agotamiento ipv4 y estrategias a futuro ale acosta

9
 Agotamiento IPv4  y estrategias a futuro  Alejand ro Acosta alejandro @ lacnic.net

Upload: saulo-95

Post on 04-Nov-2015

213 views

Category:

Documents


0 download

DESCRIPTION

Esgotamento de IPV4, Estragegia para o futuro

TRANSCRIPT

  • Agotamiento IPv4 y estrategias a futuro

    Alejandro Acostaalejandro @ lacnic.net

  • Proposed Solutions

    Network Address Translation (NAT), NAT Variations (CGN, LSN, NAT444, etc.)

    IPv6.Different types of transition mechanisms:Dualstack, 6rd, NAT64/464xlat, DS-lite, etc.

  • Network Address Translation (NAT)

    It allow several devices to share the same public IP.

    Its not a sustainable solution.

  • NAT Variations

    Carrier Grade NAT (CGN)

    Large Scale NAT (LSN)

    NAT 444

  • Internet Architecturewith NATs

    - More complex Client-server model- Highfault rate- P2P -> almost impossible

    CGN

  • Problems of NAT When sharing the same Ipv4 address, the communication

    model peer to peer is altered.

    ACLs (Access ControlLists) to avoid certain attacks have important colateral effects

    When traffic from a bad customer is blocked, traffic from multiple good customers is also blocked

    In order to identify who accessed a service, not only the IP address should be saved but also the port

  • Problems ofNAT NAT boxes have limitations related to the number of

    sessions

    Customers from different countries browse the Internet through the same IP address

    Country specific web pages (Google, Twitter) will think we are in a different country

    Twitter has country specific policy

    Geolocationapps will show a wrong location

  • Problems ofNAT

    Port forwarding will become more difficult

    Users are behind a NAT they dont control

    Issues with games (consoles and network games rely on incoming connections).

    Cost: about 40 USD per user approximatelysource:https://www.nanog.org/meetings/nanog56/presentations/Wednesday/wed.general.howard.24.pdf

  • Conclusion

    NAT is a temporary solution

    IPv6 is a long term solution!!