Colombo, Sri Lanka, 7-10 April 2009

advertisement
FORUM ON NEXT GENERATION STANDARDIZATION
(Colombo, Sri Lanka, 7-10 April 2009)
A Pilot Implementation of an NGN Dual
Stack IPv4/IPv6 network for MEWC,
Malaysia
Prof Dr Sureswaran Ramadass,
Director, National Advanced IPv6
Centre of Excellence (NAv6),
Universiti Sains Malaysia
Colombo, Sri Lanka, 7-10 April 2009
IPv6 Pilot Project
The IPv6 Pilot Project was introduced
in accordance with the National IPv6
Council’s vision of an IPv6-enabled
Malaysia by 2010
One of the major milestones is to
ensure that government agencies are
IPv6-enabled by 2008
Colombo, Sri Lanka, 7-10 April 2009
2
IPv6 Pilot Project
Two government agencies were
chosen to initiate the Pilot project MEWC and MAMPU
The Pilot Projects will be pioneering
the deployment of IPv6 in Malaysia
Will function as reference and
guideline for IPv6 deployment and
adoption, focusing on the Malaysian
government agencies
Colombo, Sri Lanka, 7-10 April 2009
3
IPv6 Pilot Project
The IPv6 deployment was
done in a gradual manner
adopting several well
recognized transition
mechanisms
Translation
The step by step approach was
taken to ensure that the
migration would be free of any
technical glitches or security
issues
The project comprise of 4
phases
Isolated deployment
Tunneling
Expanding the
infrastructure
Dual-Stack
Production Implementation
Commercial Services
Colombo, Sri Lanka, 7-10 April 2009
4
IPv6 Pilot Project Objectives
Establish basic IPv6 capability in
network devices located at the
peering points, backbone, and
Center LAN backbones
Basic IPv6 capability is defined here as
being able to transport and route in
dual-stack (IPv4 and IPv6) mode, and
that all devices that are configured in
dual-stack mode must be able to
interoperate with each other
Colombo, Sri Lanka, 7-10 April 2009
5
Areas of Focus for the Pilot Project
Colombo, Sri Lanka, 7-10 April 2009
6
Governments agencies that uses
Putrajaya Campus Network (PCN)
Government
Agencies
Involved in
the IPv6
Pilot Project
Colombo, Sri Lanka, 7-10 April 2009
7
Pilot Project IPv6 Connectivity
Current IPv6 Connectivity for MEWC and MAMPU
Colombo, Sri Lanka, 7-10 April 2009
8
Technical view of the IPv6
connectivity USM to PCN
Logical IPv6 Network Topology for the IPv6 Pilot Project
Colombo, Sri Lanka, 7-10 April 2009
9
Servers, security & routing devices
installed at MAMPU
Snapshot of
IPv6 traffic
information
monitored
using iNetmon
Colombo, Sri Lanka, 7-10 April 2009
10
Work done by NAv6 Engineers
One of many networking
equipments being configured
during Phase-3
implementation
Colombo, Sri Lanka, 7-10 April 2009
Work done by NAv6
Engineers
11
Implementation, Phase 1
Installation of a single and isolated network,
using both dual-stack and tunneling
mechanism
Colombo, Sri Lanka, 7-10 April 2009
12
Implementation, Phase 1
Testing IPv6 connectivity to a single node via
tunneling mechanism (node installed in
PNOC)
Colombo, Sri Lanka, 7-10 April 2009
13
Implementation, Phase 2
Installation of Dual-stack tunneling for
selected virtual networks using a fixed tunnel
client
Migration
of the
PNOC to a
dual-stack
network
Colombo, Sri Lanka, 7-10 April 2009
14
Implementation, Phase 3
Implementation of a fully functioning Dual-Stack
IPv6 network at MEWC
Installation of
IPv6 Router
Colombo, Sri Lanka, 7-10 April 2009
15
Implementation, Phase 4
Post implementation study on the
IPv6 internet services in MEWC
Collective and comprehensive
information based on the network
services will be acquired
A guideline for IPv6 services migration
is to be made available to MEWC
Colombo, Sri Lanka, 7-10 April 2009
16
Problems & Challenges
Available Budget & Time
Gathering accurate information
IP addresses that only have local
significance and are not advertised
outside their local networks
Devices with hardwired addresses
Important architecture devices that
are not, and will never be, IPv6
capable (RFID time management)
Colombo, Sri Lanka, 7-10 April 2009
17
Preventive Maintenances
Maintaining the IPv6 network
Continuous access to routing devices to
maintain a reliable connectivity
Checking routing topology
Access Control List (ACL)
Checking and updating the security
network security policies on security
devices (firewalls, IDS / IPS) to
ensure security is at optimum
conditions
Colombo, Sri Lanka, 7-10 April 2009
18
Preventive Maintenances
Monitoring both IPv4 and IPv6
network activities by using network
management tools (JNetmon)
Maintaining and upgrading firmware
for better support and stability
Constantly updating and maintaining
operating systems and applications
Colombo, Sri Lanka, 7-10 April 2009
19
Thank You
Q&A
Colombo, Sri Lanka, 7-10 April 2009
20
Download