Engineering Workshops 230 IPv6 Applications. Engineering Workshops 231 Security Considerations Sit down and think, “What do I do for IPv4?” –Go through.

Slides:



Advertisements
Similar presentations
 IPv6 Has built in security via IPsec (Internet Protocol Security). ◦ IPsec Operates at OSI layer 3 or internet layer of the Internet Protocol Suite.
Advertisements

December 5, 2007 CS-622 IPv6: The Next Generation 1 IPv6 The Next Generation Saroj Patil Nadine Sundquist Chuck Short CS622-F2007 University of Colorado,
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public ITE PC v4.0 Chapter 1 1 Addressing the Network – IPv4 Network Fundamentals – Chapter 6.
Understanding Internet Protocol
IPv6: The Next Generation Internet Protocol Luke Simpson and Martin Bouts ECE 4112 Spring 2005 May 2nd, 2005.
FIREWALLS. What is a Firewall? A firewall is hardware or software (or a combination of hardware and software) that monitors the transmission of packets.
FIREWALLS The function of a strong position is to make the forces holding it practically unassailable —On War, Carl Von Clausewitz On the day that you.
SYSTEM ADMINISTRATION Chapter 19
1 Linux Networking and Security Chapter 2. 2 Configuring Basic Networking Describe how networking devices differ from other Linux devices Configure Linux.
Nada Abdulla Ahmed.  SmoothWall Express is an open source firewall distribution based on the GNU/Linux operating system. Designed for ease of use, SmoothWall.
System Security Scanning and Discovery Chapter 14.
Unleashing the Power of Ubiquitous Connectivity with IPv6 Sandeep K. Singhal, Ph.D Director of Program Management Windows Networking.
Vulnerability Assessments with Nessus 3 Columbia Area LUG January
Vulnerability Analysis Borrowed from the CLICS group.
Linux+ Guide to Linux Certification, Second Edition Chapter 14 Network Configuration.
Open H323 Features, tools and basic utilization Liane Tarouco Leandro Bertholdo.
May 12, 2008 CS-526 IPv6: A Closer Look at Tunneling, Security, and Ubuntu 1 Saroj Patil Nadine Sundquist CS526-S2008 University of Colorado, Colorado.
Firewall 2 * Essential Network Security Book Slides. IT352 | Network Security |Najwa AlGhamdi 1.
© 2007 Cisco Systems, Inc. All rights reserved.Cisco Public 1 Version 4.0 Application Layer Functionality and Protocols Network Fundamentals – Chapter.
1 Lecture 20: Firewalls motivation ingredients –packet filters –application gateways –bastion hosts and DMZ example firewall design using firewalls – virtual.
TCP/IP Tools Lesson 5. Objectives Skills/ConceptsObjective Domain Description Objective Domain Number Using basic TCP/IP commands Understanding TCP/IP3.6.
Click to edit Master subtitle style Chapter 17: Troubleshooting Tools Instructor:
1 Chapter 6 Network Security Threats. 2 Objectives In this chapter, you will: Learn how to defend against packet sniffers Understand the TCP, UDP, and.
Course 201 – Administration, Content Inspection and SSL VPN
資 管 Lee Lesson 11 Coexistence and Migration. 資 管 Lee Lesson Objectives Coexistence and migration overview Coexistence mechanisms ◦ Dual Stack ◦ Tunneling.
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 IT Essentials PC Hardware and Software 4.1 Instructional Resource Chapter.
Module 7: Configuring TCP/IP Addressing and Name Resolution.
Hands-on Networking Fundamentals
Packet Filtering. 2 Objectives Describe packets and packet filtering Explain the approaches to packet filtering Recommend specific filtering rules.
Web Servers Web server software is a product that works with the operating system The server computer can run more than one software product such as .
Understanding IPv6 Slide: 1 Lesson 2 IPv6 Protocol for the Windows.NET Server Family.
CHAPTER 2 PCs on the Internet Suraya Alias. The TCP/IP Suite of Protocols Internet applications – client/server applications The client requested data.
Mike Meyers’ CompTIA Network+ ® Guide to Managing and Troubleshooting Networks, Third Edition (Exam N ) © 2012 The McGraw-Hill Companies, Inc. All.
Networking Security Chapter 8 powered by dj. Chapter Objectives  Explain various security threats  Monitor security in Windows Vista  Explain basic.
Network Tools TCP/IP interface configuration query - MAC (HW) address and IP address – Linux - /sbin/ifconfig – MS Windows – ipconfig/all 1.
1 How to Enable IPv6 in Your Subnet Quincy Wu March 10, 2004.
Objectives Configure routing in Windows Server 2008 Configure Routing and Remote Access Services in Windows Server 2008 Network Address Translation 1.
IPv6 Chapter 13.
Windows 7 Firewall.
CIS 450 – Network Security Chapter 3 – Information Gathering.
1 © 2004, Cisco Systems, Inc. All rights reserved. CISCO CONFIDENTIAL Using Internet Explorer 7.0 to Access Cisco Unity 5.0(1) Web Interfaces Unity 5.0(1)
Linux+ Guide to Linux Certification Chapter Fifteen Linux Networking.
Guide to TCP/IP Fourth Edition Chapter 11: Deploying IPv6.
Connecting to a Network Lesson 5. Objectives Understand the OSI Reference Model and its relationship to Windows 7 networking Install and configure networking.
IPv6 – What You Need To Know Tom Hollingsworth CCNP,CCVP,CCSP, MCSE.
Linux+ Guide to Linux Certification, Second Edition Chapter 14 Network Configuration.
1 CHAPTER 3 CLASSES OF ATTACK. 2 Denial of Service (DoS) Takes place when availability to resource is intentionally blocked or degraded Takes place when.
Day 14 Introduction to Networking. Unix Networking Unix is very frequently used as a server. –Server is a machine which “serves” some function Web Server.
Hour 7 The Application Layer 1. What Is the Application Layer? The Application layer is the top layer in TCP/IP's protocol suite Some of the components.
Engineering Workshops IPv6 and Microsoft Windows Bill Cerveny.
1 Windows 2008 Configuring Server Roles and Services.
1 Objectives Identify the basic components of a network Describe the features of Internet Protocol version 4 (IPv4) and Internet Protocol version 6 (IPv6)
Computer Networking From LANs to WANs: Hardware, Software, and Security Chapter 13 FTP and Telnet.
Topics Network topology Virtual LAN Port scanners and utilities Packet sniffers Weak protocols Practical exercise.
Networking in Linux. ♦ Introduction A computer network is defined as a number of systems that are connected to each other and exchange information across.
IPv6 Experiment Roque Gagliano The idea  To taste IPv6 by yourself today at the meeting.  30 minutes of IPv6 only content.  We have.
1 Syllabus at a glance – CMCN 6103 Introduction Introduction to Networking Network Fundamentals Number Systems Ethernet IP Addressing Subnetting ARP DNS.
Engineering Workshops Unix Hosts Rangers.ipv6.unl.edu Dale Finkelson.
1 Objectives Identify the basic components of a network Describe the features of Internet Protocol version 4 (IPv4) and Internet Protocol version 6 (IPv6)
“ is not to be used to pass on information or data. It should used only for company business!” – Memo from IBM Executive The Languages, Methods &
IPv6 Security Issues Georgios Koutepas, NTUA IPv6 Technology and Advanced Services Oct.19, 2004.
ITMT Windows 7 Configuration Chapter 5 – Connecting to a Network ITMT 1371 – Windows 7 Configuration 1.
NETWORK SECURITY LAB 1170 REHAB ALFALLAJ CT1406. Introduction There are a number of technologies that exist for the sole purpose of ensuring that the.
Chapter 7: Using Network Clients The Complete Guide To Linux System Administration.
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 3 Networking with Windows Server 2008.
Understand IPv6 Part 2 LESSON 3.3_B Networking Fundamentals.
Click to edit Master subtitle style
TCP/IP Utilities Richard Goldman May 29, 2003.
LESSON 3.3_A Networking Fundamentals Understand IPv6 Part 1.
Chapter 9 Objectives Understand TCP/IP Protocol.
Presentation transcript:

Engineering Workshops 230 IPv6 Applications

Engineering Workshops 231 Security Considerations Sit down and think, “What do I do for IPv4?” –Go through your best security practices –Create campus/department best security practices if necessary –Check off each practice for IPv6 as well as IPv4 Most Host OS implementations have IPv6 on by default Firewalls (host or router) –Do they support IPv6? –Are they on for IPv6 by default? –Mimic rules for IPv6!!! Know your services! –Scan all hosts and routers for IPv6 services –Nmap supports IPv6 – does NOT support subnet sweeps for IPv6 (approx. 28 years+ for 1 subnet)

Engineering Workshops 232 Security Considerations (continued) Check status of IPv6 support for your security tools –Use netflow9 for IPv6 flow support on Cisco –IDS/IPS support? –Firewall support? –Vulnerability scanner support? –Etc. Don’t allow mission critical areas to bring up IPv6 without audit/scan of devices by security group –Human Resources department –Credit Card depart –HIPAA, FERPA, etc.

Engineering Workshops 233 Security Considerations (continued) Watch out for router/application Access Control Lists and various IPv6 address types –IPv6 Mapped addresses can cause problems if application uses them and you don’t allow them –IPv6 Multicast groups are necessary for basic network connectivity –Routers will use link-local addresses for routing Be careful with stateless autoconfig –Hosts are “live” on the net with no administrative interaction Potential for DoS attacks using RH0 – – –RH0 may soon be deprecated, or disabled by default

Engineering Workshops 234 Security Considerations (continued) Automatic IPv6 tunneling can enable hosts to be on IPv6 network without realizing it –Can also skew traffic delay results Prevent hosts on your networks from spoofing IPv6 addresses –Use access lists –Or, on Cisco platforms that support it, use ipv6 verify unicast reverse-path –Also goes a long way toward blocking the RH0 threats IPSec inherent to IPv6 IPv6 Security Threats whitepaper -

Engineering Workshops 235 Operating Systems - Windows Windows XP – Supported since initial release –Type “ipv6 install” on XP (no service pack) –Type “ netsh interface ipv6 install ” for SP1 or SP2 or use control panel to add network protocol Advanced Networking Service Pack adds support for Teredo Web browser IPv6-enabled 6to4, ISATAP and Teredo supported

Engineering Workshops 236 Operating Systems - Windows IPv6 is on by default in Windows Vista, and will be supported across all Microsoft products eventually –Active DNS supports AAAA but not transport –Office does not support IPv6 yet –Exchange and SQL should in next versions Firewall in Windows 2003 server with SP1 supports IPv6 Firewall in Windows XP with SP2 supports IPv6 Ping, tracert, telnet, ftp, netstat and netsh commands all support IPv6 In Windows Vista, some P2P and/or collaboration tools are IPv6-only –e.g. Windows Meeting Space; see –If the two hosts communicating with these tools don't have native IPv6 connectivity, the IPv6 traffic will be encapsulated in tunnels

Engineering Workshops 237 Operating Systems – MacOS X IPv6 is enabled by default on all interfaces, and can be manually configured through the Network Preferences panel 6to4 can be configured, and will track IPv4 address changes The Security panel configures both v4 and v6 firewalls (ipfw and ip6fw)

Engineering Workshops 238 Operating Systems – MacOS X IPv6 support has been added for: – AppleShare – ssh and sshd – ftp and ftpd – Safari (uses v6 for sites without v4 addresses) – DNS queries – multicast DNS – many other system utilities (telnet, ping, traceroute, syslog, xinetd, etc.)

Engineering Workshops 239 Operating Systems - Linux – USAGI Project (WIDE) – "the Linux IPv6 Portal" Most major open source applications support IPv6 –Red Hat / Fedora enable IPv6 by default but do NOT install ip6tables by default! Debian IPv6 Developer’s List:

Engineering Workshops 240 Operating Systems - UNIX – WIDE’s FreeBSD IPv6 site wwws.sun.com/software/solaris/ipv6/ — IPv6 is standard in Solaris since version 8

Engineering Workshops 241 IPv6-ready hardware and software –Focuses mostly on routers, network equipment and operating systems at present –Includes participation by WIDE, IPv6 Forum, University of New Hampshire Interoperability Lab Presentations by Ron Broersma of DREN – speakers.php?go=people&id=1141 – jt-w07-day3-3.wmv

Engineering Workshops 242 DVTS DVTS – Digital Video Transport System A product of the WIDE Project, DVTS is openly available software which encapsulates DV video in IPv4 or IPv6 packets. Supports IPv4 and IPv6 Multicast

Engineering Workshops 243 OpenH323 Project Aims to create a full featured, interoperable, Open Source implementation of the ITU-T H.323 teleconferencing protocol that can be used by personal developers and commercial users without charge. Includes “OpenMCU” Supports IPv4 and IPv6

Engineering Workshops 244 6Voice “Basically 6Voice, means that Voice can be transmitted over IPv6 network, rather than the familiar public switched telephone network. This Package has SIP and RTP implementation.”

Engineering Workshops 245 Apache v.2 IPv6 support built-in (no patches or other modifications needed)

Engineering Workshops 246 Traffic: the NNTP Experiment IPv6 addresses show up explicitly in three configuration files: –incoming.conf - who can transfer articles to you –innfeed.conf - where you are feeding articles –readers.conf - who can read/post from your server All work the way you'd expect, and can accept either host names or IPv6 colon-formatted addresses (if you use colon-formatted raw addresses, enclose them in double quotes due to the use of colons as punctuation in the innfeed.conf file).

Engineering Workshops 247 Resources

Engineering Workshops 248 Contacts Internet2 IPv6 Working Group Workshop attendees are added to the working group mailing list automatically. Abilene NOC