Jump to content

Recommended Posts

Posted

As an end user, we don't really need to move very quickly at all. We are limited by our LEA/RBC connections in most cases. Even then, when they do change they will no doubt support IPv6->IPv4 NAT.

 

My guess will be that most areas will have roll-out programs at some point, co-ordinated by LEA ICT departments. Personally, I've sat down and had a look at what I need to do and started making a plan to implement it internally. As it stands though, a good amount of our equipment won't support IPv6 (our VOIP phones don't at the moment, nor do some of our printers, network scanners etc...). So, until I can be sure everything is IPv6 compatible, I'll be sticking with IPv4 internally anyway.

Posted
Several years at least, ISPs are dragging their feet hugely on this and you can keep 4 inside for most things at this point. We've been buying gear with support v6 for the past few years and so short of the core which is the case of a firmware upgrade we could switch over very easily. We won't need to for another couple of years at least even if the all singing/dancing fibre to the school stuff shows up on schedule.
Posted
I would do as local has and at least get a plan or audit what you have & if it can do IPv6. I have heard of some ISPs transferring over to IPv6 internally and this causing problems to some customers. This was mainly companies who had VLAN or proxy systems set up either with the ISP or to pass through them so I doubt it would effect a school yet but forewarned is forearmed.
Posted
Some of us work in private schools... no LA to direct or help us!

 

Eventually ISP's will or should start to migrate towards IPV6, at which point I'm sure they'll provide instructions on re-configuring routers etc. In theory we could all continue to run IPV4 internally forever - its not like any of us are going to max out the availible private IP blocks.

 

As IPV6 adoption becomes more widespread it'll be much easier to impliment, at the moment I'm sure most of us couldn't consider it for various reasons - we probably all have non-IPV6 compatible devices floating around

 

Also there are plenty of us on here working in private schools - who needs an LA ;) when the time comes(if it ever does) we'll get it sorted one way or another

Posted
With the size and (lack of) complexity of my network, I very much doubt I have anything that is v6 compliant. However, we are looking at some big changes (for us), replacing all the PCs to run Win7 and possibly going wireless, so it is something we need to factor in.
Posted
Definatly keep it in mind when buying new equipment. I'd imagine you'll find that things simply fall into place though, by the time you need to impliment IPV6 all non compliant devices will probably have been scrapped(6+ years?) or be on their way out.
Posted
Definatly keep it in mind when buying new equipment. I'd imagine you'll find that things simply fall into place though, by the time you need to impliment IPV6 all non compliant devices will probably have been scrapped(6+ years?) or be on their way out.

Even we should have got rid of our antiques in 6 years (says she crossing her fingers!) :D

Posted

Our talk at the edugeek conference covered (a little) v6 stuff. I think the slides are online here EduGeek Conference June 2011 in Preston « (James Evans) EduTech's Blog (the LUNS talk).

 

But yeah, the advice is basically, audit what you have and when buying new equipment, make sure it is v6 compatible so that when the "time comes" you can support it. Might also be worth finding out if your current ISP/provider offers any v6 or has a roadmap to do so (in the case of LEAs, I'd imagine the info will filter down to you eventually).

 

Rob

Posted

IPv6 is a commonly used term to scare people. In reality, even in the longest PC life cycles in education, you won't *need* IPv6 compliance until a PC you've just bought now is out of life. Out of all the members on this board, I would imagine only 0.01% have 100% IPv6 readiness from their internet network/PC/Mac to their ISP. A huge majority is still tunnelled through IPv4. Windows 7 and 2008 support it out of the box, so anything put in place now will theoretically already be compliant with the possible exception of network infrastructure. I know full well that EMBC need to replace the routers in a majority of shools in Northants for it to have any bearing and that won't be happening for a while yet.

 

Yes, it's going to happen. No, you won't be affected until you've retired/gotten bored of education/been priced out of your own job/no longer care.

My personal worry over it is security - IPv6 opens a HUGE can of worms on that side of things. My IRC network is taking it all with a pinch of salt currently for that reason, and any IRC network of note with full IPv6 support is battling daily to make it work. The same would apply to educational networks - filtering, site blocking, proxy blocking, anonymous TOR nodes etc. I'd actually be interested in seeing what LEA's/educational ISP's have in mind for that, and might bring it up at our next meeting :D

Posted

IP6 support on the PC side is easy even now, XP even supports IP6 and it is a couple of comand lines or maybe 15 clicks to switch it on. The biger issue is the interfaces on things like network printers, IP cameras, and the core issue is infact the core (switching and routing of IP6).

 

The things that will push IP6 forward are new tech like DirectAccess (assuming they ever make it easily configurable) and things like that which are just a nightmare to do without it. Assuming it is implemented properly it should actually make security better as many of the loopholes, workarounds and hacks that are implemented to shoehorn more hosts into IP4 are no longer required. For instance it would be possible to do end to end IPSEC encrypted communications from one host to another without it needing to be opened up, readdressed and checked to make sure that it is not tripping up by duplicatiing address spaces on each side of the link.

 

It will take time for people and software to get this stuff right though and that will be after the glacial ISPs get their stuff up to date and able to implement it, especially here. By the time it is widely avalible to most and is actually required it will be much easier.

 

Our IP6 connectivity at the moment is limited to direct local traffic as our core is not IP6 so the servers can all talk to each other quite happily over IP6 but as our ISP does not even have plans for IP6 yet upgrading our core seems pointless at this point. The new fibre network which may or may not be a farce should support it though so it makes sense to prepare where it does not cost any more or does not cost that much more.

Posted
In terms of the security ramifications - yes it needs thinking about, but it shouldn't be as big a perception shift as many may think. Yes your edge hosts may all be assigned 'global' addresses, but there will still be a border router on your network with a firewall. Just because it isn't NATing doesn't mean it isn't firewalling out all the same malicious ports/performing all the same traffic analysis as it was with v4. It just means that if you make a mistake in your border firewall rules, your edge hosts are more susceptible to being accessible from the outside (as obviously old v4 privates aren't globally routeable which provided a belt and braces to firewall misconfiguration). I see it as a benefit though. NAT does nothing but slow networks down (NAT processing is a lot more expensive than optimised routing) and cause end-to-end connectivity problems. With v6 there is just no need for NAT.
Posted

I wasn't referring quite so much to security as per direct access, but I meant via proxy anonymisers. Filtering out spoofed IPv4 addresses is (now) relatively simple, however IPv6 makes spoofing an IP literally as easy as it is to spoof a mac which has an absolute ton of ramifications. Unless it's sorted out, it's likely that spam email will multiply, botnets will become (and already are) extremely difficult to track, trace and nullify and as a direct result of that user infection levels will increase too.

It's not something I'm looking forward to dealing with.

Posted

It's an interesting discussion to have. In what way would you for-see the ability to spoof changing between v4 and v6 though? It's very hard to genuinely spoof addresses over the Internet (if you want to receive the return traffic back, which you'd need for the likes of TCP sessions for spamming etc). If however by spoofing you mean the use of anonymous Internet proxies, I don't see how that situation changes between v4 and v6? If anything, I'd see that getting rid of NAT should make combating spammers etc easier, as by ACLing or cutting off certain IP addresses, you don't run the risk of cutting off a NAT/proxy/service box and thus affecting the connectivity/services of a huge number of users.

 

Rob

Posted

The problem we've had so far from an IRC point of view is that with such a large array of addresses avaiable (which is a majority of the reason why we need to move on in the first place!) people seem to be able to get hold of an IPv6 address that wouldn't normally be available to them. I've never been aware of receiving packets meant for that IP as an issue (it is an issue obviously but nothing to do with IPv6) but just the ability to use them to proxy around restrictions is enough of a problem - hence the concern with botnets. From the same point of view NAT has rarely been a problem as we, even as the largest IRC network have no quarms about killing off an entire city's connection ability if it means our other users are safe, within good reason obviously.

I'm far from an expert on the darker side of this but my limited understanding is with more devices having a public facing IP address, there are more devices open to abuse and therefore they can be used to channel attacks - either directly (being part of a botnet) or as a proxy/passthrough for the intended traffic.

I would like to see some input from an ISP on all of that - I think it's certainly something we all need to get to grips with ASAP so we can at least prepare ourselves if not our current infrastructures.

Separately, I assume it's easy enough to maintain an IPv4 network and devices whilst having external IPv6 connetivity, therefore meaning we don't have to worry about things like printers?

Posted
I am going V6 external and V4 internal as no need internal to be running V6 what so ever. NAT to V6 is not much over head so simple solution and we are a big fe college.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...