- 18 Hot IT Certifications for 2014
- CIOs Opting for IT Contractors Over Hiring Full-Time Staff
- 12 Best Free iOS 7 Holiday Shopping Apps
- For CMOs Big Data Can Lead to Big Profits
IDG News Service - With the last IPv4 addresses about to be allocated, the good news is that IT managers -- at least in the U.S. and Europe -- don't suddenly have to get the next Internet Protocol working.
The bad news is that there are some hazards both in putting off adoption of IPv6 and in implementing it, according to vendors and industry analysts.
PANIC TIME QUIZ: How prepared are you for IPv6?
If the Asia-Pacific Network Information Center is granted two more large blocks of IP addresses, which it is entitled to because its addresses are being snatched up so fast, then a rule will kick in that forces the Internet Assigned Numbers Authority (IANA) to divide the remaining five blocks of IPv4 addresses among the world's five regional registries. Once the regional bodies run out of those addresses, they will have nowhere to turn for new ones.
IPv6, introduced in the late 1990s, offers an almost unlimited number of addresses, compared with approximately 4.3 billion addresses for IPv4. While many devices use privately held addresses that are reused on the same LAN, unique IP addresses are usually needed for servers and other types of endpoints. Particularly in fast-growing parts of the world, such as India and China, those unique addresses are being consumed quickly. The two versions aren't compatible, so, for example, client systems that only have an IPv6 address can't get to content on servers that only have IPv4 addresses.
Yet despite the dire state of IPv4, the use of IPv6 is still minuscule, according to Arbor Networks, which supplies network monitoring equipment to about three-quarters of all large Internet service providers (ISPs).
The results of Arbor's last survey of the Internet, about five months ago, show only a fraction of one-tenth of 1 percent of all traffic used IPv6, "almost below the threshold of what we could measure," Arbor Chief Scientist Craig Labovitz said.
Part of the reason is that migrating to IPv6 costs money and in most cases offers no economic benefit, observers said. However, it will take cooperation from everyone to prevent the first IPv6-only Internet users being cut off from most of the world's Internet hosts, said Jason Schiller, a senior Internet network engineer at Verizon Business. He fears some user, somewhere, may be in that predicament in the next six to 12 months if nothing is done.
That's not likely to happen to enterprises in North America or Europe, analyst Glen Hunt of Current Analysis believes. For one thing, major U.S. service providers will have IPv4 addresses to give out to their customers for some time, he said. Also, through large-scale NAT (network address translation), the carriers could also act as bridges between the IPv4 world and users who can only get IPv6, according to Hunt. With NAT, users can share a single, unique IPv4 address that is exposed to the outside Internet.
GOING, GOING ...: Policymakers to announce depletion of free pool of IPv4 addresses
However, Hunt and other experts warned that centralized, large-scale NAT has many dangers. The systems that perform the translation could become bottlenecks if asked to process too many requests. Having so many users share a single IPv4 address might also cause errors and security problems. For example, if a host suffers a DOS (denial-of-service) attack from behind the NAT device, it might associate the attack with the shared IPv4 address and respond in a way that affects all the users sharing the address, according to Verizon's Schiller. That could even involve those users getting blocked for a few minutes.
Large-scale NAT could also make troubleshooting harder for the service provider and interfere with application acceleration or even targeted advertising, if an advertiser tried to build a profile based on a shared IP address.
"If the guy next to you is into hunting and fishing, and you're not, you might start seeing ads for hunting and fishing," Schiller said.
For those reasons, Verizon hopes to avoid deploying NAT for this purpose on its own network. Instead, it recommends users set up NAT on their own premises.
Even organizations that do the right thing and deploy IPv6 may run into challenges to securing their networks, because most security systems today are built around the properties of IPv4, security experts said.
GETTING STARTED: Enterprise IPv6 address planning considerations
For example, there are so many addresses in IPv6 that the typical supply handed out to one organization is too large to scan for threats on the internal network.
"The networks are so large that to scan a typical net block would take 5 billion years," said Misha Govshteyn, vice president of technology and service provider solutions at security vendor Alert Logic. Scanning a typical IPv4 address range takes no more than a few minutes. Govshteyn added that his company is developing a new type of vulnerability assessment that will work with IPv6 networks.
This problem isn't as bad as it might seem, because there are other methods of finding potential threats, according to Danny McPherson, vice president of network security research at VeriSign Labs. A security tool can watch activity on the network or the allocation of devices through a method such as DHCP (Dynamic Host Configuration Protocol). Not being able to scan all the IP addresses in a network does prevent discovery of passive listening devices, but those devices might resist identification anyway, he added.
However, there will be headaches for companies upgrading to IPv6, McPherson said. Security products for IPv6 typically are more expensive than their IPv4 counterparts because the economies of scale haven't driven down costs yet, he said.
Partly as a result of these challenges, IPv4 will be with us for a long time, McPherson and others warned. Many systems that don't get replaced often, such as industrial SCADA platforms, could remain in place using old IPv4 addresses for years, McPherson said. IPv4 will probably remain for decades.