Re: IPv6 tranisition issues

Pekka Savola <[email protected]> Fri, 27 Dec 2002 14:35:34 +0200 (EET)
Newsgroups gmane.ietf.ngtrans
Message-ID <[email protected]>
Hello,

You raised very good points in your first message; I agree with the most 
of them, and have also raised them in presentations myself.

On Fri, 27 Dec 2002 [email protected] wrote:
> Thank you all for your inputs on this. The points I presented were
> summarized from one of my presentation slides on IPv6 and issues faced
> in IPv6 transition. I understand all the points presented and am fully
> behind IPv6. It is when you are proposing on a regulatory/governmental
> level, there has to be some substance to the claims and rebuttals.
> Hence, I am looking for a good academic/technical paper on the 'Great
> IPv4 vs. IPv6 Debate'.

Such a debate would probably be meaningless.

Why?

Because IPv6 does not have really many significant advantages, at least 
when you don't consider it in case-by-case basis.

Why?

Because folks want to have features provided by IPv6 in IPv4; think about 
NAT-traversal, IPSEC in UDP encapsulation, DHCP, zeroconf efforts, Mobile 
IPv4 route-optimization, etc.

Why?

Because they don't see IPv6 majorly kicking off any time in the immediate
future, so that they'd be better off switching IP versions, rather than
patch IPv4 (or rather, require patches from their vendors).

This is mostly an area where some "architectural guidance" (sometimes
stated missing in the IETF) could be useful.  Of course, such thing is 
always a double-edged sword..

(I, for one, would be interested in having some guidance e.g. when 
chartering working groups -- e.g. have zerouter, NEMO, etc. working groups 
develop *only* IPv6 solutions.)
 
> 2. QoS. Beside the obvious differences in the respective IP header
> labels, QoS implementation between the two are rather similar. In fact
> QoS flow tagging in both IPv4 (TOS) and IPv6 (Flow) are similar where an
> 8-bit label is used (although IPv6 allows for a 24-bit label) so as for
> flow tagging to operate in both environments. Both protocols will
> support MPLS tagging (TE/QoS/IP-VPN) and RSVP for QoS implementations.
> Of course the IPv6 QoS solution is more streamlined and much improved,
> but is this reason enough to switch to/develop applications/etc in IPv6 now?

Nope.
 
> 3. Multicast/Anycast. With the exception of anycast and the major
> improvement on multicast in IPv6, other advancements other than
> addressing structure/capabilities again is not a valid enough reason for
> IPv6 multicast support. Anycast is still being further developed. Areas
> that need addressing are router-processing power (for the additional
> multicast tables) and the management/set-up/operation of IGMP is complex
> amongst others.

IPv6 multicast is currently worse off than IPv4.  But more bits in an 
address could provide some advantages (e.g. simplification in the 
multicast model) -- see e.g. draft-savola-mboned-rpaddr.
 
> 4. Security. Beside the inclusion of AH and ESP at the IP level instead
> of at the higher layers, there are only slight differences between IPSec
> implementations between IPv4 and IPv6. IPSec, which is optional on IPv4,
> does not ensure an 'end-to-end' implementation unlike the mandatory
> version on IPv6. But is this realy necessary/important?

IPsec is not all that useful unless it's used, of course.

What's problematic in IPsec today is keying.  Ignoring that fact, another 
problem is caused by NAT's not passing AH/ESP protocols: this is where 
IPv6 addressing helps.  However, there is this effort going on at UDP 
encapsulation of IPsec, allowing NAT-traversal.
 
> These are some of the questions (beside the ones I highlighted) that
> need to be answered when asked 'Why now?'. Of course these IPv4 issues
> will one day need to be addressed, but not today. Perhaps in the future
> and perhaps there will be another next generation IP to solve these.

Why IPv6, indeed?

It's an architecturally better solution: end-to-end connectivity is a
property that has been partially lost and regained with hacks.

IPv6 makes this simpler, "the way it should be".

It isn't magic bullet, of course.

But really, why should *Joe Random's Organization* care?

Well, perhaps you are convinced that IPv6 or something like that will get 
off *one day*, and you want to start preparing now.  How aggressive the 
effort, depends on your belief in the timetable you believe IPv6 is 
getting usable.

Or perhaps IPv4 and issues relating to dealing with the hacks (think e.g.  
NAT-traversing application vendor's helpdesk people!) is too costly.

The real, tangible justifications do need some fleshing out, because 
that's how we can _really_ try to push IPv6 to organizations.

-- 
Pekka Savola                 "Tell me of difficulties surmounted,
Netcore Oy                   not those you stumble over and fall"
Systems. Networks. Security.  -- Robert Jordan: A Crown of Swords