ietf92-v6ops@dallas jpne map-e deployment · have session table 464xlat ds-lite map-e map-t. ... 2...

28
240b::1 Copyright(C) JPNE, All Rights Reserved. 240b::1 IETF92-v6ops@Dallas JPNE MAP-E Deployment Mar.25.2015 Japan Network Enabler (JPNE) Akira Nakagawa

Upload: phamdan

Post on 14-Apr-2018

216 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::1Copyright(C) JPNE, All Rights Reserved. 240b::1

IETF92-v6ops@Dallas

JPNE MAP-E Deployment

日本ネットワークイネイブラー株式会社(JPNE)

中川あきら

Mar.25.2015

Japan Network Enabler (JPNE)

Akira Nakagawa

Page 2: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::2Copyright(C) JPNE, All Rights Reserved. 240b::2

Agenda

1. IPv6 Deployment Status in Japan

2. IPv6 Deployment Status of JPNE

3.Our Experiences

Page 3: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::3Copyright(C) JPNE, All Rights Reserved. 240b::3

IPv6 history in Japan at a glance

Dawn Business

2001-2010 2011-

•NTT-East/West enabled IPv6 on Access NW(NGN).

•ISPs WITHOUT Access NW can start IPv6.

•ISPs WITH Access NW also started IPv6

NTT-East/West Started IPv6

R&D

•Commercial or Trial Service by leading Companies

Page 4: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::4Copyright(C) JPNE, All Rights Reserved. 240b::4

Japanese position (Observed by Akamai)

Country-base measurement.Japanese IPv6 rate is 5.5%. as of

Feb.28.2015

state of Internethttp://www.stateoftheinternet.com/trends-visualizations-ipv6-adoption-ipv4-exhaustion-global-heat-map-network-country-growth-data.html

Page 5: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::5Copyright(C) JPNE, All Rights Reserved. 240b::5

IPv6 Network operator measurements

Network(AS)-base measurement

World IPv6 Launch http://www.worldipv6launch.org/measurements/

Japanese:No.3 KDDINo.13 CTCNo.14 SoftBank BBNo.24 STNetNo.37 iTSCOM

(as of Feb. 28 2015)

Page 6: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::6Copyright(C) JPNE, All Rights Reserved. 240b::6

NAT444CGN

NW Providers in Japan

Divided into Four.

NTT-East/West with ISPs are the majority.

NTT-East/West

(NGN:Next Generation Network)

ISPs

KDDI,CTC,etc

Subsidiaries of Power

Company

CATVs

BackboneNetwork

AccessNetwork

Share of FTTH:77%(East)65%(West)(*1)

Internet

(*1)http://www.ictr.co.jp/report/20140704000064.html

Page 7: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::7Copyright(C) JPNE, All Rights Reserved. 240b::7

IPv6 Deployment rate of NGN (NTT-East/West)

IPv6 User(K)

IPv6Deployment

IPv6 Promotion Councilhttp://v6pc.jp/jp/spread/ipv6spread_03.phtml

Page 8: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::8Copyright(C) JPNE, All Rights Reserved. 240b::8

IPv6 Deployment rate of KDDI and CTC

IPv6Deployment

IPv6 Promotion Councilhttp://v6pc.jp/jp/spread/ipv6spread_03.phtml

Completed

KDDI (au Hikari)

CTC (Commufa Hikari)

Page 9: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::9Copyright(C) JPNE, All Rights Reserved. 240b::9

IPv6 Transition status in Japan

Providers started Dual Stack.

Different method depending on their present NW and strategy.

NTT-EastNEE-West

OCNso-net

etc.

JPNEMulti-feed

JPIX(Trial)

v4/v6 on PPPoE

MAP-E DS-Lite

AnyProvider

464XLAT

BBIX

KDDI

DualStack

v6 + v4 Tunnel

Page 10: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::10Copyright(C) JPNE, All Rights Reserved. 240b::10

Recent Outstanding Progress in Japan

Maker/CompanyTransition technology

Consumer/Enterprise

Released date orDate started to use

transition function in JP

NEC PlatformsWG1810HP

MAP-E464XLAT

ConsumerFeb. 2015

(not on sale yet)

NEC PlatformsRG-G200LV(*1) DS-Lite Consumer

Feb. 2015(not on sale yet)

BuffaloWXR-1900DHP

MAP-EDS-Lite

Consumer Oct. 2014

Huawei WS325 DS-Lite Consumer Oct. 2014

Cisco 1812J DS-Lite Enterprise Oct. 2014

IIJ SEIL DS-Lite Enterprise Oct. 2014

YAMAHA NVR500 DS-Lite So-Ho Oct. 2014

NTT-East/West MAP-E(*2) Consumer Apr. 2013

Some Makers released IPv6 transition functions for Home/Enterprise Routers.

(*2)Home Router doesn’t have MAP-E function, needed to use Flets JOINT(*1) for export only

Page 11: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::11Copyright(C) JPNE, All Rights Reserved. 240b::11

Agenda

1. IPv6 Deployment Status in Japan

2. IPv6 Deployment Status of JPNE

3.Our Experiences

Page 12: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::12Copyright(C) JPNE, All Rights Reserved. 240b::12

Some ways of IPv6 Transition

Network operators can choose the best one according to their strategy.

Translation•Enables Traffic Engineering without DPI.

Tunnel

Stateful at center(NAT64/CGN)•Enables small start•Number of user port is changable.

Stateless at center•No logging•No session management•Center node scales because it doesn’t have session table

464XLAT

MAP-EDS-Lite

MAP-T

Page 13: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::13Copyright(C) JPNE, All Rights Reserved. 240b::13

IPv4Internet

IPv6Internet

What is MAP-E ?

IPv6

Home Router

BR

IPv4 IPv6 BR : Border Relay

IPv4 over IPv6

IPv4

IPv4

IPv6

•Terminates Tunnel•IPv4 NAT

•Terminates Tunnel•IPv4 Address Sharing•Stateless (no CGN)•no Logging Server

Page 14: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::14Copyright(C) JPNE, All Rights Reserved. 240b::14

MAP-E in our Network

IPv4Internet

IPv6Internet

BR

BR : Border RelaySPI : Stateful Packet Inspection

IPv4 over IPv6

IPv4 over IPv6

Home Router(v4NAT/v6SPI)

IPv6

IPv6

DNS cache

IPv6

Home Router(v4NAT/v6SPI)

Stateless,(not CGN)

IPv6

Page 15: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::15Copyright(C) JPNE, All Rights Reserved. 240b::15

Why MAP-E for JPNE ?

Easy Operation

no Logging (deferent from CGN)

no session management

Center node scales according to only traffic, not number of users.

Easy Customer Support

no Configuration at Home Router

Avoiding traffic from Center Node

Direct communication between users

Page 16: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::16Copyright(C) JPNE, All Rights Reserved. 240b::16

Why MAP-E for Users ?

Users don’t care MAP-E, IPv6, IPv4…

Like Air

Page 17: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::17Copyright(C) JPNE, All Rights Reserved. 240b::17

Our Final Goal

v4 Sunsetv6Internet

v4Internet

JPNE)

IPv4over

IPv6offloading IPv6

Final Goal

Steps

1. Overlaying IPv4 on IPv6.

2. Offloading traffic to simple IPv6.

3. Removing overplayed IPv4.

Now

Page 18: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::18Copyright(C) JPNE, All Rights Reserved. 240b::18

Agenda

1. IPv6 Deployment Status in Japan

2. IPv6 Deployment Status of JPNE

3.Our Experiences

Page 19: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::19Copyright(C) JPNE, All Rights Reserved. 240b::19

Speed Test via Internet

NOT special environment.

down

1st 2nd 3rd

IPv4(MAP-E)

800 799 814

823 817 810

820 818 807

Ave. 814 811 810

IPv6

814 768 814

845 501 751

860 748 792

Ave. 840 672 786

(Mbps)

Cerulean Hotelin Tokyo (Dec.3.2014)

PC

Home Router

TemporalEvent NW

Speed Test Site

IPv6: IIJmiohttp://speedtest6.iijmio.jp/

IPv4: Radish Network Speed Testinghttp://netspeed.studio-radish.com/

Ethernet

Page 20: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::20Copyright(C) JPNE, All Rights Reserved. 240b::20

Enough Ports per user

Number of port per user is fixed in MAP-E.

We tried over-subscribing test before designing our MAP-E NW.

We assigned enough ports per user.

9:22

9:24

9:26

9:28

9:30

9:32

9:34

9:36

9:38

9:40

9:42

9:44

9:46

9:48

9:50

9:52

9:54

9:56

9:58

10:…

10:…

10:…

10:…

10:…

10:…

10:…

10:…

10:…

10:…

10:…

10:…

10:…

Enough portsper end-user

Used ports during the test

Number of Port / user

Page 21: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::21Copyright(C) JPNE, All Rights Reserved. 240b::21

IPv6/IPv4 Trouble shooting

Test1:IPv4 Internet IP reachabilityTest2:IPv4 Internet with Name resolution (*)Test3:IPv6 Internet IP reachabilityTest4:IPv6 Internet with Name resolution (*)Test5:IPv6 Backbone IP reachabilityTest6:IPv6 Backbone with Name resolution (*)

Test1,2We simplified trouble shooting by tool. (see next page)

DNS(*)

IPv4Internet

IPv6 Internet

Test5,6

Test3,4

v4

v6

v6

Page 22: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::22Copyright(C) JPNE, All Rights Reserved. 240b::22

IPv6/IPv4 Trouble Shoot Tool

Test1

Test2

Test3

Start

IPv4/IPv6 Trouble shooting

Your are accessingby IPv6

Measuring

Page 23: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::23Copyright(C) JPNE, All Rights Reserved. 240b::23

Abuse Issue

Content / Server

ISP

Very important to do both.

(1)Taking Log of port number at Server, Firewall, etc.

(2)Off-loading traffic to IPv6 for increasing the possibility of identifing the sender.

IPv4AddressSharing

Same IP

F/W・L/B etc.

Page 24: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::24Copyright(C) JPNE, All Rights Reserved. 240b::24

Traffic growth

Traffic growth indicates number of MAP-E Users are increasing.

bps

201405

201406

201407

201408

201409

201410

201411

201412

201501

201502

Page 25: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::25Copyright(C) JPNE, All Rights Reserved. 240b::25

Destination based traffic

bps

Most of IPv6 traffic is Google.

Page 26: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::26Copyright(C) JPNE, All Rights Reserved. 240b::26

IPv6 Traffic Ratio

20% of Internet traffic is IPv6. Gradually increasing.

201405

201406

201407

201408

201409

201410

201411

201412

201501

201502

Page 27: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::27Copyright(C) JPNE, All Rights Reserved. 240b::27

Summary

Japanese IPv6 users and traffic are increasing.

Japanese NW providers have introduced variety of IPv6 transition technology.

MAP-E is Stable, Easy operation, Easy Customer support, speed is fast enough.

Important to take logging of port at Server, Firewall, Load Balancer, etc.

One important thing is to offload traffic to IPv6.

Page 28: IETF92-v6ops@Dallas JPNE MAP-E Deployment · have session table 464XLAT DS-Lite MAP-E MAP-T. ... 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 ... Internet Society @ APRICOT 2015 Session Created

240b::28Copyright(C) JPNE, All Rights Reserved. 240b::28

http://jpne.co.jp