IPv6 Deployment: Time for Action?
A while ago I was asked to write an article about IPv6 training. I could just cover the training aspect, like what’s offered (answer: not much) and whether someone can train the whole operations team like you could in the IPv4 or MPLS/VPN world (answer: no), but I wanted to understand whether anyone is really using IPv6 in a production network.
I found a few academic networks (after all, there are about 2000 IPv6 prefixes assigned and someone should be doing something with them), but not much of what I would call a real production environment, which is a bad thing, as it looks like the IPv4 address space will get saturated in a few years.
Update 2010-03-12: Numerous commercial ISPs now offer native IPv6 connectivity, but they also face significant deployment challenges. You will find an overview of those in my Upcoming Internet Challenges webinar. IPv6 edge- and backbone designs and configurations are explained in the Building Large IPv6 Service Provider Networks webinar.
My conclusions are summarized in the article I wrote for SearchTelecom.com. I still have mixed feelings about our ability to be IPv6-ready when needed (as well as when we’ll need it). At the very least, if you’re running an enterprise network, there’s no need to rush (unless, of course, there are tax breaks or incentives on the horizon); unless you decide to deploy IPv6 internally (hopefully for a good reason), the first time you’ll meet it is when you’ll deploy dual stack on your public servers to avoid NATing to IPv6-only clients on the public Internet.
Of course, I can be completely wrong, in which case I would highly appreciate your corrections.
We started because of a customers request. Right now we get more and more requests for internet-access using ipv6, but as shawn said, the traffic ist still marginally.
Time for enterprises to also say "hey, what the heck - we got it for free, let's leave it enabled and start running a trial - see how that goes".
- IPv6 only works with what cisco refer to as legacy firewall; it does not work with Zone-Based Firewall
- IPv6 does not work with BVI interfaces (you can't route bridged ipv6)
How about residential customers or SOHO offices? Anyone running IPv6 over DSL or cable? Dialup? IPv6 with AAA/Radius server? Production firewalls?
And, last but definitely not least, we all know that the biggest hurdles will be the applications :(
I setup my home router and connected to a free IPv6 tunnel broker. They provided me with a /64 (yes, /64, no kidding) for my LAN and I formed IPv6 BGP peering with their IPv6 router over the IPv6 GRE tunnel. I also enabled IOS IPv6 firewall but as of the latest IOS (12.4(15)T1) only basic TCP, UDP, and FTP are supported. On the LAN side you setup stateless DHCPv6 and enable your Windows XP or Vista to be dual-stack or just IPv6 only (only Vista can do that). I am still a novice in IPv6 but I must tell you that I have learned something from this home-lab setup with a real IPv6 tunnel broker over the Internet.
ECAI6 (European Conference on Applied IPv6) slides:
http://www.guug.de/veranstaltungen/ecai6-2007/abstracts.html