong ISP
2001:db8:1000::/36
ISP-A
2001:db8:1000:1::100 Internet
2001:db8:8000:1::100
ISP-B
2001:db8:8000::/36
36 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Problem: Source Address Selection
Disconnected network
2001:db8:a000::1
2001:db8:1000::/36
ISP-A Internet
2001:db8:1000:1::100
2001:db8:8000:1::100
ASP-B
2001:db8:8000::/36
37 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Problem: Next-Hop Route Selection
IPv6
Internet
Corporate Partner
network network
38 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Problem: DNS Server Selection
Different Answers
Query: Internet
NSP
(Interne
cnn.com t)
ASP / VPN
Query: (myasp.com)
myasp.com
39 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
IETF Related I-Ds
<IETF>
- Source address selection policy
- draft-ietf-6man-addr-select-opt
Distributing Address Selection Policy using DHCPv6
- Route selection policy
- draft-ietf-mif-dhcpv6-route-option
DHCPv6 Route Option
- DNS selection policy
- draft-ietf-mif-dns-server-selection
- DNS Server Selection on Multi-Homed Hosts
40 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Source address selection/Route information/DNS selection distribution
RG/Host Behaviour
DHCPv6 ADVERTISE
IA_PD: 2001:1:0:1::/64
OPTION_ROUTE: 2001:1::/32 -> xSP1
DNS_SERVER_SELECT: 2001:1::10 xSP1.com
OPTION_DASP: 2001:1::/32, Label 1, Prec 30
DHCPv6 SOLICIT
IA_PD, OPTION_ROUTE,
DNS_SERVER_SELECT,
OPTION_DASP
OPTION_ROUTE: 2001:1::/32 -> xSP1
DHCPv6 ADVERTISE
2001:2::/32 -> xSP2 IA_PD: 2001:2:0:1::/64
OPTION_ROUTE: 2001:2::/32 -> xSP2
DNS_SERVER_SELECT: 2001:1::10 xSP1.com
DNS_SERVER_SELECT: 2001:2::10 xSP2.com
2001:2::10 xSP2.com OPTION_DASP: 2001:2::/32, Label 2, Prec 10
OPTION_DASP: 2001:1::/32, Label 1, Prec 30
2001:2::/32, Label 2, Prec 10
41 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
Source address selection/Route information/DNS selection distribution
RG/Host Behaviour
RA PIO:
2001:1:0:1::/64 Autonomous
2001:2:0:1::/64 Autonomous
Construct
IP address
DHCPv6 SOLICIT
OPTION_DASP
DHCPv6 ADVERTISE
OPTION_DASP: 2001:1::/32, Label 1, Prec 30
OPTION_DASP: 2001:2::/32, Label 2, Prec 10
DHCPv6 SOLICIT
OPTION_DASP
DHCPv6 ADVERTISE
OPTION_DASP: 2001:1::/32, Label 1, Prec 30
OPTION_DASP: 2001:2::/32, Label 2, Prec 10
42 | Apricot 2011 | IPv6 transition © 2010 Alcatel-Lucent. All rights reserved. Internal Use Only
THANK YOU