Opendium_Steve Posted November 25, 2019 Posted November 25, 2019 RIPE NCC have announced that they're expecting to run out of /22 IPv4 networks this week. Won't affect end-users yet, but it piqued my curiosity. How many schools have any IPv6 deployment yet?
mavhc Posted November 25, 2019 Posted November 25, 2019 I asked exa about it, but they said it wouldn't work with their surfprotect filtering
chris11256 Posted November 25, 2019 Posted November 25, 2019 Not planned yet & I haven't asked BT if we can have one. My last school was full dual stack with everything except BYOD. So I'd very much like to go down that route, just requries a lot of planning. 1
TechMonkey Posted November 25, 2019 Posted November 25, 2019 (edited) I've voted "not even thought about" though I've done preliminary planning, checking what can and can't work. Just not got so far as making a plan to actually roll it out. BT say we can have IPv6 addresses when ready (it was part of our tender for a new line), biggest issue is Smoothwall doesn't support it yet. Internally I'm confident everything important is compliant, I don't doubt that there will be a few silly devices that won't work. Biggest factor is me! I have a faint fear of not being able to reel off IP ranges and addresses. I need to study it more because I'm sure once I understand it more fully it will all be fine, but there is a slight irrational fear that the whole system is just handing over the controls and then you don't have to understand it, which worries me for when it goes wrong! Edited November 25, 2019 by TechMonkey 1
Opendium_Steve Posted November 25, 2019 Author Posted November 25, 2019 Not planned yet & I haven't asked BT if we can have one. In my experience, BT leased lines have come with IPv6 as standard for the past few years, so if you've got a BT leased line, getting IPv6 on the border at least should be easy. My last school was full dual stack with everything except BYOD. So I'd very much like to go down that route, just requries a lot of planning. Out of interest, was there a reason why it wasn't attempted on BYOD too? Biggest factor is me! I have a faint fear of not being able to reel off IP ranges and addresses. I need to study it more because I'm sure once I understand it more fully it will all be fine, but there is a slight irrational fear that the whole system is just handing over the controls and then you don't have to understand it, which worries me for when it goes wrong! Yes, I think not being able to remember IP addresses off the top of your head is a common fear. Mostly you can rely on DNS, but things can get a bit hairy when DNS goes wrong. Have you needed to convince the SLT to do any investment into this work (e.g. giving you time to plan, learn, etc.), or is it just something you've been doing when you've got some time spare, so no need to actually mention it to the higher-ups?
localzuk Posted November 25, 2019 Posted November 25, 2019 Thought about it a few years ago. Decided after looking at what it'd need across our network that it simply isn't something that's gonna affect us for a while. The internet isn't going to go IPv6 only any time soon, and even if it does, there's tunnelling that can be done. However, realistically, we could change our network *relatively* easy these days. I'm fairly sure everything except our Trend boiler controllers, and our older Net2 controllers (most of these have died and been replaced now though). It'd just take some diagraming, planning and setting up. Nothing overly complex. 1
TechMonkey Posted November 25, 2019 Posted November 25, 2019 Have you needed to convince the SLT to do any investment into this work (e.g. giving you time to plan, learn, etc.), or is it just something you've been doing when you've got some time spare, so no need to actually mention it to the higher-ups? No, they wouldn't have a clue what I was talking about. It is part of my job so I have just been plugging away as and when. Anything new that we source or tender for, the question is asked. Much like @localzuk, it really comes down to a cost benefit. For the amount of work we would have to put in, the snagging we would have to carry out after and the grief it may cause compared to the upside it really isn't a priority at the moment. But when it does it should be a relatively easy job of a bit of planning, adding in some IPv6 DHCP entries, a few edits to make static IPs to go DHCP and we should be golden... He said confidently! 1
mavhc Posted November 25, 2019 Posted November 25, 2019 Upgrade your switches and enable ipv6, check reserving ram for the ipv6 table doesn't affect performance. Set a test computer up with dual stack, see if anything breaks. Force internet via ipv6, check firewall, etc etc
chris11256 Posted November 25, 2019 Posted November 25, 2019 In my experience, BT leased lines have come with IPv6 as standard for the past few years, so if you've got a BT leased line, getting IPv6 on the border at least should be easy. Out of interest, was there a reason why it wasn't attempted on BYOD too? Yes, I think not being able to remember IP addresses off the top of your head is a common fear. Mostly you can rely on DNS, but things can get a bit hairy when DNS goes wrong. Have you needed to convince the SLT to do any investment into this work (e.g. giving you time to plan, learn, etc.), or is it just something you've been doing when you've got some time spare, so no need to actually mention it to the higher-ups? The no Ipv6 on BYOD wasn't my call. For some reason it just wasn't something that my old boss wanted to do.
FN-GM Posted November 25, 2019 Posted November 25, 2019 Can't believe the amount of people who haven't even thought about it yet!
TechMonkey Posted November 26, 2019 Posted November 26, 2019 But as I mentioned that option covers a multitude of sins, from not bothered up to the point just shy of having a plan. Plenty could have looked at it, have it as part of their purchasing standard but just don't have a plan to transition.
mcolbourn Posted November 26, 2019 Posted November 26, 2019 Well I voted "We've not even thought about IPv6 yet" but doing this now forces me to take a look and work out a plan of action etc.
Opendium_Steve Posted November 26, 2019 Author Posted November 26, 2019 Can't believe the amount of people who haven't even thought about it yet! I can, I'm afraid. Distinctly remember being in a network planning meeting, IPv6 was mentioned and the response was "oh you're not going to make us roll out IPv6 are you"? (Obviously the answer was "not if you don't want to" since the customer is always right, but still... ) Anyway, RIPE says they're now gone: https://www.ripe.net/publications/news/about-ripe-ncc-and-ripe/the-ripe-ncc-has-run-out-of-ipv4-addresses This currently doesn't mean a lot for end users. Existing ISPs and hosting providers generally have plenty of IPv4 addresses already and can reorganise to put them where they are needed. It's a big deal for new ISPs and hosting providers though - it basically means that you can't start a new ISP or hosting company, because you can't get any IPv4 addresses (and realistically, an IPv6-only datacentre isn't going to survive). And that's basically going to continue to be the case until the vast majority of end users have IPv6 connectivity.
FishCustard Posted November 26, 2019 Posted November 26, 2019 Planning only - almost all our equipment is IPv6 capable, only some plant may prove difficult. No IPv6 Internet connectivity. For some light entertainment... 2
Davit2005 Posted November 26, 2019 Posted November 26, 2019 (edited) We have a separate internet connection for a large department that I have setup IPv6 for. The rest of the network we have not any plans for IPv6 as yet, too many other considerations. I have a huge /56 IPv6 range provided by my home ISP which I am using internally, whilst IPv4 public IP addresses I have got the most that BT will give me of a /29. Edited November 26, 2019 by Davit2005
Chuckster Posted November 26, 2019 Posted November 26, 2019 How does IPv6 affect the internal network? Correct me if I'm wrong but, I thought you could leave it on the IPv4 whilst your front-facing device(s), e.g. firewall, can be IPv6, no?
pete Posted November 26, 2019 Posted November 26, 2019 Have a plan, done a limited internal deployment for testing. The Hurricane Electric IPv6 cert is educational: https://ipv6.he.net/certification 1
Opendium_Steve Posted November 26, 2019 Author Posted November 26, 2019 How does IPv6 affect the internal network? Correct me if I'm wrong but, I thought you could leave it on the IPv4 whilst your front-facing device(s), e.g. firewall, can be IPv6, no? No... well, it depends In order to talk to an IPv6-only server somewhere on the internet, your end of the IP connection needs to be IPv6. For web traffic, "your end of the IP connection" is probably your proxy, so you can get away with just having IPv6 on the proxy and IPv4 on the workstations. If you're using a transparent proxy, you'll probably want IPv6 all the way to the workstation. For other protocols, where a proxy isn't involved, you're probably going to need IPv6 across your whole LAN. There are some bodges (DNS46/NAT46, etc) to allow you to run an IPv4-only internal network and still talk to IPv6-only services, but you're probably better off going dual-stacked (so, both IPv4 and v6 across your whole network). If you really want to run a single-stack network, you're probably better off migrating the whole thing to IPv6-only and using technologies such as DNS64/NAT64, 464XLAT, etc. to make v4-only stuff work.
mavhc Posted November 26, 2019 Posted November 26, 2019 The main thing is to learn about ipv6, it's not just ipv4 with more numbers
mcolbourn Posted November 26, 2019 Posted November 26, 2019 The main thing is to learn about ipv6, it's not just ipv4 with more numbers No it has letters too
mavhc Posted November 26, 2019 Posted November 26, 2019 No it has letters too They're just higher numbers
mavhc Posted November 27, 2019 Posted November 27, 2019 eg https://www.nullzero.co.uk/android-does-not-support-dhcpv6-and-google-wont-fix-that RDNSS is required
Opendium_Steve Posted November 27, 2019 Author Posted November 27, 2019 eg https://www.nullzero.co.uk/android-does-not-support-dhcpv6-and-google-wont-fix-that The lack of DHCPv6 support in Android is a bit of a pain for networks using 802.1x or a captive portal to identify users (which is basically any BYOD network). Or rather, IPv6 privacy extensions are the problem, and using DHCPv6 happens to be about the only way to disable this feature. With IPv4, your gateway can associate a user name with an IP address (either by using a captive portal, or looking at the Framed-IP-Address attribute of RADIUS accounting messages). When your proxy sees requests coming from a specific IP address, it can look up who is currently known to be using that IP address. For IPv6, you can do the same if devices have a relatively stable addresses. Unfortunately, if you are using SLAAC, most devices now enable privacy extensions, which means they regularly change IP address. Your proxy (or whatever) can't easily figure out who is logged onto a specific IP address because the IP has probably changed since the user originally logged in. In fact, each device will actually use multiple addresses at the same time. There's no way for the router to tell devices to disable privacy extensions whilst still using SLAAC, the only thing you can do it tell devices to use DHCPv6 instead of SLAAC, which implicitly turns off the privacy extensions by assigning a fixed(ish) address to each device. So if devices don't support DHCPv6, you can't identify users by IP address, and instead you have to use the MAC address. Using the MAC address works fine, but limits your network topology - it means your devices must have a layer 2 connection to your proxy, because otherwise the proxy can't see the device's MAC address. Within Google, there seems to be a general belief that end-users should have the maximum amount of privacy possible, even from the network administrator... I don't think this attitude really holds up very well for enterprise networks - if you have a misbehaving device on your network its really important to know which device it is, so randomising the IP address every minute or so is pretty counter productive.
EXA_Mark Posted November 27, 2019 Posted November 27, 2019 Just a quickie from a suppliers perspective. We have been running dual-stack across our network infrastructure on IPv4 & v6 since 2007 and a huge amount of network traffic coming back into us, in particular sites such as Google and Facebook by default is via IPv6 nowadays. BUT very few customers across any sector, Education included have made the move, but the rapid deployment and exhaustion of v4 across the world (not us specifically) will mean people will have to do at some point in the not too distant future. If any of our customers on here want an IPv6 allocation, just give your account manager a call/email, or PM me. It should go without saying, but I will in case anyone asks, we do not charge for this, it is part of the standard service. 2
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now