IPv6 &lanne Ciscon tuo2eissa Ser$fioinnit Rei&tys Tietoturva IPSec toimipisteyhteydet Anyconnect etäyhteydet Kuormanjako/Osoitemuunnokset Kollaboraa&otuo2eet WLAN
h2ps://www.ipv6ready.org/
h2ps://www.ipv6ready.org/db/index.php/public/search/?l=&c=&ds=&de=&pc=2&ap=2&oem=&etc=&fw=&vn=cisco+systems&do=1&o=13
UGSv6 Profile h2p://www.cisco.com/web/strategy/government/security_cer&fica&on/cert_ipv6.html
h2p://www.ripe.net/ripe/docs/current- ripe- documents/ripe- 554#intro1
(L2- kytkimille) Cat3XXX/cat4XXX ei tunneloi Cat3XXX/cat4XXX ei tunneloi X
X??
X
IPv6 &lanne Ciscon tuo2eissa Ser&fikaa&t Rei$tys Tietoturva IPSec toimipisteyhteydet Anyconnect etäyhteydet Osoitemuunnokset Kollaboraa$otuoCeet WLAN
Rei&]met ja kytkimet varsin OK Perustoiminnallisuudet Kytkinten MLD snooping IPv6 First Hop Security 2960, cat3560/3750 (15.0(2)SE), Cat4600, Cat6500 IPv6 support on BVI Interface 15.1(2)T Mahdollistaa WLAN tuen 800-sarjalaisissa VRF toiminnallisuus Cat3XXX/cat4XXX kytkimissä, catalyst 6500 OK
Cisco IPv6 Security ASA Firewall Since version 7.0 (released 2005) Flexibility: Dual stack, IPv6 only, IPv4 only Stateful- Failover (ASA 8.2.2) Cannot configure extension headers in ACL (but parsing is done) USGv6 profile NPD 8.4.2(10)- > IOS Firewall IOS 12.3(7)T (released 2005) Zone- based firewall on IOS- XE 3.6 (2012) IPS Since 6.2 (released 2008) Email Security Appliance (ESA) end 2011 Web Security Appliance (WSA) end 2011
ASA Firewall IPv6 Support
IPSec toimipisteyhteydet IPv6 tunnelit IPv4 yli (IPSec/DMVPN) OK DMVPN IPv6 verkon yli 15.2(1)T Dynaamiset osoi2eet etätoimipisteillä Etätoimipisteiden väliset dynaamiset tunnelit Helppo konfiguroin& päätoimipisteellä
Anyconnect 3.1 etäyhteydet Työasemaversio (ios/android versio ei vielä tue IPv6:Ca) Client IP Assigned IP Cisco ASA Headend SSL and DTLS IKEv2 (IPsec) IPv4 IPv4 IPv4 Yes Yes IPv4 IPv6 IPv4 Yes No IPv4 and IPv6 IPv4 IPv4 and IPv6 Yes Yes IPv4 and IPv6 IPv6 IPv4 and IPv6 Yes No IPv4 and IPv6 IPv4 and IPv6 IPv4 and IPv6 Yes No IPv6 IPv4 IPv6 Yes Yes IPv6 IPv6 IPv6 Yes No
Palvelinten kuormanjako/ osoitemuunnokset ACE SLB66 v6 v6 v6 ACE SLB64 v6 v4 v4 v6 v4 A5(1.0) ACE30, ACE4710 A5(1.0) ACE30, ACE4710 Stateful NAT64 v6 v4 v4 server
Osoitemuunnokset Stateless NAT64 ASR1000 tammikuu 2011 Stateful NAT64 ASR1000 kesäkuu 2011 Mahdollistaa liikenteen IPv6 verkosta IPv4 interne]in
Kollaboraa$oratkaisut
IPv6 in WLAN <7.2 CAPWAP Tunnel IPv6 ICMPv6 mul&cast messages sent to all clients (including L3 roamed clients) at low data rates. All IPv6 packets are bridged on the VLAN transmi]ng unnecessary ICMPv6 messages in both direc&ons. In releases prior to 7.2, enabling IPv6 bridging provided a limited solu&on with no Layer 3 mobility and non- op&mized delivery of essen&al ICMPv6 messages to clients.
Wireless LAN Mobility Security / First Hop Security Guest Access: Wired/Wireless Media Rich Deployment / Quality of Services Branch Deployment Consideration Location Services Dual Stack Client Management
Many IPv6 Addresses Per Client Up to 8 IPv6 Addresses are Tracked per Client Support for many IPv6 addresses per client is necessary because: Clients can have mul&ple address types per interface Clients can be assigned addresses via mul&ple methods such as SLAAC and DHCPv6 Most clients automa&cally generate a temporary address in addi&on to assigned addresses
SSID-A Anchor WLC CAPWAP Tunnel DHCPv6 /RA Reply Router 1 Roaming Client SSID-A Mobility Tunnel DHCPv6/NDP CAPWAP Tunnel Foreign WLC Router 2 IPv6 address is always learned at the anchor either through DHCPv6 or NDP DHCPv6 from a roamed client at the foreign controller will be tunneled to the anchor controller, which will learn the IPv6 address from the DHCPv6 replies. Similarly NDP messages for a roamed client are processed at the anchor controller. Whenever a new IPv6 address is learned at the anchor the new address is sent in a mobility message to the foreign controller.
CAPWAP Tunnel IPv6 VLAN Ethernet IPv6 802.11 Router Advertisement IPv6 802.11 CAPWAP IPv4 Ethernet RA Guard - RA from client blocked at AP (Local and FlexConnect) Undesired IPv6 Addresses/Prefix Source Guard DHCP Server Advertisement DHCP SA blocked at Wireless Controller (will not be implemented in 7.2, scoped for future)
CAPWAP Tunnel IPv6 VLAN Ethernet IPv6 802.11 IPv6 802.11 CAPWAP IPv4 Ethernet Rate Limiting/ Throttling Router Advertisement (Periodic) Neighbor Solicitation Suppression Neighbor Discovery Suppression Neighbor Solicitation Proxy Neighbor Advertisement Neighbor Solicitation Dropping NS at Controller for unknown mobile clients Neighbor Discovery (ND) Suppression - Response to NS with cache binding table entries
Existing guest network can be upgraded to support dual stack clients for both wired and wireless access Guest authentication is performed only once for dual stack clients before allowing access to the network Internet DMZ or Anchor Wireless Controller Guest client IP addresses can be obtained at the DMZ DHCP servers or IPv6 capable routers using SLAAC VLANSelect is supported for Dual Stack clients Radius Accounting will include IPv4/IPv6 addressess for any Guest Access Guest configuration and management are supported on Cisco Prime Network Control System (NCS) AAA Override for ACL will be supported Cisco ASA Firewall EoIP Guest Tunnel CAPWAP Wireless Controller Corporate Intranet Isolated L2 VLAN Wired Guest Wireless Guest
IPv6 802.11 CAPWAP Tunnel Ethernet IPv4 CAPWAP 802.11 IPv6 Ethernet VLAN IPv6 IPv4 Header Version Header Length Identification Type of Services Protocol Flags Source IP Address (32 bits) Destination IP Address (32 bits) Total Length Fragment Offset Header Checksum Downstream User Traffic Version Traffic Class Payload Length Next Header Source IP Address (128 bits) IPv6 Header Flow Label Hop Limit Options Padding IPv6 Traffic Class bits (bits 4-11) in the IPv6 header is copied to the IPv4 Type of Service (bits 8-15) in the CAPWAP IPv4 header on all downstream traffic Destination IP Address (128 bits)
Kysymyksiä? IPv6 &lanne Ciscon tuo2eissa Ser$fioinnit Rei&tys Tietoturva IPSec toimipisteyhteydet Anyconnect etäyhteydet Kuormanjako/Osoitemuunnokset Kollaboraa&otuo2eet WLAN