Upgrade to Pro — share decks privately, control downloads, hide ads and more …

IPv6-Based Services and Operational Experiences in Japan

IPv6-Based Services and Operational Experiences in Japan

Australian IPv6 Summit 2007

Shintaro Kojima

November 20, 2007
Tweet

More Decks by Shintaro Kojima

Other Decks in Technology

Transcript

  1.       Copyright © 2007 by NTT Communications Corporation All rights reserved. IPv6-Based

    Services and Operational Experiences in Japan Shintaro Kojima IP Architect NTT Communications
  2.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 2

    Agenda •  About NTT •  IPv6/IPv4 Dual Stack Backbone and Operations •  How IPv4 Depletion Make Impacts on Access Provider and Enterprise Business •  IPv6 Products and Services Offered by NTT •  Summary
  3.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 5

    66.4 65.9 63.1 59.8 43.5 40.2 38.3 35.9 28.5 25.7 25.1 24.8 21.5 18.6 17.3 16.5 16.1 15.1 77.0 Verizon Communications NTT Deutsche Telekom Telefonica France Telecom AT&T Vodafone Sprint Nextel Telecom Italia BT China Mobile Communications KDDI Comcast Vivendi China Telecommunications America Movil Korea Telecom Telstra BCE Carso Global Telecom Royal KPN Source: July 23, 2007 World’s Top 21 Telecom Companies by Revenue ($US Billion) 92.0 93.2 Who is NTT?
  4.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 6

    1998: Verio begins participation in PAIX native IPv6 IX 2000: Verio obtains IPv6 sTLA from ARIN 2002: World Communications Awards (WCA) awards NTT Communications with “Best Technology Foresight” for its IPv6 Global products 2003: Communications Solutions magazine names NTT/VERIO IPv6 Gateway Services “Product of the Year” 2004: NTT Com wins the World Communications Awards “Best New Service” award for IPv6/IPv4 Global Dual Service 2003: NTT/VERIO launches IPv6 Native, Tunneling, and Dual Stack commercial service in North America 1996: NTT Labs started one of the world’s largest global IPv6 research networks 1999: NTT Com begins IPv6 tunneling trial for Japanese customers 2001: NTT Com pioneers worlds first IPv6 connectivity services on a commercial basis 2004: NTT IPv6 Native and Dual Stack services available around the globe 2005: Dual stack Virtual Private Server released. First ISP to offer an IPv6 managed firewall service 10/2006 – Launched the NTT Communications IPv6 Transition Consultancy 2/2007 – Awarded GSA Schedule 70 contract for IPv6 IP transit NTT Communications IPv6 Service History NTT’s History and IPv6
  5.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 7

    – IPv4 Addresses: – World's Population: – IPv6 Addresses:  Source: ”Internet Routing Guide” from Shoei Publishing (IPv4)A Bucketful of Sand (IPv6)Sand Volume Equivalent to Our Sun (IPv4)1mm in Length (IPv6)84,000 Times Wider than the Diameter of Our Galaxy IPv6 realizes a wide variety of applications and services in a simple and scalable manner with no concerns of IP address limitations or depletion 4,294,967,296 about 6,300,000,000 340,282,366,920,938,463,463,374,607,431,768,211,456 Address Abundance: Comparative Examples IPv6 - What and Why?
  6.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 8

    Now: Client-Server Model ü PC-oriented, One-way or Archive style Communication ü Evil of Anonymity, D.I.Y Connection Future: Machine-to-Machine(M2M) Model ü All IP, bidirectional and real-time communication ü Assignable ID per Machine, Managed Connection Home Network Office Network Data Center Mobile Network Sensor Network DTV PVR Home Security Monitor Camera IC Card MFP CO2 Management Building/Facility Management Digital Cam Mobile Phone Mobile Player Contents Remote Assistance CAD Collaboration IPv6 M2M IPv4 C-S PC PC PC Server Big Picture of Our Goal
  7.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 9

    •  On 19 June 2007, JPNIC issued a press release regarding the IPv4 address consumption. •  The IPv4 address pool is expected to run out around 2010, according to the most reliable predictions. –  After 2010, ISP cannot have new customer and enterprise system cannot be expanded on the current system. –  ISP and engineering have to consider from now "What's happen?", "What is the problem?", "What should we change?" Prediction of exhaustion date by Geoff Huston (generated at 12-Sep-2007 09:57) The red line indicates the number of /8 address blocks remaining in the IANA free pool. The light blue line indicates the number of /8 address blocks available in RIR free address pools. The vertical line indicates today. IPv4 address exhaustion
  8.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 10

    JPNIC has started to work on and evaluate concrete measures with organized efforts internally and externally. •  Address Management Policy Evaluation WG has been organized under experts’ and executive guidance, and submitted its distribution policy proposal to APNIC. “Distribute a single /8 to each RIR at the point when new IANA free pool hits 5*/8” •  Countermeasures for IPv4 Address Inventory Depletion WG has also been organized. It evaluates countermeasures against IPv4 exhaustion on technical standpoint, and expected impact to IPv4 business. •  How to migrate IPv4 to IPv6 ? - IPv4/IPv6 translation ? •  How to continue IPv4 business with limited number of Address ? - private IPv4 address with NAT ? JPNIC’s approach to IPv4 depletion
  9.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 12

    Global Backbone: Completed in 2003 Domestic Backbone: Completed in 2005 IPv6/IPv4 Dual Stack Backbone
  10.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 13

    IPv6/IPv4 Dual Stack Backbone has shown a good performance without any additional investment and critical problems as well. - core routers / routing protocols generally look mature enough to handle current IPv6 traffic. But still, we have some operational difficulties: - stats tools are not available on IPv6 environment IPv6 MIB support, SNMP over IPv6 support ... - IPv6-enabled irrd/whois have been released, but poor performance yet... - There are only few collectors which are capable of netflow v9 For future IPv6 traffic engineering, we need RSVP-TE for IPv6 and LDP for IPv6 IPv6/IPv4 Dual Stack Backbone
  11.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 14

    Source: CAIDA http://www.caida.org/analysis/topology/as_core_network/ipv6.xml Situated in the Heart of Global IPv6 NTT Communications’ IPv6 : Best Balanced and Worldwide Reachable
  12.       Copyright © 2007 by NTT Communications Corporation All rights reserved. How

    IPv4 Depletion Make Impacts on Access Provider and Enterprise Business
  13.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 17

    IP-VPN DMZ DNS・FW・IDS Web Internet Internet VPN Customer Customer’s Partner factory Store Branch Office Head Quarter IPv6-only software/system IPSec IPv4 global address IPv4 VPN Client IPv4 global address translator/DNS-ALG multiple NAT UPnP NAT Traversal IPv6-only clients / servers VPN Intra NW DMZ Expected Problems from 2010
  14.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 18

    early deployment of IPv6 equipments IPv6 enabled WWW (w/ IPv6 Proxy) IPv4 IPv6 IPv6 proxy DNS-ALG IPv4 Web Server :router :server :VPN equipment : APL IPv6 Security Internet VPN renewal (IPv6 VPN) Server IPv6 IPv6/IPv4 FW IPv6/IPv4 - multiple NAT, UPnP, OS upgrade - ASIC implementation IPsec VPN, SSL-VPN, IPv4 over IPv6 FW, IDS, Anti-Virus Some Solutions are available to IPv4 Depletion in Japan ... Solutions to IPv4 Depletion
  15.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 19

    Provider for Consumers for Enterprise Customers NTT Communications IPv6 Internet Connectivity (FTTH, ADSL, Wi-Fi, PHS, Dial-up) IPv6 Internet Connectivity NTT-East IPv6 Non-Internet Connectivity (Video Streaming, VOIP, TV Phone, File Sharing) IPv6 VPN NTT-West IPv6 Non-Internet Connectivity (Video Streaming, VOIP, TV Phone, File Sharing) IPv6 VPN KDDI   IPv6 Internet Connectivity IIJ   IPv6 Internet Connectivity Nifty IPv6 Internet Connectivity (ADSL)   Free Bit IPv6 Internet Connectivity (Tunnel Service)   IIJ mio IPv6 Internet Connectivity (Tunnel Service)   NTT-ME (Xephion) IPv6 Internet Connectivity * http://www.soumu.go.jp/s-news/2007/070330_12.html IPv6 Services in Japan
  16.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 20

    Total Building System Matsushita Electric Works - EMIT System IP Video Phone NTT Regional. TV with IPv6 STB Toshiba Co. Router ALAXALA Network Corporation: - High-end gigabit router Translator SEIKO Precision Inc.: - Network Time Server - IPv4 / IPv6 Translator Broadband Router: YAMAHA Corporation: - Broadband VoIP Router Home Router corega K.K. Remote Camera Server: Chuo Electronics co.,Ltd(CEC): Field Server & Sensor Yokogawa Electric - "Fis" Environment Analysis System IPv6 phone FreeBit Co. Ltd: Networked Audition Machine Yokogawa Electric IPv6 Camera Panasonic Communications Printers - Panasonic Communications - Ricoh Company Ltd. Windows Vista Microsoft Corporation Antivirus Software Trend Micro Incorporated TV Conference Tandberg IPv6 Products sold in Japan
  17.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 22

    IPv6 IPv4 ü Launched in December 2005 ü IPv6 Tunneling Service over IPv4 based on L2TP ü Fixed IP address and non-fixed IP address to be given (Prefix for subnet: /64) ü Original tunneling software provided for subscribers Radius Mail/Web Proxy IPv6 Tunneling Termination Unit L2TP,UDP Implemented OCN IPv6: IPv6 Emulation for Consumer Customers
  18.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 23

    How’s your pet when you… Run a bath remotely before… Fridge tells you what you… Don't miss the TV show … Cool down my room before… With IPv6, you can… IPv6 really changes my life!! Fridge Camera Air Conditioner Video Bath IPv6 Router Various home appliances will be controlled as you wish… OCN IPv6 Brings New Life Style...
  19.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 24

    From Outside Mobile Phones Mobile PCs /PDAs IPv6-non-native devices communicate via Reverse Proxy Server The Internet Reverse Proxy Server (IPv4 ßà IPv6) DNS Server IPv4-IPv6 Conversion OCN IPv6 Router-mode Broadband Router /ADSL Modem IPv6 Network Camera Viewing my home by remotely controlling IPv6 camera My Home OCN IPv6 has an option to control IPv6 devices using non-native consoles such as mobile phones or PDAs OCN IPv6 Mobile: Interoperability with Mobile Units
  20.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 25

    Managed by Web Interface •  Rev-Proxy –  IPv4/IPv6 Translator •  DNS –  IPv6 zone OCN IPv6 Mobile: Control Panel
  21.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 26

    IPv4/IPv6 Dual Router Tokyo Hong Kong /London IPv4/IPv6 Dual Router HD Camera HD Camera HD Vision from Hong Kong HD Vision from Tokyo SD Vision from London HD Vision from Japan Global IP Network(IPv6) Test Date: Feb 13, 2006 Video: W720p(H.264) Audio: AAC-LD CASE: IPv6 High Definition Video Conference Test with TANDBERG
  22.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 27

    27 Multicast Servers Distribution Server FLET’s.net (IPv6 Multicast) IPv6 Multicasting Weather Ministry warning warning IPv4 è IPv6 The system informs the warning via IPv6 multicast network before earthquake arrive. Normal status Informing the Warning earthquake sensor network calculate the arrival time Case: Earthquake warning system
  23.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 28

    Security Easiness Low Cost Telc o B Router/NAT Router/NAT The Internet Model ISP A ISP B Device ID? Trust Trust? Trust Line ID Line ID × × × × × × Trust? Telephone Model Telc o A Tel:03-xxx Tel:06-xxx Trust Trust Trust Device ID Signaling Signaling Interconnection at Conduit Level Incapable of Blocking Malicious Users Unable to Manage Communication Based on Device IDs not Fully Given and Coordinated Provision of Conduit + D.I.Y. Work Interconnection at Signaling Level Capable of Blocking Malicious Users Able to Manage Communications by Device ID (Telephone Number) and Signaling Signaling and Data Channel Exchange Based on Costly Circuit-switch m2m-x Model ISP A ISP B m2m-x m2m-x Trust Sampling from Both Worlds • Secured, easy and low-cost new IP network by ”signaling authentication” • FMC and NGN will also adopt the same architectural philosophy Device ID? Trust? Q R Q R Q Security Easiness Low Cost R Device ID Signaling Device ID Signaling Device ID Signaling Security Easiness Low Cost R R R Interconnection at Signaling Level Capable of Blocking Malicious User Able to Manage Communications by Device ID and Signaling Lower Cost Achieved Having Data Channel Bypassing the Server m2m-x Essentials : Building an Ultimate Network
  24.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 29

    m2m-x Management Server Home Network Mobile Phone Gateway IPv6 Internet Enterprise Network m2m-x Management Server functions: - Authentication - Access control -  Issuance/distribution of encryption keys -  Visible only for authorized peers -  Firewall control Secure, Easy and Low-priced m2m-x (Machine to Machine for any[thing|place|time])
  25.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 30

    PlayStation 2 with USB camera Takara : IP Thread Telephone Toshiba : Home appliance network Pioneer : Cyber Conference System m2m-x Trials (2004.1Q-)
  26.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 31

    Sanyo Electric : IPv6 Multimedia Player Ricoh : Ubiquitous Printing System Matsushita Electric Works : Home System Nextech : Mah-jongg Game on Line m2m-x Trials (2004.1Q-) Continued
  27.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 32

    •  developing Portable CPE for m2m-x •  Portable CPE automatically configures appropriate VPN group (PnP) Portable CPE (under development)
  28.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 33

    41 41 m2m-x Cost reduction by integrating different systems with different destinations to a single access circuit Ø Enables constructing multiple secured network over a single access circuit Ø Enables centralized and simultaneous configuration changes of different locations by a central policy management server Ø Enables flexible control, for example, managing a system from multiple locations and establishing connections only with selected terminals. IP-phones POS User PCs IP-phones Management Servers User PCs Headquarter Local Offices Shops Ventilation and Air Conditioning Illuminations Censors Management PC Video-ads Facilities Policy Management Server Existing systems Shared use of an access circuit Video Phone Video Distribution Video-phone :Policy1(for Energy Company) :Policy 2(Video Distribution) :CPE(Multi Policy Connecting Devices) Access control and authentication based on individual terminals. Cost reduction by monitoring Multiple clients. Energy Monitoring Company Video Distribution Center IPv6 m2m-x: machine to machine for any[thing|place|time] Multi-Policy VPN
  29.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 34

    Multi-Policy VPN •  multi vendor system (thermometer, facility management system, elevator monitoring system ...) •  each vendor can reach its equipment remotely for responsive support •  remote access can be restricted properly with IPv6 Multi-Policy VPN encryption device            Policy Management Server museum LAN vendors LAN IPv6 Network Firewall M2M secure communication encryption device cam thermo meters elevator Firewall NOC blg management power company blg management system IPv6 Field Trial at Tokyo Metropolitan Art Museum (IPv6 Facility Examples)
  30.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 35

    other IPv6 Solutions •  Convenience Store –  Multicast network provides data simultaneously. –  7,000+ stores in nation-wide in Japan. •  Intelligent Building "Saitama-wave" –  Facility network is worked on IPv6 network –  NTT Facilities provide IPv6 Building Automation System and sensors. –  Large number of sensors are connected and distinguished with plenty of IPv6 address. •  MIC project : "RFID-Tag system" –  Quality of beef is guaranteed with networked RFID-Tag System. –  RFID readers are secure-connected with IPv6 IPSec technology. –  RFID-Tag system traces from processing plant to home.
  31.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 36

    •  Remote Management: Building Facility System –  Intensive management reduces work cost. •  Remote support: 15 % Reduction –  Expert analyzes and optimizes the energy of building. •  Light and Blind control: 30% Reduction 2469 MJ/㎡year 1744 MJ/㎡year 29.4% Reduction Heat A/C Light Oth Operation System Expert *** museum  ....  - ....  - .... .... Remote Management *** office  ....  - ....  - .... .... -  .... -  .... -  .... -  .... Collaboration Remote Support FM Center Remote Operation Bendor C Vendor B Vendor A Analysis and Optimization by Expert Energy Analysis Remote Maintenance IPv6 Network National Project: Building Facility Management
  32.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 37

    •  International Joint IT Experiment in Asia –  Theme: e-trade, multi-language, IPv6 communication, collaboration and International IX –  Field: long distance education, medical treatment, etc. –  IPv6 supports P2P communication and collaboration Mitaka City, Tokyo Asia Broadband Network to China to Singapore IPv6 based appliances m2m-x signaling for p2p communication to Thailand (This project is supported by MIC) Mitaka Daini Junior High School (Tokyo, Japan) Catholic High School (Singapore) Low Delay, P2P Direct and Secure Communication 2007: medical treatment and education collaboration    between Japan and Thailand National Project: Asia Broadband Program
  33.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 38

    Satit Kaset School, Bangkok Culture Exchange, Tele-education Hiroshima municipal technical high school, Hiroshima Weather Sensor IP Camera UV Sensor Dust Sensor Sensors and Cameras Bangkok Hiroshima Data Viewer Compare and Discussion National Project : Sensor Network
  34.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 40

    Why IPv6? People are interested in for non-internet use (Intranet, IPVPN) Positively   Value Adding •  IPv6 supports brand-new IP equipments and enables IP systems •  Higher reliability / maintenanceablity / scalability   Low Cost •  IPv6 provides Network Integration and simple / smart IP Network   Preparation for Future Migration •  As the 1st stage of system renewal Negatively ...   IPv4 Address exhaustion   Government Policy
  35.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 41

    In addition to IPv4/IPv6 Internet traffic, •  Broadband Service for Information Appliance –  TV Phone, TV Broadcasting •  P2P Direct and Low Delay Communication –  Collaboration, RFID system, e-Learning, e-trade •  New IP Market and Business –  Building Management, Factory Automation •  Ubiquitous Service: IPv6 Internet and End-End Security Management –  e-Government, Extranet, Remote Maintenance What will change with IPv6?
  36.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 42

    NTT Communications’ IPv6 Road Map Today 1999 2000 2001 2002 2003 2004 2005 Global Backbone Trial Commercial Dual Stack 2006 Dual Transit (Global) Dual ADSL (JP) Configured Tunnel Native Transit (Global) HK Other Asia Pacific, USA Connectivity Services Japan Trial Commercial Dual Transit (JP) Trial OCN IPv6 for Consumer (JP) Platform Services m2m-x VPS Server Hosting (IPv4/IPv6 Dual) Trial Trial VOD 2007 2008 IPv6 IPVPN (JP) Europe
  37.       Copyright © 2007 by NTT Communications Corporation All rights reserved. 43

    Thank you for your attention http://www.v6.ntt.net http://www.ipv6style.jp [email protected]