QI Fazhi/IHEP CC
IPv6 Deployment @IHEP
QI Fazhi/ IHEP CC Fazhi.QI@ihep.ac.cn HEPiX,Beijing, October 2012
IPv6 Deployment @IHEP QI Fazhi/ IHEP CC Fazhi.QI@ihep.ac.cn - - PowerPoint PPT Presentation
IPv6 Deployment @IHEP QI Fazhi/ IHEP CC Fazhi.QI@ihep.ac.cn HEPiX,Beijing, October 2012 QI Fazhi IHEP CC 2 Context Why IPv6? Background & History Key technologies Deployment Principles Current Status Work Plan QI
QI Fazhi/IHEP CC
QI Fazhi/ IHEP CC Fazhi.QI@ihep.ac.cn HEPiX,Beijing, October 2012
QI Fazhi/IHEP CC
2 *
QI Fazhi/IHEP CC
QI Fazhi/IHEP CC
CNGI project approved, Leaded by National Reform and Development Committee, Started the Chinese IPv6 Network backbone deployment Chinese Government released the “Twelfth Five-Year” Development Plan for next-generation
Premier Wen Jiabao Chaired the State Council meeting to discuss how to speed up the develpoment of the China Next Generation network
The National Reform and Development Committee fund for the research of CNGI industrialization and security projects
QI Fazhi/IHEP CC
QI Fazhi/IHEP CC
QI Fazhi/IHEP CC
– 1Gbps IPv6 Link to CNGI, Part of IHEP endpoints support IPv6
– IHEP started to use the IPv6 Link to do the HEP data transfer between the cooperated Universities(SDU/…)
– IHEP DNS supports IPv6
– Dual Stack IHEP Campus Network, 10Gbps IPv6 link CNGI(Fund from The National Reform and Development Committee ) – Associated with ChinaNet/Universities, applied the CNGI industrialization and security projects
QI Fazhi/IHEP CC
QI Fazhi/IHEP CC
– tunnel between IPv6 islands – translate between IPv4 and IPv6
– Configured tunnels
– Automatic tunnels
– Server-based automatic tunneling
– Router to router
Addressing Protocol)
– Host to router, router to host – Maybe host to host
– Host to router, router to host
QI Fazhi/IHEP CC
– To use the high available bandwidth
transfer,
– Network performance: 10 times improvement
USTC IPv6 Server IHEP IPv6 Server USTC Router IHEP Router eth0 eth0 eth1 eth1 eth1 eth1 USTC IHEP IPv6 Network Link (CNGI)
QI Fazhi/IHEP CC
– Stateless Autoconfiguration
from any other device.
– Stateful Autoconfiguration
a server.
QI Fazhi/IHEP CC
– new port numbers
– a new message format, and restructured options
QI Fazhi/IHEP CC
QI Fazhi/IHEP CC
– Users (IP) management – Monitoring – Access control
– DNS – WEB – Email – ……
QI Fazhi/IHEP CC
– IPv6/IPv4 host addresses assigned by DHCPv6/DHCPv4 servers, based on the MAC address declared in the IPDB
QI Fazhi/IHEP CC
– Internal(Private) Network
– To Internet: open – From Internet: Deny
– DMZ1:Special Server/User Network
– DMZ2: Public Server Network
can not access internal area
– WAN: Internet zone
QI Fazhi/IHEP CC
QI Fazhi/IHEP CC
– All the network devices(switch/router/firewall) support IPv6
– Easy to do (all the devices are dual stack supported) – Cacti & Nagios with IPv6 patch
– The ipdb & access control system: in production – DHCPv6: on going
achieve ipv6 address.
– Firewall: in production – IDS: in production – Network traffic and user behavior analysis: on going
QI Fazhi/IHEP CC
– 2001:cc0:2010::0/48
– One IPv6 subnet per vlan, together with the IPv4 subnet. Subnet mask: /64 – For example:Vlan 32: 202.122.32.0/24 2001:cc0:2010:32::0/64
– DNS: ✔ – DHCP: ✔ – NTP: ✔ – Web(partly supported) – Video webcast: on going
QI Fazhi/IHEP CC
Online Register
MAC/User Name/Email/Tel/Building/R
number/……
Switch configuration updated Assign IP address
IPDB
DHCP configuration updated save
Approved by Admin
Submit no
Switch information: IP/Port/Vlan/ Switch-Room/Plugin Number relationship Vlan/IP subnet/switch-port relationship IP/MAC relationship ……
QI Fazhi/IHEP CC
QI Fazhi/IHEP CC
– DHCPv6 client for windows xp
– Most of the IHEP IPv6 traffic are video/iptv/…… – Less scientific data go through IPv6
QI Fazhi/IHEP CC
– Public web services running here
– HEPiX IPv6 Group
– In discussion
QI Fazhi/IHEP CC