Top 5 Misperceptions about Enterprise IPv6 Deployment - #3
The No. 3 entry in this series covers where you need to deploy IPv6, day one. Where you turn IPv6 on day one is usually driven by two factors: use case and time frame. Since IPv6 is just IP and you probably have IP everywhere today, it makes sense that you now need IPv6 everywhere. The reality is that this is not really true, at least not immediately.
If you are trying to represent your organization on the Internet then start there. You don’t have to have every network segment, host, application and service lit up with IPv6 internally in order to do that. If you have hosts internal to your environment that need access to IPv6-enabled services/applications then start with those specific hosts, the services/apps and the network that connects them. This is, again, most likely not all of your entire organization day one.
I have presented for years three “start here” scenarios. The first one is what I call “Core-to-Edge”. This model is used when you have no defined time frame for deployment, but you want to have your network prepared for the eventuality of IPv6 services one day. The core of the network is chosen as you have a smaller number of devices to touch, you can deploy IPv6 without interrupting the IPv4 part of the network, the production applications and the hosts. You can screw this thing up several times, redo your addressing and still not hurt the network. Once you learn stuff like routing, addressing, QoS and other important services, you can then start dual stacking from the core towards the edge (i.e. campus, branch, remote access VPN, etc…). Figure 1 shows this core-to-edge model from a high-level.

Figure 1: core-to-edge model
The second model is what I call “Edge-to-Core”. This is a more difficult deployment step as it relies nearly 100% on tunneling. It is used by those organizations that need to connect endpoints to the Internet or their own internal Data Centers and apps that are IPv6-enabled and do it in a hurry. This may be used by a vendor who is writing software that is IPv6-aware and they need their developers to have access to an IPv6 environment to do their job. They may not have the luxury of time or money to dual stack the whole network at once so they start small with an overlay deployment. As time goes on the network underneath the tunneling or overlay environment can be dual stack enabled and then the tunnels can go away. Figure 2 shows the edge-to-core model.

Figure 2: edge-to-core model
The third model is the “Internet Edge-Only” model. This is quite popular these days and simply has the Internet Edge IPv6-enabled so the organization can represent its services and content over both the existing IPv4 connection and the new IPv6 connection. Figure 3 shows the Internet Edge-Only model and over time, the internal network can be IPv6 enabled if that makes sense.
Figure 3: Internet Edge-Only” model. Click to enlarge diagram.
Use IPv6 for what you need it for, where you need it. That is mostly likely not in every nook-and-cranny across your worldwide network. Will you have IPv6 deployed everywhere one day? Most likely, but you really don’t need to take that step all at once.




