Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
80
IPv4 Usage Trend Duplicate Address Detection (DAD) feature IPV6 SECURITY
IPv4 Historical Usage SOLVED? IPv6 has embedded support for IPsec. Currently, the host operating
60 Network Address IPV6 NOTATION system can configure an IPsec tunnel between the host and any other
Translation (NAT) The following diagram demonstrates the notation and shortcuts for host that has IPv6 support. With IPv4, the vast majority of IPsec
40 and Port Address IPv6 addresses. deployments use a client-server model, whereby an IPsec terminating
Translation (PAT) device handles the authentication, encryption and decryption
20 were developed as 128 bits are expressed as 8 functions. With IPv6 IPsec, the host could create an IPsec tunnel
solutions to the dimin- fields of 16-bits in Hex notation between an IPsec headend device or directly to another host.
0 ishing number of
1980 1985 1990 1995 2000 2005 2010 available IP addresses. 2031:0000:130F:0000:0000:09C0:876A:130B IPV6 MOBILITY
Time NAT and PAT allow As a shorthand, leading zeros IPv6 supports a greater array of features for the mobile user,
a company or user to share a single or a few assigned IP addresses in each are optional: whether the mobile device is a cell phone, PDA, laptop computer,
among several private addresses (which are not bound by an address 2031:0:130F:0:0:9C0:876A:130B or a moving military vehicle. Mobile IPv6 supports a more stream-
authority). Although these schemes preserve address space and Also, successive fields of 0 lined approach to routing packets to and from the mobile device
provide anonymity, these benefits come at the cost of individuality, can be represented as ::, and also supports IPsec between the mobile device and other
which conflicts with the reason for networking (and the Internet) 2031:0:130F::9C0:876A:130B network devices and hosts.
allowing peer-to-peer collaboration through shared applications. The :: shorthand can be
used only once per address IPV6 TRANSITION
NAT/PAT Breaks While Internet Service Providers (ISPs) have started shifting to IPv6,
V Peer-to-Peer V 2031:0:130F::9C0:876A::130B
some companies will not notice a change as the migration will likely
IPv4 take many more years.
Internet An IPv6 address uses the first 64 bits in the address for the network ID
IPv6 and the second 64 bits for the host ID. The network ID is separated
Internet
into prefix chunks. The diagram below shows the address hierarchy.
19962001 2002 2003 2004 2005 2006 20072010
Q Q Q Q Q Q Q Q Q Q Q Q Q Q Q Q Q Q Q Q
1 2 3 4 1 2 3 4 1 2 3 4 1 2 3 4 1 2 3 4
V IPv6 Internet
2001::/16 Early adopters
Application port <= Duration 3+ years =>
ISP
ISP adoption <= Duration 3+ years =>
2001:0410::/32
Consumer adoption <= Duration 5+ years =>
Site 1 Site 1
2001:0410:0001:/48 2001:0410:0002:/48 Enterprise adoption <= Duration 5+ years =>
IP Version 6 (IPv6) not only provides a solution to the shortage of it E-Europe, E-Japan, North-America IPv6 Task Force,
addresses, also allows for the restoration of a true end-to-end model
where hosts can connect to each other unobstructed and with greater 2001:0410:0002:0002:/64 2001:0410:0002:0001:/64
flexibility. The critical elements in IPv6 are allowing each host to have
a unique global IP address, maintaining connectivity even when in
motion, and natively securing host communications.
2001:0410:0002:0001:000A:09C:0876A:130B Copyright 2008 Cisco Systems, Inc. All rights reserved. Cisco, Cisco IOS, Cisco Systems, and
Written as the Cisco Systems logo are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the
2001:0410:2:1:A:09C:876A:130B
United States and certain other countries. All other trademarks mentioned in this document or Web
site are the property of their respective owners. The use of the word partner does not imply a
partnership relationship between Cisco and any other company. (0402R) He/LW5810 0304