IPv6 Campus
Deployment Updates
Shumon Huque
University of Pennsylvania
Internet2 Joint Techs Conference
Salt Lake City, Utah
February 1st 2010
1
Campus Deployment
Updates Panel
• Shumon Huque, University of Pennsylvania
• Alan Whinery, University of Hawaii
• Randy Bush, Internet Initiative Japan
• Focus: move beyond talking about IPv6 just in the
network and into applications and services also.
2
Mark Prior’s deployment survey
www.mrp.net/IPv6_Survey.html
3
Web Mail DNS NTP XMPP
4
5
More comprehensive
examination
Would be useful to have a more comprehensive,
systematic categorization of IPv6 network &
application services available and used at the
campuses.What is the list of common applications?
Which are IPv6 capable? Are they production or
non-production? What is the scope (eg. department,
entire campus, etc)? ...
These panels may be one way of doing this.
6
Application Services
• DNS (authoritative, recursive)
• Web (HTTP)
• Email (SMTP, POP, IMAP, Submission)
• Time services (NTP, SNTP)
• Remote Login (SSH,Telnet, ...)
• Instant Messaging (XMPP, SIMPLE, ...)
• VoIP (SIP or any other protocol based)
• Authentication (Kerberos, PKI,Web-ISO systems ..)
• Directory (LDAP, ...)
7
More Services
• Address Assignment (SLAAC, stateless/stateful
DHCPv6)
• RA-Guard, SEND, DHCPv6 filtering
• Network Management (SNMP)
• Traffic accounting, characterization systems
(MRTG, Arbor Peakflow, Netflow v9/IPFIX, ...)
• IPsec in IPv6
• Disaster Recovery considerations
8
Middleboxes
• Firewalls
• IDS
• VPNs
• Server Load Balancers
• etc
9
Transition & Coexistence
Mechanisms
• NAT-PT (deprecated)
• NAT64, DNS64
• IVI
• Dual Stack Lite
• A+P
10
Multi-homing
• Provider-Independent (PI, portable) address
space?
• Future possibilities:
• SHIM6
• LISP (Locator/ID Separation Protocol)
• IRTF RRG (routing research group) work
11
Network
• Border, Core, Distribution, Edge, ...
• Percentage of subnets/routed-interfaces
• How many server & enduser subnets?
• How many of those are outside central IT?
• Estimated number of IPv6 capable devices
connected to native IPv6 infrastructure
• How much native vs tunnelled traffic
12
University of
Pennsylvania
update
13
Documentation
• http://www.upenn.edu/computing/ipv6/
• Penn IPv6 Deployment Strategy paper:
• http://www.upenn.edu/computing/ipv6/
strategy.html
14
Penn Deployment
Timeline
• Initial deployment began in our GigaPoP,
MAGPI (late 2002)
• Penn campus deployment began 2005
• Work ongoing (of course)
15
MAGPI GigaPoP
• PA Address space from Internet2 /40
• Routing: IS-IS, MBGP-4
• Stateless Address Autoconfiguration
• Services: DNS, NTP, SSH,Web
• Multicast (work in progress)
• Provides IPv6 to UPenn, Princeton, NJEdge
16
University campus
• Production deployment began 2005
• Started with PA space delegated from
MAGPI (2001:468:1802::/48)
• Later obtained PI space from ARIN -
2607:f470::/32
• Renumbering still in progress
17
Campus Network
• Routing: IS-IS, M-BGP4
• Border, core, & many distribution routers
• Growing # of enduser & server subnets
• All campus subnets by the end of FY’11?
• Engineering School: almost all subnets
• drivers: teaching & research; eliminate tunnels
18
External connectivity
• Singly homed today via MAGPI and
Internet2
• 2 Commercial ISPs: Level-3 & Cogent
• examining IPv6 options through them
• Level3:“beta” tunneled IPv6 service today,
“limited” (?) native service at end of 1Q
• Cogent: native or tunneled service today,
depending on location & connection type
19
Address Assignment
• Servers: static addresses
• Endstations
• Stateless autoconfig (mainly)
• DHCPv6 (planning)
20
Application Services
• Campus Wide Production Services:
• DNS
• NTP
• Jabber (XMPP)
21
DNS
• Authoritative DNS - ISC BIND
• Campus resolver - ISC BIND
• DNS Content Management system
• Homegrown, custom protocol
• Supports AAAA and v6 PTR records
22
Authoritative DNS
$ dig @192.5.6.30 +norecurse www.upenn.edu a
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1895
;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 4, ADDITIONAL: 6
;; AUTHORITY SECTION:
upenn.edu. 172800 IN NS dns1.udel.edu.
upenn.edu. 172800 IN NS dns2.udel.edu.
upenn.edu. 172800 IN NS noc2.dccs.upenn.edu.
upenn.edu. 172800 IN NS noc3.dccs.upenn.edu.
;; ADDITIONAL SECTION:
dns1.udel.edu. 172800 IN A 128.175.13.16
dns2.udel.edu. 172800 IN A 128.175.13.17
noc2.dccs.upenn.edu. 172800 IN A 128.91.254.1
noc2.dccs.upenn.edu. 172800 IN AAAA 2001:468:1802:102::805b:fe01
noc3.dccs.upenn.edu. 172800 IN A 128.91.251.158
noc3.dccs.upenn.edu. 172800 IN AAAA 2607:f470:1003::3:3
Looking at upenn.edu referral answer from EDU nameservers
referralglue
23
DNS resolver service
• IPv6 capable campus recursive resolvers
available, but ...
• No easy way to distribute them (don’t do
DHCPv6 yet, and not all clients can even do
DHCPv6, like Mac OS X)
• If someone asks, we tell them, and they
manually configure the addresses
24
Application Services
• Services posing impediments:
• Web (Akamai)*
• E-mail (Message Labs/Symantec)
*Disclaimer: I wasn’t involved in Akamaizing the Penn website, and
this is probably not the place to discuss the topic of whether
querier-specific DNS responses are good or evil, so I’m not going
to do that (today).
25
Web
;; QUESTION SECTION:
;www.upenn.edu.!! ! IN!A
;; ANSWER SECTION:
www.upenn.edu.! ! 300!IN!CNAME! www.upenn.edu.edgesuite.net.
www.upenn.edu.edgesuite.net. 19482 IN! CNAME! a536.g.akamai.net.
a536.g.akamai.net.! 20! IN! A! 128.91.34.234
a536.g.akamai.net.! 20! IN! A! 128.91.34.233
Penn website via Akamai IPv4, as viewed from
Penn
Penn-campus Akamai nodes, located on IPv6 capable network, so
IPv6 possible in theory.
26
Web
;; QUESTION SECTION:
;www.upenn.edu.!! ! IN!AAAA
;; ANSWER SECTION:
www.upenn.edu.! ! 300!IN!CNAME! www.upenn.edu.edgesuite.net.
www.upenn.edu.edgesuite.net. 19482 IN! CNAME! a536.g.akamai.net.
Penn website IPv6 view, via Akamai:
We had been talking privately with Akamai about a possible trial
IPv6 on the Penn campus Akamai nodes. But latest answer (1/28):
“No IPv6 rollout plan in the immediate future. However, we’d be
glad to work with you in rolling out IPv6 when we start the phased
rollout”.
No address records returned. No official IPv6 plans have been
announced by Akamai.
27
E-mail
• Central mail service uses Message Labs
• inbound/outbound virus scanning, and SPAM
scoring
• from our Message Labs rep: “IPv6 is not currently
on our roadmap” (June 2009)
• Mail access/submission? (IMAP, POP, webmail)?
• we might start with these first
28
Application Services
• Kerberos
• RADIUS
• CoSign/Shibboleth (Web ISO, federation)
• LDAP
29
Kerberos
• Server implementation: MIT Kerberos
• Production server names not yet IPv6
addressable
• We do have IPv6 specific server names
• kerberos{1,2,3}.ipv6.upenn.edu
• Users can manually install client side
configuration files that use them
30
CoSign
• Web ISO system (umich, weblogin.org)
• Login server support not there yet
• Web application servers can be deployed
on IPv6 and will be able to authenticate
users with CoSign
• Our Shibboleth deployment uses CoSign as
IDP (bottleneck) - I’ve heard other work is
needed to support it.
31
IPv6-IPv4 Transition
• Trial deployment of DualStack Lite on campus,
with Comcast & Engineering school faculty, as an
experiment/research project.
• http://tools.ietf.org/html/draft-ietf-softwire-dual-
stack-lite-02
• It’s more likely that Penn will deploy something like
NAT64 & DNS64 though, ie. enable v4-only and
v6-only devices to communicate.
32
33
Questions/Comments?
Shumon Huque
shuque [at] upenn.edu
34

More Related Content

PDF
Testing Rolling Roots
PDF
OARC 26: Scoring the Root Server System
PDF
Update on IPv6 activity in CERNET2
PDF
IPv6 in Finland - What Did We Measure?
PDF
mnNOG 1: Securing internet Routing
PDF
VNIX-NOG 2021: IPv6 Deployment Update
PDF
28th TWNIC OPM and TWNOG 2017: Security best practices for network operators
PDF
Welcome to the APNIC Member Gathering, Mongolia
Testing Rolling Roots
OARC 26: Scoring the Root Server System
Update on IPv6 activity in CERNET2
IPv6 in Finland - What Did We Measure?
mnNOG 1: Securing internet Routing
VNIX-NOG 2021: IPv6 Deployment Update
28th TWNIC OPM and TWNOG 2017: Security best practices for network operators
Welcome to the APNIC Member Gathering, Mongolia

What's hot (20)

PPTX
Extending the Yahoo Streaming Benchmark + MapR Benchmarks
PDF
Measuring IPv6 at Web Clients and Caching Resolvers
PDF
Rolling the Root Zone DNSSEC Key Signing Key
PDF
IPv6 Deployment Case on a Korean Governmental Website
PDF
HSB - Secure DNS en BGP ontwikkelingen - Benno Overeinder
PDF
Iptablesrocks
PDF
Kafka Summit SF Apr 26 2016 - Generating Real-time Recommendations with NiFi,...
PPTX
IPv6 and the DNS, RIPE 73
PDF
Openlab.2014 02-13.major.vi sion
PPTX
IPv6 deployment at APNIC
PPTX
Data centric mls rhel ecosystem
PPTX
Openstack meetup: Bootstrapping OpenStack to Corporate IT
PDF
BSides: BGP Hijacking and Secure Internet Routing
PDF
OARC 26: Who's asking
PDF
HTTP/2: What's new?
PPTX
PBS and Scheduling at NCI: The past, present and future
PDF
More specific announcments in BGP
PDF
Ingesting Drone Data into Big Data Platforms
PDF
Network Automation (Bay Area Juniper Networks Meetup)
PPTX
Future Architecture of Streaming Analytics: Capitalizing on the Analytics of ...
Extending the Yahoo Streaming Benchmark + MapR Benchmarks
Measuring IPv6 at Web Clients and Caching Resolvers
Rolling the Root Zone DNSSEC Key Signing Key
IPv6 Deployment Case on a Korean Governmental Website
HSB - Secure DNS en BGP ontwikkelingen - Benno Overeinder
Iptablesrocks
Kafka Summit SF Apr 26 2016 - Generating Real-time Recommendations with NiFi,...
IPv6 and the DNS, RIPE 73
Openlab.2014 02-13.major.vi sion
IPv6 deployment at APNIC
Data centric mls rhel ecosystem
Openstack meetup: Bootstrapping OpenStack to Corporate IT
BSides: BGP Hijacking and Secure Internet Routing
OARC 26: Who's asking
HTTP/2: What's new?
PBS and Scheduling at NCI: The past, present and future
More specific announcments in BGP
Ingesting Drone Data into Big Data Platforms
Network Automation (Bay Area Juniper Networks Meetup)
Future Architecture of Streaming Analytics: Capitalizing on the Analytics of ...
Ad

Similar to IPv6 Campus Deployment Panel (20)

PPT
MAGPI: Advanced Services: IPv6, Multicast, DNSSEC
PDF
Tech 2 Tech IPv6 presentation
PDF
IPv6 Security Panel (U of Penn)
PDF
12.00 - Dr. Tim Chown - University of Southampton
PPTX
IPv6 deployment on GridPP & WLCG
PPTX
APNIC Update
PPTX
Network research
PDF
IPv6 Deployment: Why and Why not?
PPTX
Challenges in Practicing High Frequency Releases in Cloud Environments
PDF
The performance of IPv6, by John Brzozowski [APNIC 38 / IPv6 Plenary]
PDF
Private Network Project for Colleges
PDF
02 - IDNOG04 - Sheryl Hermoso (APNIC) - IPv6 Deployment at APNIC
PDF
Successes and Challenges of IPv6 Transition at APNIC
PDF
ION Ljubljana - Nathalie Trenaman: World IPv6 Launch and RIPE Atlas Visualisa...
PDF
2012 11-09 facex - i pv6 transition planning-
PPTX
IPv6 on the Interop Network
PPTX
Future services on Janet
PDF
Getting The World IPv6 Enabled
PDF
SIPv6 Test Program
PDF
IPv6 Deployment: Why and Why not? - HostingCon 2013
MAGPI: Advanced Services: IPv6, Multicast, DNSSEC
Tech 2 Tech IPv6 presentation
IPv6 Security Panel (U of Penn)
12.00 - Dr. Tim Chown - University of Southampton
IPv6 deployment on GridPP & WLCG
APNIC Update
Network research
IPv6 Deployment: Why and Why not?
Challenges in Practicing High Frequency Releases in Cloud Environments
The performance of IPv6, by John Brzozowski [APNIC 38 / IPv6 Plenary]
Private Network Project for Colleges
02 - IDNOG04 - Sheryl Hermoso (APNIC) - IPv6 Deployment at APNIC
Successes and Challenges of IPv6 Transition at APNIC
ION Ljubljana - Nathalie Trenaman: World IPv6 Launch and RIPE Atlas Visualisa...
2012 11-09 facex - i pv6 transition planning-
IPv6 on the Interop Network
Future services on Janet
Getting The World IPv6 Enabled
SIPv6 Test Program
IPv6 Deployment: Why and Why not? - HostingCon 2013
Ad

More from Shumon Huque (20)

PDF
DANE and DNSSEC Authentication Chain Extension for TLS
PDF
Client Certificates in DANE TLSA Records
PDF
Query-name Minimization and Authoritative Server Behavior
PDF
DANE and Application Uses of DNSSEC
PDF
Hands-on getdns Tutorial
PDF
DANE and Application Uses of DNSSEC
PDF
IPv6 Tutorial; USENIX LISA 2013
PDF
DNSSEC Tutorial; USENIX LISA 2013
PDF
IPv6 Transition in Research & Education
PDF
Authorization at Penn
PDF
IPv6 Deployment Panel
PDF
A survey of DNSSEC Deployment in the US R&E Community
PDF
World IPv6 Launch at Penn
PDF
Open Source VoIP at Penn
PDF
Kerberos at Penn (MIT Kerberos Consortium)
PPT
.EDU DNSSEC Testbed - Lessons Learned
PDF
.EDU DNSSEC Testbed
PDF
DNSSEC at Penn
PDF
PennNet and MAGPI
PPT
Internet2 DNSSEC Pilot
DANE and DNSSEC Authentication Chain Extension for TLS
Client Certificates in DANE TLSA Records
Query-name Minimization and Authoritative Server Behavior
DANE and Application Uses of DNSSEC
Hands-on getdns Tutorial
DANE and Application Uses of DNSSEC
IPv6 Tutorial; USENIX LISA 2013
DNSSEC Tutorial; USENIX LISA 2013
IPv6 Transition in Research & Education
Authorization at Penn
IPv6 Deployment Panel
A survey of DNSSEC Deployment in the US R&E Community
World IPv6 Launch at Penn
Open Source VoIP at Penn
Kerberos at Penn (MIT Kerberos Consortium)
.EDU DNSSEC Testbed - Lessons Learned
.EDU DNSSEC Testbed
DNSSEC at Penn
PennNet and MAGPI
Internet2 DNSSEC Pilot

Recently uploaded (20)

PDF
Consumable AI The What, Why & How for Small Teams.pdf
PDF
sustainability-14-14877-v2.pddhzftheheeeee
PDF
“A New Era of 3D Sensing: Transforming Industries and Creating Opportunities,...
PPTX
TEXTILE technology diploma scope and career opportunities
PDF
Improvisation in detection of pomegranate leaf disease using transfer learni...
DOCX
Basics of Cloud Computing - Cloud Ecosystem
PDF
NewMind AI Weekly Chronicles – August ’25 Week III
PPTX
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
PPT
What is a Computer? Input Devices /output devices
PPT
Module 1.ppt Iot fundamentals and Architecture
PDF
Credit Without Borders: AI and Financial Inclusion in Bangladesh
PDF
Accessing-Finance-in-Jordan-MENA 2024 2025.pdf
PDF
STKI Israel Market Study 2025 version august
PPTX
The various Industrial Revolutions .pptx
PDF
The influence of sentiment analysis in enhancing early warning system model f...
PDF
OpenACC and Open Hackathons Monthly Highlights July 2025
PDF
A proposed approach for plagiarism detection in Myanmar Unicode text
PPT
Geologic Time for studying geology for geologist
PPTX
Build Your First AI Agent with UiPath.pptx
PDF
sbt 2.0: go big (Scala Days 2025 edition)
Consumable AI The What, Why & How for Small Teams.pdf
sustainability-14-14877-v2.pddhzftheheeeee
“A New Era of 3D Sensing: Transforming Industries and Creating Opportunities,...
TEXTILE technology diploma scope and career opportunities
Improvisation in detection of pomegranate leaf disease using transfer learni...
Basics of Cloud Computing - Cloud Ecosystem
NewMind AI Weekly Chronicles – August ’25 Week III
MicrosoftCybserSecurityReferenceArchitecture-April-2025.pptx
What is a Computer? Input Devices /output devices
Module 1.ppt Iot fundamentals and Architecture
Credit Without Borders: AI and Financial Inclusion in Bangladesh
Accessing-Finance-in-Jordan-MENA 2024 2025.pdf
STKI Israel Market Study 2025 version august
The various Industrial Revolutions .pptx
The influence of sentiment analysis in enhancing early warning system model f...
OpenACC and Open Hackathons Monthly Highlights July 2025
A proposed approach for plagiarism detection in Myanmar Unicode text
Geologic Time for studying geology for geologist
Build Your First AI Agent with UiPath.pptx
sbt 2.0: go big (Scala Days 2025 edition)

IPv6 Campus Deployment Panel

  • 1. IPv6 Campus Deployment Updates Shumon Huque University of Pennsylvania Internet2 Joint Techs Conference Salt Lake City, Utah February 1st 2010 1
  • 2. Campus Deployment Updates Panel • Shumon Huque, University of Pennsylvania • Alan Whinery, University of Hawaii • Randy Bush, Internet Initiative Japan • Focus: move beyond talking about IPv6 just in the network and into applications and services also. 2
  • 3. Mark Prior’s deployment survey www.mrp.net/IPv6_Survey.html 3
  • 4. Web Mail DNS NTP XMPP 4
  • 5. 5
  • 6. More comprehensive examination Would be useful to have a more comprehensive, systematic categorization of IPv6 network & application services available and used at the campuses.What is the list of common applications? Which are IPv6 capable? Are they production or non-production? What is the scope (eg. department, entire campus, etc)? ... These panels may be one way of doing this. 6
  • 7. Application Services • DNS (authoritative, recursive) • Web (HTTP) • Email (SMTP, POP, IMAP, Submission) • Time services (NTP, SNTP) • Remote Login (SSH,Telnet, ...) • Instant Messaging (XMPP, SIMPLE, ...) • VoIP (SIP or any other protocol based) • Authentication (Kerberos, PKI,Web-ISO systems ..) • Directory (LDAP, ...) 7
  • 8. More Services • Address Assignment (SLAAC, stateless/stateful DHCPv6) • RA-Guard, SEND, DHCPv6 filtering • Network Management (SNMP) • Traffic accounting, characterization systems (MRTG, Arbor Peakflow, Netflow v9/IPFIX, ...) • IPsec in IPv6 • Disaster Recovery considerations 8
  • 9. Middleboxes • Firewalls • IDS • VPNs • Server Load Balancers • etc 9
  • 10. Transition & Coexistence Mechanisms • NAT-PT (deprecated) • NAT64, DNS64 • IVI • Dual Stack Lite • A+P 10
  • 11. Multi-homing • Provider-Independent (PI, portable) address space? • Future possibilities: • SHIM6 • LISP (Locator/ID Separation Protocol) • IRTF RRG (routing research group) work 11
  • 12. Network • Border, Core, Distribution, Edge, ... • Percentage of subnets/routed-interfaces • How many server & enduser subnets? • How many of those are outside central IT? • Estimated number of IPv6 capable devices connected to native IPv6 infrastructure • How much native vs tunnelled traffic 12
  • 14. Documentation • http://www.upenn.edu/computing/ipv6/ • Penn IPv6 Deployment Strategy paper: • http://www.upenn.edu/computing/ipv6/ strategy.html 14
  • 15. Penn Deployment Timeline • Initial deployment began in our GigaPoP, MAGPI (late 2002) • Penn campus deployment began 2005 • Work ongoing (of course) 15
  • 16. MAGPI GigaPoP • PA Address space from Internet2 /40 • Routing: IS-IS, MBGP-4 • Stateless Address Autoconfiguration • Services: DNS, NTP, SSH,Web • Multicast (work in progress) • Provides IPv6 to UPenn, Princeton, NJEdge 16
  • 17. University campus • Production deployment began 2005 • Started with PA space delegated from MAGPI (2001:468:1802::/48) • Later obtained PI space from ARIN - 2607:f470::/32 • Renumbering still in progress 17
  • 18. Campus Network • Routing: IS-IS, M-BGP4 • Border, core, & many distribution routers • Growing # of enduser & server subnets • All campus subnets by the end of FY’11? • Engineering School: almost all subnets • drivers: teaching & research; eliminate tunnels 18
  • 19. External connectivity • Singly homed today via MAGPI and Internet2 • 2 Commercial ISPs: Level-3 & Cogent • examining IPv6 options through them • Level3:“beta” tunneled IPv6 service today, “limited” (?) native service at end of 1Q • Cogent: native or tunneled service today, depending on location & connection type 19
  • 20. Address Assignment • Servers: static addresses • Endstations • Stateless autoconfig (mainly) • DHCPv6 (planning) 20
  • 21. Application Services • Campus Wide Production Services: • DNS • NTP • Jabber (XMPP) 21
  • 22. DNS • Authoritative DNS - ISC BIND • Campus resolver - ISC BIND • DNS Content Management system • Homegrown, custom protocol • Supports AAAA and v6 PTR records 22
  • 23. Authoritative DNS $ dig @192.5.6.30 +norecurse www.upenn.edu a ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1895 ;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 4, ADDITIONAL: 6 ;; AUTHORITY SECTION: upenn.edu. 172800 IN NS dns1.udel.edu. upenn.edu. 172800 IN NS dns2.udel.edu. upenn.edu. 172800 IN NS noc2.dccs.upenn.edu. upenn.edu. 172800 IN NS noc3.dccs.upenn.edu. ;; ADDITIONAL SECTION: dns1.udel.edu. 172800 IN A 128.175.13.16 dns2.udel.edu. 172800 IN A 128.175.13.17 noc2.dccs.upenn.edu. 172800 IN A 128.91.254.1 noc2.dccs.upenn.edu. 172800 IN AAAA 2001:468:1802:102::805b:fe01 noc3.dccs.upenn.edu. 172800 IN A 128.91.251.158 noc3.dccs.upenn.edu. 172800 IN AAAA 2607:f470:1003::3:3 Looking at upenn.edu referral answer from EDU nameservers referralglue 23
  • 24. DNS resolver service • IPv6 capable campus recursive resolvers available, but ... • No easy way to distribute them (don’t do DHCPv6 yet, and not all clients can even do DHCPv6, like Mac OS X) • If someone asks, we tell them, and they manually configure the addresses 24
  • 25. Application Services • Services posing impediments: • Web (Akamai)* • E-mail (Message Labs/Symantec) *Disclaimer: I wasn’t involved in Akamaizing the Penn website, and this is probably not the place to discuss the topic of whether querier-specific DNS responses are good or evil, so I’m not going to do that (today). 25
  • 26. Web ;; QUESTION SECTION: ;www.upenn.edu.!! ! IN!A ;; ANSWER SECTION: www.upenn.edu.! ! 300!IN!CNAME! www.upenn.edu.edgesuite.net. www.upenn.edu.edgesuite.net. 19482 IN! CNAME! a536.g.akamai.net. a536.g.akamai.net.! 20! IN! A! 128.91.34.234 a536.g.akamai.net.! 20! IN! A! 128.91.34.233 Penn website via Akamai IPv4, as viewed from Penn Penn-campus Akamai nodes, located on IPv6 capable network, so IPv6 possible in theory. 26
  • 27. Web ;; QUESTION SECTION: ;www.upenn.edu.!! ! IN!AAAA ;; ANSWER SECTION: www.upenn.edu.! ! 300!IN!CNAME! www.upenn.edu.edgesuite.net. www.upenn.edu.edgesuite.net. 19482 IN! CNAME! a536.g.akamai.net. Penn website IPv6 view, via Akamai: We had been talking privately with Akamai about a possible trial IPv6 on the Penn campus Akamai nodes. But latest answer (1/28): “No IPv6 rollout plan in the immediate future. However, we’d be glad to work with you in rolling out IPv6 when we start the phased rollout”. No address records returned. No official IPv6 plans have been announced by Akamai. 27
  • 28. E-mail • Central mail service uses Message Labs • inbound/outbound virus scanning, and SPAM scoring • from our Message Labs rep: “IPv6 is not currently on our roadmap” (June 2009) • Mail access/submission? (IMAP, POP, webmail)? • we might start with these first 28
  • 29. Application Services • Kerberos • RADIUS • CoSign/Shibboleth (Web ISO, federation) • LDAP 29
  • 30. Kerberos • Server implementation: MIT Kerberos • Production server names not yet IPv6 addressable • We do have IPv6 specific server names • kerberos{1,2,3}.ipv6.upenn.edu • Users can manually install client side configuration files that use them 30
  • 31. CoSign • Web ISO system (umich, weblogin.org) • Login server support not there yet • Web application servers can be deployed on IPv6 and will be able to authenticate users with CoSign • Our Shibboleth deployment uses CoSign as IDP (bottleneck) - I’ve heard other work is needed to support it. 31
  • 32. IPv6-IPv4 Transition • Trial deployment of DualStack Lite on campus, with Comcast & Engineering school faculty, as an experiment/research project. • http://tools.ietf.org/html/draft-ietf-softwire-dual- stack-lite-02 • It’s more likely that Penn will deploy something like NAT64 & DNS64 though, ie. enable v4-only and v6-only devices to communicate. 32
  • 33. 33