SAVI Requirements and Solutions for ISP IPv6 Access Network ISP-access-01.txt.

Slides:



Advertisements
Similar presentations
A CGA based Source Address Authentication Method in IPv6 Access Network(CSA) Guang Yao, Jun Bi and Pingping Lin Tsinghua University APAN26 Queenstown,
Advertisements

Security Issues In Mobile IP
Akihiro Tanabe, Daisuke Andou, Kaori Izutsu, Tsunemasa Hayashi and Hiroshi Tohjo NTT Access Network Service Systems Laboratories {atanabe, dandou,
Automatic Configuration of IP Networks and Routers Kenji Hori, Kiyohito Yoshihara, and Hiroki Horiuchi KDDI R&D Laboratories Inc Ohara Kamifukuoka-Shi.
© 2006 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 IPv6 via IPv4 SP Networks - 6rd draft-townsley-ipv6-6rd-01.txt (also.
IETF 80 th Problem Statement for Operational IPv6/IPv4 Co-existence 3/31/2011 Chongfeng Xie Qiong Sun
On demand IPv4 address provisioning in Dual-Stack PPP deployment scenarios. Karsten Fleischhauer, Fixed Mobile Engineering Germany Olaf Bonneß, T-Labs.
Everything.
Source Address Selection in Multi-Prefix Multi-Service Network Arifumi Matsumoto NTT PF Lab.
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
URP Usage Scenarios for NAS Yoshihiro Ohba August 2001 Toshiba America Research, Inc.
User Network Interface - auto-configuration mechanism -
Application Guide For Mesh AP – MAP-3120
IP over ETH over IEEE draft-riegel-16ng-ip-over-eth-over Max Riegel
Page 1 / 14 The Mesh Comparison PLANET’s Layer 3 MAP products v.s. 3 rd ’s Layer 2 Mesh.
1 Basic Installation and GUI Tech Basic Installation and GUI : Objectives  Installing the Quadro  Configuring the Quadro  Installing IP phones.
Omniran GPP Trusted WLAN Access to EPC Use Case Analysis Date: Authors: NameAffiliationPhone Max RiegelNSN
11 TROUBLESHOOTING Chapter 12. Chapter 12: TROUBLESHOOTING2 OVERVIEW  Determine whether a network communications problem is related to TCP/IP.  Understand.
IPv6 Address Provisioning In IPv6 world there are three provisioning aspects wich are independent of whether the IPv6 node is a Host or CE router: IPv6.
Wireless and Switch Security NETS David Mitchell.
History DHCP was first defined as a standards track protocol in RFC 1531 in October 1993, as an extension to the Bootstrap Protocol (BOOTP). The motivation.
Presented by Serge Kpan LTEC Network Systems Administration 1.
Linux+ Guide to Linux Certification, Second Edition Chapter 14 Network Configuration.
Wi-Fi Structures.
Network Address Translation, Remote Access and Virtual Private Networks BSAD 146 Dave Novak Sources: Network+ Guide to Networks, Dean 2013.
1 IPv6 in CableLabs DOCSIS 3.0 IETF v6ops wg meeting IETF#65 Ralph Droms Alain Durand
TCP/IP Addressing Design. Objectives Choose an appropriate IP addressing scheme based on business and technical requirements Identify IP addressing problems.
Networking Components Chad Benedict – LTEC
NetComm Wireless Transparent Bridge Mode Feature Spotlight.
Guoliang YANG Problem Statement of China Telecom.
Installation of Set Top Box (STB) Model: S-Box7203
Omniran OmniRAN Wi-Fi Hotspot Roaming Use Case Date: Authors: NameAffiliationPhone Max RiegelNSN
NETWORKING COMPONENTS Zach Avis. Hub A hub is a low cost way to connect two computers. A hub can also act as a repeater. When a signal comes from one.
1 Chapter 6 Network Security Threats. 2 Objectives In this chapter, you will: Learn how to defend against packet sniffers Understand the TCP, UDP, and.
CECS 5460 – Assignment 3 Stacey VanderHeiden Güney.
Windows Internet Connection Sharing Dave Eitelbach Program Manager Networking And Communications Microsoft Corporation.
Network Components 101 Travis Hill.
Chapter 4. After completion of this chapter, you should be able to: Explain “what is the Internet? And how we connect to the Internet using an ISP. Explain.
Cisco 1 - Networking Basics Perrine. J Page 19/17/2015 Chapter 9 What transport layer protocol does TFTP use? 1.TCP 2.IP 3.UDP 4.CFTP.
Altai Certification Training Backend Network Planning
Common Devices Used In Computer Networks
Access Protocols PPP vs. DHCP Chapter 5. Overview PPP DHCP User identities Assignment of IP addresses Assignment of other parameters.
DHCP Security DHCP Snooping and Security David Mitchell 03/19/2008.
DHCPv6 Route Option (draft-dec-dhcpv6-route-option-03.txt) IETF 77, March 2010 : Wojciech Dec Richard Johnson
VIRTUAL PRIVATE NETWORK By: Tammy Be Khoa Kieu Stephen Tran Michael Tse.
Linux+ Guide to Linux Certification, Second Edition Chapter 14 Network Configuration.
NETWORKING COMPONENTS AN OVERVIEW OF COMMONLY USED HARDWARE Christopher Johnson LTEC 4550.
3Com Confidential Proprietary 3G CDMA AAA Function Yingchun Xu 3COM.
NETWORK COMPONENTS Assignment #3. Hub A hub is used in a wired network to connect Ethernet cables from a number of devices together. The hub allows each.
RADIUS issues in IPv6 deployments draft-hu-v6ops-radius-issues-ipv6-01 J. Hu, YL. Ouyang, Q. Wang, J. Qin,
The Intranet.
輔大資工所 在職研一 報告人:林煥銘 學號: Public Access Mobility LAN: Extending The Wireless Internet into The LAN Environment Jun Li, Stephen B. Weinstein, Junbiao.
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Connecting to the Network Introduction to Networking Concepts.
Chapter 6: Securing the Local Area Network
Networking Components William Isakson LTEC 4550 October 7, 2012 Module 3.
(ITI310) By Eng. BASSEM ALSAID SESSIONS 9: Dynamic Host Configuration Protocol (DHCP)
 Router Configurations part2 2 nd semester
IETF66 PANA WG Problem Statement for a time-basis accounting in an "always-on“ Broadband scenario R. Maglione - Telecom Italia
IPv6 Security Issues Georgios Koutepas, NTUA IPv6 Technology and Advanced Services Oct.19, 2004.
© 2015 Infoblox Inc. All Rights Reserved. Tom Coffeen, IPv6 Evangelist UKNOF January 2015 Tom Coffeen, IPv6 Evangelist UKNOF January 2015 DHCPv6 Operational.
Windows Vista Configuration MCTS : Advanced Networking.
Real Exam Questions Answers
How to pass Cisco Exam in first attempt?
2018 Huawei H Real Questions Killtest
PPPoE Internet Point to Point Protocol over Ethernet
Mobile IP Outline Homework #4 Solutions Intro to mobile IP Operation
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
SAVI Requirements and Solutions for IPv4/IPv6 Transition
Mobile IP Outline Intro to mobile IP Operation Problems with mobility.
Presentation transcript:

SAVI Requirements and Solutions for ISP IPv6 Access Network ISP-access-01.txt

Abstract The Source Address Validation Improvement (SAVI) was developed to prevent IP source address spoofing which can enable impersonation and malicious traffic redirection. An Internet Service Provider (ISP) who provides Internet access services, information services and value-added services to the customers should guarantee security of its network and customers' privacy. Thus, the mechanism is essential for ISPs. However, due to a diversity of ISPs' access network, SAVI solution is also different accordingly. This document describes five scenarios of ISPs' IPv6 access network, moreover, states its SAVI requirements and according tentative solutions. These scenarios will cover the most of the Internet access scenes in China Telecom. And maybe the reference to other ISPs.

Current Network Situation Spoofing issue becomes more critical IPv4 exhaustion Transition is a long period SAVI only works in IPv6 Ethernet subnet with DHPC now. Spoofable netblocks, IP addresses and AS From MIT spoofer project IPv4 Address Resources From

Scenario 1: Home gateway act as DHCPv6 proxy BRAS PPP ND DHCPv6 DHCP General Scene Workflow 1. HG get a link-local IPv6 address from BRAS via PPPOE and ND RA. It is the WAN IP address of the HG. 2. HG get IPv6 prefix from BRAS via DHCPv6-PD. It is the Prefix for the ones access to the HG, here are PC and STB. 3. PC or STB device get IPv6 prefix via DHCPv6-PD. Note: Of course PC and STB can also get IPv6 address via ND/RA, but the DHCPv6 is much popular. General Scene Workflow 1. HG get a link-local IPv6 address from BRAS via PPPOE and ND RA. It is the WAN IP address of the HG. 2. HG get IPv6 prefix from BRAS via DHCPv6-PD. It is the Prefix for the ones access to the HG, here are PC and STB. 3. PC or STB device get IPv6 prefix via DHCPv6-PD. Note: Of course PC and STB can also get IPv6 address via ND/RA, but the DHCPv6 is much popular. SAVI Solution: 1. Deploy SAVI device to position of near HG 2.SAVI mechanism needs to improve to snoop the procedure of DHCPv6-PD so as to bind the relationship.---Its new one? SAVI Solution: 1. Deploy SAVI device to position of near HG 2.SAVI mechanism needs to improve to snoop the procedure of DHCPv6-PD so as to bind the relationship.---Its new one? Note: BRAS: Broadband Remote Access Server HG: Home Gateway. Here HG is L3 router. STB: Set Top-box Note: BRAS: Broadband Remote Access Server HG: Home Gateway. Here HG is L3 router. STB: Set Top-box

Scenario 2: STB gets IP address via DHCPv6 12 General Scene Workflow STB which has internal account and password gets IPv6 prefix by DHCPv6. 1. STB send request to all routers on local link by using link-local address based on its MAC address. 2. The BRAS informs STB to adopt DHCPv6 address assignment method as a response. 3. STB initiate DHCPv6 procedure and BRAS act as a DHCP Relay to add some authorities' messages. 4. AAA server decides whether assign address parameters according to the result of authentication. BRAS receives IPv6 parameters from AAA server, and then, informs STB by DHCPv6. Note: There also maybe HG between STB and BRAS, but used as L2 bridge only. General Scene Workflow STB which has internal account and password gets IPv6 prefix by DHCPv6. 1. STB send request to all routers on local link by using link-local address based on its MAC address. 2. The BRAS informs STB to adopt DHCPv6 address assignment method as a response. 3. STB initiate DHCPv6 procedure and BRAS act as a DHCP Relay to add some authorities' messages. 4. AAA server decides whether assign address parameters according to the result of authentication. BRAS receives IPv6 parameters from AAA server, and then, informs STB by DHCPv6. Note: There also maybe HG between STB and BRAS, but used as L2 bridge only. SAVI Solution: 1. Deploy SAVI device to position of near STB 2. It just needs to bind relationship which is included in existing function. SAVI Solution: 1. Deploy SAVI device to position of near STB 2. It just needs to bind relationship which is included in existing function. BRAS DHCP DHCPv6 AAA DHCP Server

Scenario 3: PC gets IP address via PPPoE & RA General Scene Workflow 1. PC get link-local address via PPPoE. 2. BRAS broadcast IP prefix via RA 3. PC automatically configuration General Scene Workflow 1. PC get link-local address via PPPoE. 2. BRAS broadcast IP prefix via RA 3. PC automatically configuration SAVI Solution: 1. Deploy SAVI device to position of near PC 2. It is also need to improve its mechanism in order to enable PPPoE snooping like scenario 1 and binding relationship SAVI Solution: 1. Deploy SAVI device to position of near PC 2. It is also need to improve its mechanism in order to enable PPPoE snooping like scenario 1 and binding relationship BRAS ND AAA PPP

BRAS DHCP DHCPv6 AAA Laptop DHCP Server Scenario 4: Laptop accesses Internet via WLAN General Scene Workflow 1. Laptop get IPv6 address via DHCPv6. 2. Users were enforced to be certified by submitting password on a portal page. General Scene Workflow 1. Laptop get IPv6 address via DHCPv6. 2. Users were enforced to be certified by submitting password on a portal page. SAVI Solution: 1. Deploy SAVI switch to position of near laptop. 2. It just needs to bind relationship <LAPTOP's IP Address, port, LAPTOP's MAC> which is included in existing function. SAVI Solution: 1. Deploy SAVI switch to position of near laptop. 2. It just needs to bind relationship <LAPTOP's IP Address, port, LAPTOP's MAC> which is included in existing function.

BRAS DHCPv 6 AAA Lapto p PDSN WAG AN-AAA PPP DHCP NDND Scenario 5: Laptop accesses Internet via C+W SAVI Solution: 1. Deploy SAVI switch to position of near PC 2. It is also need to improve its mechanism in order to enable PPPoE snooping like scenario 1 and binding relationship. SAVI Solution: 1. Deploy SAVI switch to position of near PC 2. It is also need to improve its mechanism in order to enable PPPoE snooping like scenario 1 and binding relationship. General Scene Workflow 1. Laptop get a temporary IPv6 address from BRAS via DHCPv6. 2. Laptop obtains the WAG address from DNS server. The laptop establishes a UDP tunnel to WAG by sending register request. 3. If the tunnel established successfully, the laptop can get IPv6 prefix from PDSN via PPP and RA, whereas PDSN acts as the PPP terminal. 4. At last, the laptop gets some additional information such as DNS address. When the above steps all accomplished, the laptop acquires the ability to access Internet. General Scene Workflow 1. Laptop get a temporary IPv6 address from BRAS via DHCPv6. 2. Laptop obtains the WAG address from DNS server. The laptop establishes a UDP tunnel to WAG by sending register request. 3. If the tunnel established successfully, the laptop can get IPv6 prefix from PDSN via PPP and RA, whereas PDSN acts as the PPP terminal. 4. At last, the laptop gets some additional information such as DNS address. When the above steps all accomplished, the laptop acquires the ability to access Internet. Note: WAG: Wireless Access Gateway PDSN: Packet Data Serving Node AN-AAA: Access Network Authentication, Authorization and Accounting Server Note: WAG: Wireless Access Gateway PDSN: Packet Data Serving Node AN-AAA: Access Network Authentication, Authorization and Accounting Server

Conclusion There are various scenarios of ISPs'IPv6 Access Network. Because each scenario uses different address assignment method and protocol, there are a variety of requirements to validate source address for ISPs' IPv6 access network. SAVI cannot support all protocols and methods right now, but, due to expansibility of SAVI, the mechanism can satisfy these various demands with a little improvement. This document presents five typical scenarios of ISPs'IPv6 access network, and proposes tentative SAVI solutions including some improvement.

End Thanks! Authors' Addresses Fan Shi China Telecom Ke Xu Tsinghua University Liang Zhu Tsinghua University Guangwu Hu Tsinghua University