IPv6 時代の を考える ~DS-Lite 8 th July 2010 鹿志村康生 (Yasuo Kashimura) yasuo.kashimura@alcatel-lucent.com
DS-Lite ( Dual stack Lite) draft-ietf-softwire-dual-stack-lite Dual-Stack Lite Broadband Deployments Following Exhaustion IPv6 only Access 上で パケットを IPv6でTunnel(-in-IPv6) => Management cost 削減 Concentrator 上で - NAPT を提供 Continuity IPv6 Migration => 複数の Userで Global Address を共用することによる Address 節約 private -in-ipv6 IPv6-only BNG IPv6 only Access DS-Lite Concentrator (AFTR) IPv6 Dual-stack Core global Internet IPv6 Internet 2 JANOG26 July 2010 Copyright 2010 Alcatel-Lucent. All rights reserved.
DS-Lite Component と機能 AFTR(Address Family Transition Router) Function in IPv6 tunnel Termination - NAPT 基本的な NAPT に関する Requirement は LSN に準ずる NAT Behavioral Requirements for TCP/UDP/ICMP, etc.. SubscriberのIPv6 source addressをsubscriber identification として使用 Inside addressはlookup の際に気にしない CPE(Home router) Function No NAT on CPE in IPv6 encapsulation DNS proxy : Host---(DNS)--->CPE---(IPv6DNS)--->ISP sdns-server #CPEはconcentratorのIPv6 アドレスを知っておく必要がある Out-of-band/Manual/via DHCPv6 (draft-ietf-softwire-ds-lite-tunnel-option) 3 JANOG26 July 2010 Copyright 2010 Alcatel-Lucent. All rights reserved.
DS-Lite Packet Flow Priv. RFC1918, 192.0.0.0/29 Tunnel Routing -in-ipv6 tunneled Tunnel IPV4 Global DS-Lite AFTR IPv6 Dst-=198.51.100.1 Src-=192.168.0.2 Src-port=10000 Dst-IPv6=2001:db8:20::2 Src-IPv6=2001:db8:10::2 Dst-=198.51.100.0 Src-=192.168.0.2 Src-port=10000 Decap v4napt Softwire-ID Inside IP Prot Inside Src Port Dst-=198.51.100.0 Src-=192.0.2.1 Src-port=20000 Outside IP Prot Outside SrcPort 2001:db8:10::2 192.168.0.2 TCP 10000 192.0.2.1 TCP 20000 Server 4 JANOG26 July 2010 Copyright 2010 Alcatel-Lucent. All rights reserved.
DS-Lite + A+P draft-ietf-softwire-dual-stack-lite draft-ymbk-aplusp The A+P Approach to the Address Shortage IPv6 only Access 上で パケットを IPv6でTunnel(-in-IPv6) CPEがGlobal address/port-range を学習 CPE 上で - NAPT NAT 機能を CPE 側へ Distribute できるためより Scalable Minimal state core More Flexible, more close to End-to-End transparency (but still limited) Continuity private A+P NAT A+P NAT -in-ipv6 IPv6-only BNG AFTR/ A+P router global Internet IPv6 Migration A+P NAT IPv6 only Access IPv6 Dual-stack Core IPv6 Internet 5 JANOG26 July 2010 Copyright 2010 Alcatel-Lucent. All rights reserved.
DS-Lite + A+P Packet Flow Priv. RFC1918, 192.0.0.0/29 Tunnel -in-ipv6 tunneled Tunnel Routing IPV4 Global DS-Lite A+P Assigned port-range IP=12.0.0.3 Port=10000-11000 Server Decap IPv6 Dst-=128.0.0.1 Src-=10.0.0.2 Src-port=8000 Dst-IPv6= a::1 Src-IPv6= a::2 Dst-=128.0.0.1 Src-=12.0.0.3 Src-port=10000 Dst-=128.0.0.1 Src-=12.0.0.3 Src-port=10000 6 JANOG26 July 2010 Copyright 2010 Alcatel-Lucent. All rights reserved.
DS-Lite deployment consideration (1) - CPE への機能追加要 - NAT に関する Policy をどう考えるか - 加入者管理 /Per-Subscriber-Control? Subscriber 毎の QoS/NAT policy control 等 A+P での Address/port-range 情報配布 User の識別 認証? - End-to-End Transparency. A+P? UpNP draft-wing-softwire-port-control-protocol draft-bpw-softwire-pcp-dhcp-01 draft-bpw-softwire-upnp-pcp-interworking 7 JANOG26 July 2010 Copyright 2010 Alcatel-Lucent. All rights reserved.
DS-Lite deployment consideration (2) - 機能配置 Central Site に配置して集約 Edge 方面に分散配置 スケーラビリティ パラメータにも影響 Tunnel 数 NAT session 数 パフォーマンス etc HA 要件をどこまで求めるか 移行フェーズをどう考えるか Edge に配置 = Dual-stack ドメインは減らない Bottle-neck となり得るポイントがどこにあるか DS-Lite : AFTR DS-Lite + A+P : CPE 8 JANOG26 July 2010 Copyright 2010 Alcatel-Lucent. All rights reserved.
Edge 方向への機能分散の 1 方法 :L2-aware NAT IPoE Internet PPPoE L2TP BNG+ 7750-SR IPv6 Internet L2Access Continuity Priv. Shared Priv. Public ROUTED draft-miles-behave-l2nat(expired) DS-Lite の考え方を L2 session に拡張 違いは Access 網は L2 L3-EdgeにNAT 機能を実装 L2 session ID(IPoE/PPPoE/L2TP) をSubscriber ID として使用する CPEに に関する追加機能不要 9 JANOG26 July 2010 Copyright 2010 Alcatel-Lucent. All rights reserved.
Applicability の拡張 : GI(Gateway Initiated)-DS-Lite AD (access device) AD (access device) Access tunnel BNG+ GI-DS-Lite GW TID-1 CID-1 CID / / Port CID-1 / a.b.c.d / tcp 10000 GRE/MPLS/IPinIP or IPv6 Public / port e.f.g.h / tcp 20000 CID-2 / a.b.c.d / tcp 11000 e.f.g.h / tcp 21000 Internet enb GTP SGW GTP TID-2 CID-2 GRE/MPLS/IPinIP PGW+ GI-DS-Lite GW AFTR IPv6 Internet Access Priv. draft-ietf-softwire-gateway-init-ds-lite Tunnel Switching Priv. Public ROUTED DS-Lite をベースに様々な Access Architecture への Applicability の拡張 PPP/1:1VLAN/MIP/PMIP/GTP 等 Mobile 含む様々な Architecture に対応 GI-DS-Lite Gateway から AFTRへTunnel(GRE or MPLS or IPinIP) を張る Access Device に機能追加は不要 GRE 使用の場合には Access Deviceの アドレス重複も許容 10 JANOG26 July 2010 Copyright 2010 Alcatel-Lucent. All rights reserved.
www.alcatel-lucent.com www.alcatel-lucent.com 11 JANOG26 July 2010 Copyright 2010 Alcatel-Lucent. All rights reserved.