Re: IPV4 to IPv6 migration
Jeroen Massar <jeroen-LqLoW1FB7k/[email protected]> Sun, 01 Jun 2008 10:36:43 +0200
| Newsgroups | gmane.org.apnic.global-v6 |
|---|---|
| Organization | Unfix |
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--===============0287842878==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature";
boundary="------------enigF0A353D7BF1F6937FB9BA5B6"
This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enigF0A353D7BF1F6937FB9BA5B6
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: quoted-printable
sapumal jayatissa wrote:
> Hi,
> In migration to IPv6 in large scale organization, can we use private=20
> IPv6 addresses ?
You could, but it is most likely much better to avoid any use of=20
'private' (I do hope you mean ULA here) addresses.
> Or do we need to use Global addresses for all the nodes which may never=
=20
> access Internet ?
Using Global Addresses is generally the smarter thing to do:
a) one will have plenty of addresses anyway
b) one day, a device will have to talk to the public Internet
Especially because of b) and because of things like Path MTU, you will=20
require a public address in most places.
> Can we use proxy servers with IPv6 ?
If you want, of course. But, it does break the end-end idea and when you =
are proxying you can also stick to IPv4 and just upgrade the proxy to do =
IPv6.
> If we NAT, then we have to NAT in between global routable to global=20
> routable,
> only to hide the real IP address, Is this o.k ?
You *NEVER EVER EVER EVER* NAT in IPv6.
Please read RFC4864 ("Local Network Protection for IPv6") for a lot more =
information about this and how to solve the problems you might have.
If you even are going to remotely think of using NAT, just stick with=20
IPv4 as that works fine for you and you don't have to upgrade anything.
If you really want to 'hide' real IP addresses there is one solution=20
that you should be using: don't connect to the Internet, but allow=20
people to only to use a proxy to use services on the Internet. You are=20
then of course not talking about Internet connectivity anymore.
Do note that due the use of RFC3041 ("Privacy Extensions for Stateless=20
Address Autoconfiguration in IPv6") addresses will change rapidly=20
anyway, thus it will be quite difficult for hosts outside to determine=20
how many people/addresses/hosts are inside. Unfortunately for you though =
the concept of 'cookies' will break this where webservers will have a=20
lot of other means of tracking people&hosts.
Greets,
Jeroen
--------------enigF0A353D7BF1F6937FB9BA5B6
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (MingW32)
iD8DBQFIQl+hKaooUjM+fCMRArq+AKCCq10YgbJbm/56B8ESGVHsoMUm3wCbBBZM
pp30Cro9PQmu3GVSX4DeKT0=
=k3RD
-----END PGP SIGNATURE-----
--------------enigF0A353D7BF1F6937FB9BA5B6--
--===============0287842878==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
global-v6 mailing list
[email protected]
http://mailman.apnic.net/mailman/listinfo/global-v6
--===============0287842878==--