IPv Implementation - The Naked Truth
By
- Dr. Omar Amer Abouabdalla
IPv6 Global Sdn. Bhd.
- mar@ipv6global.my
IPv Implementation - The Naked Truth By Dr. Omar Amer - - PowerPoint PPT Presentation
IPv Implementation - The Naked Truth By Dr. Omar Amer Abouabdalla IPv6 Global Sdn. Bhd. omar@ipv6global.my Things to Connect to Internet Why IPv6??? No more room in IPv4 Quite empty in IPv6 IPv6 Implementation to to Where to
By
IPv6 Global Sdn. Bhd.
No more room in IPv4 Quite empty in IPv6
Where to start???
the safest to add IPv6.
issues such as security and management.
experience before going to the edge.
using dual stack strategy.
tunneling.
connect endpoints to Data Centers and apps that are IPv6- enabled.
in core cannot support IPv6.
Talking Behind My Back? Within the confines of your network, many devices may be communicating
not sending packets to and from the Internet!
Stateless Address Autoconfiguration SLAAC could automatically created a EUI-64 address. However, this makes your MAC public, which you may consider a privacy issue.
(CGA) [RFC 3972]
There are options to rectify this issue:
1. MAC Address: 90-3A-2B-06-2C-D1 2. Split in half: 90-3A-2B 06-2C-D1 3. Insert FFFE: 90:3A:2B:FF:FE:06:2C:D1 4. Change 7th bit to 1: 92:3A:2B:FF:FE:06:2C:D1
THC-IPv6 Attack Suite
Alive6 Parasite6 Redir6 Fake_Router6 Detect-New-IPv6 DoS-New-IPv6 Smurf6 rSmurf6 TooBig6 Fake_MIPv6 Fake_mld6 Fake_Advertiser6 SendPees6 DNSDict6 Trace6 Flood_Router6 Flood_Advertise6 Fuzz_IP6 etc…
Unfortunately, IPv6 security controls and products seems to be a bit behind.
THC-IPv6 Attack Suite Nmap Wireshark Multi-Generator (MGEN) IPv6 Security Scanner (vscan6) Halfscan6 Strobe Netcat6 Imps6-tools Relay6 6tunnel NT6tunnel VoodooNet Scapy6 Metasploit (etc.) Web Browsers (XSS & SQLi) TCPDump COLD Spak6 Isic6 Hyenae SendIP Packit 4to6ddos 6tunneldos
areas supporting the “wrong” version of protocol.
security policies.
their inability to check two protocols in the same time.
and IPv6 nodes.
dealing with the IPv4 A records as well as the IPv6 AAAA records.
software.
infrastructure to see if there is proper memory for route tables and the switch forwarding tables to handle IPv6 routes and packets.
support IPv6 configuration and routing protocols, while operating systems on the host side must also be IPv6 capable.
posture for the dual-stack environment (IPv4 and IPv6) at the same level as for IPv4 alone
software vendors (for monitoring, content distribution, and more) could work with IPv6.
network may not work the same way in an IPv6 environment.
administration tools may not provide full-fledged support for IPv6.
stop unwanted IPv4 traffic are unlikely to be effective at stopping any IPv6 traffic.
deny 192.168.12.0 0.0.0.255
deny ipv6 2001:db8:0:12::/64 any
an IPv6 address.
IPv6 is being implemented specifically because IPv4 addresses cannot be acquired.
tables.
addressing.
gradual basis, rather than all at once.
simplest approach.
either IPv4 or IPv6 to communicate.
communicate with a dual stacked node.
group of interconnected routers .
converted.
routers need to be converted first.
network are required, nor are the headaches that can occur when using them.
Readiness Assessment Implementation Strategy & Framework Implementation Conformance Audit
IPv6 Deployment Pre-deployment Deployment Post-deployment