Professional Documents
Culture Documents
Fgont Lacnog2017 Ipv6 Is Standard
Fgont Lacnog2017 Ipv6 Is Standard
Fgont Lacnog2017 Ipv6 Is Standard
Fernando Gont
LACNOG 2017
Montevideo, Uruguay. September 18-22, 2017
IPv6 is Internet Standard!(?)
Fernando Gont
LACNOG 2017
Montevideo, Uruguay. September 18-22, 2017
About the speaker...
Security Researcher and Consultant at SI6 Networks
Author/co-author of 30 IETF RFCs (15+ on IPv6)
Author of the SI6 Networks' IPv6 toolkit
https://www.si6networks.com/tools/ipv6toolkit
More information at: https://www.gont.com.ar
Everyday work:
Security
Assessment
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
What this presentation is about
4
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
What this presentation is about
Some IPv6-related documents have been recently elevated to
Internet Standard maturity level
For some, this is an indication of the level of maturity of IPv6
To an extent, we challenge/question such belief
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
A message from Bertrand Russell...
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
IETF Standards Maturity Levels
7
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
IETF standards maturity levels
IETF standards track documents have an associated maturity
level (RFC2026)
Proposed Standard (PS)
Spec is stable and well-understood
Draft Standard (DS)
PS + 2 independent implementations + successful operational experience
Internet Standard (IS)
PS ++ (significant implementation an operational experience)
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
What is IPv6?
9
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
What is IPv6?
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
What has been progressed to IS?
11
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Progressing IPv6 to IS
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Core IPv6 spec (RFC2460) to IS
Incorporated changes
14
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Core IPv6 spec (RFC2460) to IS
Deprecation of RHT0
15
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Deprecation of RHT0
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Core IPv6 spec (RFC2460) to IS
Fragmentation-related changes
17
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Overlapping fragments
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Generation of atomic fragments
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Generation of atomic fragments (II)
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Processing of atomic fragments
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Pathological first fragments
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Pathological first fragments (II)
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Core IPv6 spec (RFC2460) to IS
Omissions
24
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Operational experience with EHs
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Requirements for Frag IDs
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Core IPv6 spec (RFC2460) to IS
Controversy
27
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Insertion of IPv6 Extension Headers
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Insertion of IPv6 Extension Headers (II)
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Core IPv6 spec (RFC2460) to IS
Security Considerations
30
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Security Considerations
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Path-MTUD to (RFC1981) to IS
32
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Path MTU Discovery
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Path MTU Discovery to IS
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
IPv6 Addr. Arch. (RFC4291) to IS
(Failure to move...)
35
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Addressing architecture to IS
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Addressing architecture to IS (II)
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Conclusions
38
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Conclusions
Only a tiny part of the IPv6 protocol suite has been formally
elevated to Internet Standard
Despite hopes, there are aspects of the protocol for which we
lack wide-scale successful operational experience
At times, the maturity level of a spec is used as an excuse for
not changing it (including patching flaws)
All the above says nothing about the maturity of IPv6
implementations
Which is close to that of IPv4 implementations in the 90's
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Acknowledgements
40
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Ivan Arce (@4Dgifts)
An Argentina-based maradonian
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Enno Rey (@Enno_Insinuator)
A Germany-based maradonian
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Diego Armando Maradona
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Questions?
44
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017
Thanks!
Fernando Gont
fgont@si6networks.com
www.si6networks.com
LACNOG 2017
2017 SI6 Networks. All rights reserved
Montevideo, Uruguay. September 18-22, 2017