We have known for a long time that ARIN would be depleting their IPv4 address pool sometime this year. It happened yesterday Sept 24, 2015. So what does that really mean? Unlike some of the other RIRs around the world, ARIN chose to not have any excess reserved pool but to simply completely burn down what IPv4 address blocks they have left in inventory. This means that unlike other RIRs there is not "reserve" bucket at all to reach back into.
Honestly, while the event in very important we are still going to see IPv4 use for a long time. The reason why is that the majority of small and medium sized businesses still get their IPv4 address space from their local service provider. These ISPs still have IPv4 inventory left. I haven't seen any consolidated information about how much inventory major US providers have left but I can imagine at least several years worth. So, if a business needs IPv4 addresses they can still get them.
I do think to get them you will pay more money. Plan and simple economics come up. IPv4 is now a scarce commodity and the price per IPv4 address will only go up over time. This means that IPv6 addresses will become more common as they will be the cost effective option. Especially since that is the only way for the service providers to continue to grow and add customers. So for customers demanding IPv4 for any reason they will have to pay more and those that are willing to go IPv6 only will likely get the most cost effective service pricing.
The other impact is that a lot more folks are going to have to start getting comfortable with IPv6. How to manage it, use it and write applications that run on top of it. There is no way you can claim to be an early adopter of IPv6 at all now but you can certainly join the rapidly growing group of users who are learning and using IPv6. IPv6 is the future and the future is now!
- Ed
Showing posts with label IPv4. Show all posts
Showing posts with label IPv4. Show all posts
Friday, September 25, 2015
Wednesday, April 23, 2014
ARIN moves into Phase 4 and is down to their last /8 of IPv4 - it is time for IPv6
It is official, as of today (April 23, 2014) ARIN and by extension North America has run into the final phase of IPv4 address allocations. They are down to their last /8 and therefore the largest allocation now will be a /22 along with showing a use case for transition over to IPv6. If you have no transition plan, you can't even get that last /22.
You can see more information about Phase 4 at the ARIN press release. This is a huge deal for the Internet community and will likely change some corporate and enterprise adoption plans and thinking in the near future. If you are curious, it looks like Akamai was the big winner with the 104.64.0.0/10 allocation going to them and tipping the inventory level.
So for all of you holding off thinking IPv6 will never impact them, it is time to start planning and figuring out your design and implementation schedules. You will have a bit of time for the service providers to burn through their existing inventory of IPv4 but after that you will have to purchase IPv4 at the going market rate. It makes IPv6 look more and more attractive.
If you want some help getting started in a lab or deploying and you run Windows you might want to pick up my book.
Welcome to a brave new world, I think I need to pick up my "the world is ending" sign and go walk around downtown San Francisco for the day.
- Ed
You can see more information about Phase 4 at the ARIN press release. This is a huge deal for the Internet community and will likely change some corporate and enterprise adoption plans and thinking in the near future. If you are curious, it looks like Akamai was the big winner with the 104.64.0.0/10 allocation going to them and tipping the inventory level.
So for all of you holding off thinking IPv6 will never impact them, it is time to start planning and figuring out your design and implementation schedules. You will have a bit of time for the service providers to burn through their existing inventory of IPv4 but after that you will have to purchase IPv4 at the going market rate. It makes IPv6 look more and more attractive.
If you want some help getting started in a lab or deploying and you run Windows you might want to pick up my book.
Welcome to a brave new world, I think I need to pick up my "the world is ending" sign and go walk around downtown San Francisco for the day.
- Ed
Wednesday, December 18, 2013
IPv6 is like global warming
I recently was on twitter going back and forth with some colleagues on the topic of IPv6 (shocking, I know) and I said the following:
"IPv6 is like global warming, sea level rise is easy to ignore (or deny) but it will impacts a crazy number of people"
This resonates with me. The fact that regardless of how you feel about global warming (man made, natural fluctuation, curse from a $deity) the effects are what matters. There is sea level rise (it is measurable, we are measuring it, it is going up) and given the fact that a very high percentage of the world populations live close or on the edges of the oceans they are going to be impacted.
There are practical ways to deal with this. Most agree the sea level change isn't going to jump up 3+ feet overnight (outside of storm surges, etc.) so it is possible to plan and take corrective action. There are cities and governments in the world where this is happening today. They are being proactive and realize it will take a long time to get everyone to adjust to this new change (building codes, zoning, etc.) There are also those that are not taking these actions. Finally there are those unfortunate few who can't address it even if they wanted to, like some small remote islands.
We won't know the final outcome and impact until years later. Who did the right strategic move and planned, implemented and were ready for the eventual sea level rise? It is analogous to those who plan, implement and deploy IPv6. In both situations you can wait. But eventually you must deal with the issue. Will you be ready when the sea level rise happens? Will you able to execute on IPv6 when your company needs you to?
So perhaps the global warming community can say:
"Global warming is like IPv6, IPv4 depletion is easy to ignore (or deny) but it will impact a crazy number of people"
How is that for turning it back around!
- Ed
"IPv6 is like global warming, sea level rise is easy to ignore (or deny) but it will impacts a crazy number of people"
This resonates with me. The fact that regardless of how you feel about global warming (man made, natural fluctuation, curse from a $deity) the effects are what matters. There is sea level rise (it is measurable, we are measuring it, it is going up) and given the fact that a very high percentage of the world populations live close or on the edges of the oceans they are going to be impacted.
There are practical ways to deal with this. Most agree the sea level change isn't going to jump up 3+ feet overnight (outside of storm surges, etc.) so it is possible to plan and take corrective action. There are cities and governments in the world where this is happening today. They are being proactive and realize it will take a long time to get everyone to adjust to this new change (building codes, zoning, etc.) There are also those that are not taking these actions. Finally there are those unfortunate few who can't address it even if they wanted to, like some small remote islands.
We won't know the final outcome and impact until years later. Who did the right strategic move and planned, implemented and were ready for the eventual sea level rise? It is analogous to those who plan, implement and deploy IPv6. In both situations you can wait. But eventually you must deal with the issue. Will you be ready when the sea level rise happens? Will you able to execute on IPv6 when your company needs you to?
So perhaps the global warming community can say:
"Global warming is like IPv6, IPv4 depletion is easy to ignore (or deny) but it will impact a crazy number of people"
How is that for turning it back around!
- Ed
Thursday, February 03, 2011
Final /8 allocations from IANA to all RIR's happened this morning
IANA finally allocated out the last five /8 IPv4 address blocks this morning in a formal ceremony in Florida. So the free pool of IPv4 address block is done - there is nothing left to hand out to regional registries at all. I guess we are starting off the Chinese New Year with a bang. Silly little rabbit - IPv4 addresses are for kids!
Now I wondering how the IPv4 address request rates are doing at all the RIR's for this month. ARIN has their press release up on the event here.
- Ed
Now I wondering how the IPv4 address request rates are doing at all the RIR's for this month. ARIN has their press release up on the event here.
- Ed
Monday, January 31, 2011
Jan 31, 2011 - IANA IPv4 delegation exhausted - up next the RIR's
For those keeping track of IANA's IPv4 /8 delegations to the Regional Internet Registries (RIR) the final blocks 2 /8's have been assigned, 39/8 and 106/8 went to APNIC. You can see the IANA IPv4 Address Space Registry for details of how things are delegated out not that it will help much but it is interesting to see some of the Legacy allocations.
So the next 5 /8's will be allocated automatically here shortly - guess IANA wanted to do that slower then all at once with the other 2 /8's going out to APNIC. So that is it - IPv4 address space is officially exhausted.
From a practical perspective not a lot will change until the RIR's start running out of address block. The rates will vary for each RIR and Stephen Lagerholm has a great blog on the run rates and what the timing likely will be until they have no IPv4 addresses to hand out anymore.
So what will everyone do once that happens? Luckily the Answer to the Ultimate Question of Life, the Universe and Everything is 42... or is it 2^128?
- Ed
So the next 5 /8's will be allocated automatically here shortly - guess IANA wanted to do that slower then all at once with the other 2 /8's going out to APNIC. So that is it - IPv4 address space is officially exhausted.
From a practical perspective not a lot will change until the RIR's start running out of address block. The rates will vary for each RIR and Stephen Lagerholm has a great blog on the run rates and what the timing likely will be until they have no IPv4 addresses to hand out anymore.
So what will everyone do once that happens? Luckily the Answer to the Ultimate Question of Life, the Universe and Everything is 42... or is it 2^128?
- Ed
Tuesday, October 19, 2010
IPv6 - The Ostrich Effect
I have decided it is time to label one of the psychological effects being seen in the IT Professional community in regards to IPv6. I am calling it the Ostrich Effect and I am defining it as:
"The aversion to receiving information about IPv6 or avoiding the topic long enough in hopes it will go away"
It seems there are several different grouping of opinions regarding IPv6 and here are my quick outline of those groups below. I do think some of my group's mental states lines up with the stages of grief which are Denial, Anger, Negotiation, Depression and Acceptance however I think mine have more to do with the camps that have evolved around the issue of IPv6. I actually think that for each group defined below they will still have to go through all the stages of grief, I just think some will make it through without issue and some might not make it at all.
1. The "it will never happen" group
Typically folks in this category are more project planners, IT directors and CFO types who are justifying their comments by making generic snide references to how long have people been saying we would run out of IPv4 addresses and that it hasn't come to pass or that there is no new beneficial value from planning or even looking into IPv6. Their primary concerns are cost controls not operational issues so to them IPv6 only looks like an additional cost without any benefit. There are also people who believe IPv4 can live forever by doing even more NAT/PAT solutions but they clearly haven't looked at the bigger picture of the challenges with that for solution providers and carriers. Also, many in this group tend not to understand the larger issues with IPv4 vs IPv6 such as routing table size, the usage rate of addresses etc and seem to think that we can simply "recover" IPv4 addresses from folks who got allocated "too many" in the early days of IPv4. In a desperate plea to those folks, go take a look at what ARIN has to say about that.
2. The "I'm not convinced and this is annoying" group
Honestly, I think most business and management folks fit into this category right now. That is why there are IPv6 Task Forces all over the US to try and help people understand why they should be in the 3 or 4 category. Many professionals feel it is hard enough to keep up on what they have today in terms of technology so to learn a whole new networking protocol adds a lot of burden for the same perceived functionality they get out of IPv4 today. In addition, they truly believe they have a lot more time to work this out then they actually do. Basically they are stalling and are annoyed that people are telling them they have to pay attention.
3. The "I get it but I will wait for broader adoption" group
This group of people understand it is coming but don't want to be the first to have to do it. Unfortunately most network admins and system admins fit in this group. What is more alarming is they are horribly lacking in training and resources to get IPv6 working in their environment and unfortunately are unlikely to get budget to get the training they need. Hence their desire to wait! What is of great concern for them is when their management moves from group 2 to group 4 overnight. Then their management expects them to be able to implement overnight too. My only advise is get training any way you can so you are ready when the sleeping giant awakens.
4. The "I am totally stoked to get IPv6 rolled out" group
The rare group of IT professionals and visionary business leaders who understand that for their business model to continue working they must be able to support and communicate with everyone who might potentially be on the Internet, regardless of if they are using IPv4 or IPv6 to reach you. And with the address pool depletion happening soon (maybe before the end of 2010 if there is a run on addressing) you will have no choice - you MUST adopt IPv6 to meet that goal. So, they are already planning to design, deploy and support it, it means continued business which means everyone can keep the lights on. In other words, they get it. Many forward thinking companies have already starting doing this - kudos to you!
5. The "I've been doing IPv6 for years - what took you so long" group
The front runners and leaders who are using IPv6 as a strategic advantage as market leaders of services hoping to gain new customers and take customers from those who are unable to meet the new business requirements of those in group 4. Hate to say it but to be in group 5 means you've already been doing IPv6 for more than a year or longer. This group has left the station and it's an exclusive club and you can't join - sorry, it's just too late. For those in this group - you rock.
I hope to post up a road map that I am developing for the CAv6TF soon. It is for IT Professionals to allow them to rapidly meet the IPv6 requirements that will drop on them like a lead balloon. It is specifically targeted for folks in group 3 and 4 and has both the road map but a checklist too.
- Ed
"The aversion to receiving information about IPv6 or avoiding the topic long enough in hopes it will go away"
It seems there are several different grouping of opinions regarding IPv6 and here are my quick outline of those groups below. I do think some of my group's mental states lines up with the stages of grief which are Denial, Anger, Negotiation, Depression and Acceptance however I think mine have more to do with the camps that have evolved around the issue of IPv6. I actually think that for each group defined below they will still have to go through all the stages of grief, I just think some will make it through without issue and some might not make it at all.
1. The "it will never happen" group
Typically folks in this category are more project planners, IT directors and CFO types who are justifying their comments by making generic snide references to how long have people been saying we would run out of IPv4 addresses and that it hasn't come to pass or that there is no new beneficial value from planning or even looking into IPv6. Their primary concerns are cost controls not operational issues so to them IPv6 only looks like an additional cost without any benefit. There are also people who believe IPv4 can live forever by doing even more NAT/PAT solutions but they clearly haven't looked at the bigger picture of the challenges with that for solution providers and carriers. Also, many in this group tend not to understand the larger issues with IPv4 vs IPv6 such as routing table size, the usage rate of addresses etc and seem to think that we can simply "recover" IPv4 addresses from folks who got allocated "too many" in the early days of IPv4. In a desperate plea to those folks, go take a look at what ARIN has to say about that.
2. The "I'm not convinced and this is annoying" group
Honestly, I think most business and management folks fit into this category right now. That is why there are IPv6 Task Forces all over the US to try and help people understand why they should be in the 3 or 4 category. Many professionals feel it is hard enough to keep up on what they have today in terms of technology so to learn a whole new networking protocol adds a lot of burden for the same perceived functionality they get out of IPv4 today. In addition, they truly believe they have a lot more time to work this out then they actually do. Basically they are stalling and are annoyed that people are telling them they have to pay attention.
3. The "I get it but I will wait for broader adoption" group
This group of people understand it is coming but don't want to be the first to have to do it. Unfortunately most network admins and system admins fit in this group. What is more alarming is they are horribly lacking in training and resources to get IPv6 working in their environment and unfortunately are unlikely to get budget to get the training they need. Hence their desire to wait! What is of great concern for them is when their management moves from group 2 to group 4 overnight. Then their management expects them to be able to implement overnight too. My only advise is get training any way you can so you are ready when the sleeping giant awakens.
4. The "I am totally stoked to get IPv6 rolled out" group
The rare group of IT professionals and visionary business leaders who understand that for their business model to continue working they must be able to support and communicate with everyone who might potentially be on the Internet, regardless of if they are using IPv4 or IPv6 to reach you. And with the address pool depletion happening soon (maybe before the end of 2010 if there is a run on addressing) you will have no choice - you MUST adopt IPv6 to meet that goal. So, they are already planning to design, deploy and support it, it means continued business which means everyone can keep the lights on. In other words, they get it. Many forward thinking companies have already starting doing this - kudos to you!
5. The "I've been doing IPv6 for years - what took you so long" group
The front runners and leaders who are using IPv6 as a strategic advantage as market leaders of services hoping to gain new customers and take customers from those who are unable to meet the new business requirements of those in group 4. Hate to say it but to be in group 5 means you've already been doing IPv6 for more than a year or longer. This group has left the station and it's an exclusive club and you can't join - sorry, it's just too late. For those in this group - you rock.
I hope to post up a road map that I am developing for the CAv6TF soon. It is for IT Professionals to allow them to rapidly meet the IPv6 requirements that will drop on them like a lead balloon. It is specifically targeted for folks in group 3 and 4 and has both the road map but a checklist too.
- Ed
Thursday, July 29, 2010
Why paying attention to IPv6 is now important
As a personal interest I have been working with and following developments of IPv6 for several years. I started presented on IPv6 back in 2006 because of what was happening with Windows Vista and the changes that Microsoft was doing with the OS and their new networking stack. Here we are in 2010 and I think we are past early adopters in regards to IPv6. In fact, I now think if you are not paying attention to what is happening with IPv6 it could start impacting your ability to perform your job soon, especially if you are an IT Professional.
So, who do I think will be impacted the most by the transition and more prolific use of IPv6? I think you might be surprised.
The standard answer is network engineers and granted they indeed will be rolling out and maintaining dual IPv4/IPv6 networks for years to come but I actually don't think IPv6 will be as much of a challenge for network engineers to get up and running assuming they have moderately newer network equipment. Granted, there are issues with lack of feature parity but that will be resolved over time and will be fast tracked when equipment manufactures realize they are losing sales due to the lack of the parity.
Next on the list is system admins. I think many will find IPv6 to be a bit more of a challenge in regards to the differences in behavior of the protocol and getting worked out the behavior differences of applications as a result. This is a huge issue for client machines in terms of what OS you are running on your desktop and what the server does or does not support. I would argue that the majority of system admins know enough IPv4 networking to allow them to do their job but likely will have some challenges with differences in IPv6. I know there are some great system admins out there who could run networks also so obviously this a wildly general statement but I still feel there is going to be a bigger learning curve for system admins than they care to admit. Perhaps it is time for Microsoft to bring back a dedicated networking exam - like the old MCP TCP/IP exam?
The surprise group is application developers and database admins. Just think about how much code has been written out there to account for IPv4 addresses. IPv4 addresses are 32bit and I would imagine the majority of applications out there are storing that value under a declared INTEGER. I could be wrong - maybe they are all stored as a STRING instead but I have a feeling that isn't the case. IPv6 addresses on the other hand are 128bit and likely the majority of applications will have to be modified to account for the new size, difference in how they are represented (in HEX not DEC) and also the fact that the application might potentially have to pay attention to which interface it is directing traffic through. This doesn't even cover all the databases out there that are storing IPv4 information and the SQLNET statements all based around IPv4 to query those databases.
To top it all off, IPv6 can represented an address in multiple ways due to the zero compression option. So searching through logs or analyzing output could be an additional issue unless some standards are agreed to in advance in terms of how to store and represent an IPv6 address. So imagine trying to correlate information from multiple systems and they can't match stuff because the IPv6 addresses are represented differently in each system. I think some of these issues will be the biggest road blocks to overcome in the months and years ahead for IPv6.
So, why is it important to pay attention to IPv6 now? It is important because the adoption and momentum behind the protocol has already begun. Major content providers like Facebook and network providers like Comcast and content delivery providers like Limelight have all deployed IPv6 already and are doing their trials now. If you have no knowledge or understanding of IPv6 how will you address your business needs when you need to either access content, deliver content or work with a network when you don't understand the protocol they are using to move traffic?
In short, if you don't have a working understanding of IPv6, you are already behind. Take a quick quiz. Do you know what behavior Windows 7 has when it has a public IPv4 address? What is different if it gets a public IPv6 address? Which protocol does it use for DNS resolution if it has both an IPv4 and IPv6 address? Does the type of IPv6 address it has matter to the default behavior? This is all just for Windows 7, now do this for OSX, Windows Vista, Windows XP, Windows Server 2003, 2008, 2008R2, Linux and Solaris. How did you do?
- Ed
So, who do I think will be impacted the most by the transition and more prolific use of IPv6? I think you might be surprised.
The standard answer is network engineers and granted they indeed will be rolling out and maintaining dual IPv4/IPv6 networks for years to come but I actually don't think IPv6 will be as much of a challenge for network engineers to get up and running assuming they have moderately newer network equipment. Granted, there are issues with lack of feature parity but that will be resolved over time and will be fast tracked when equipment manufactures realize they are losing sales due to the lack of the parity.
Next on the list is system admins. I think many will find IPv6 to be a bit more of a challenge in regards to the differences in behavior of the protocol and getting worked out the behavior differences of applications as a result. This is a huge issue for client machines in terms of what OS you are running on your desktop and what the server does or does not support. I would argue that the majority of system admins know enough IPv4 networking to allow them to do their job but likely will have some challenges with differences in IPv6. I know there are some great system admins out there who could run networks also so obviously this a wildly general statement but I still feel there is going to be a bigger learning curve for system admins than they care to admit. Perhaps it is time for Microsoft to bring back a dedicated networking exam - like the old MCP TCP/IP exam?
The surprise group is application developers and database admins. Just think about how much code has been written out there to account for IPv4 addresses. IPv4 addresses are 32bit and I would imagine the majority of applications out there are storing that value under a declared INTEGER. I could be wrong - maybe they are all stored as a STRING instead but I have a feeling that isn't the case. IPv6 addresses on the other hand are 128bit and likely the majority of applications will have to be modified to account for the new size, difference in how they are represented (in HEX not DEC) and also the fact that the application might potentially have to pay attention to which interface it is directing traffic through. This doesn't even cover all the databases out there that are storing IPv4 information and the SQLNET statements all based around IPv4 to query those databases.
To top it all off, IPv6 can represented an address in multiple ways due to the zero compression option. So searching through logs or analyzing output could be an additional issue unless some standards are agreed to in advance in terms of how to store and represent an IPv6 address. So imagine trying to correlate information from multiple systems and they can't match stuff because the IPv6 addresses are represented differently in each system. I think some of these issues will be the biggest road blocks to overcome in the months and years ahead for IPv6.
So, why is it important to pay attention to IPv6 now? It is important because the adoption and momentum behind the protocol has already begun. Major content providers like Facebook and network providers like Comcast and content delivery providers like Limelight have all deployed IPv6 already and are doing their trials now. If you have no knowledge or understanding of IPv6 how will you address your business needs when you need to either access content, deliver content or work with a network when you don't understand the protocol they are using to move traffic?
In short, if you don't have a working understanding of IPv6, you are already behind. Take a quick quiz. Do you know what behavior Windows 7 has when it has a public IPv4 address? What is different if it gets a public IPv6 address? Which protocol does it use for DNS resolution if it has both an IPv4 and IPv6 address? Does the type of IPv6 address it has matter to the default behavior? This is all just for Windows 7, now do this for OSX, Windows Vista, Windows XP, Windows Server 2003, 2008, 2008R2, Linux and Solaris. How did you do?
- Ed
Friday, January 29, 2010
Recommended rfc networks to consider as filters
There are many ways to help protect your network from attack, one of the simpilist and most effective is actually to filter incoming and outgoing traffic from your network. An excellent place to start is to utilize the rfc's to define IPv4 addresses that are not or never will be in use on the public Internet and not allowing that traffic inbound. In the same vein, you can use the same information to limit what is allowed to leave your network, such as only IPv4 addresses that are legitimately routable on the public Internet.
This is not a new or unique solution but it is more commonly done at the service provider and larger enterprise level because those type of operations pay attention to the rfc's but also because they recieve much higher traffic loads on average traditionally. I believe that this technique is still useful for much smaller operations to use and is relatively simple to set up and maintain.
Here is a short list of rfc's to put in your firewall or edge router of addresses you should not be seeing from the Internet and ones that you should consider filtering out before sending traffic out to the Internet.
network RFC 1112
description - Host Extensions for IP Multicasting - in RFC 1700 also
240.0.0.0 240.0.0.0
network RFC 1700
description - assigned numbers - multicast, current, host, and reserved
224.0.0.0 240.0.0.0
240.0.0.0 240.0.0.0
0.0.0.0 255.0.0.0
127.0.0.0 255.0.0.0
network RFC 1797
description - Class A Subnet Experiment - may get reallocated - use the bogon list instead
39.0.0.0 255.0.0.0
network RFC 1918
description - reserved private IPv4 addresses
10.0.0.0 255.0.0.0
172.16.0.0 255.240.0.0
192.168.0.0 255.255.0.0
network RFC 2544
description - Benchmarking Methodology for Network Interconnect Devices
198.18.0.0 255.254.0.0
network RFC 3068
description - IPv4 reserved 6to4 IPv6 gateway services
192.88.99.0 255.255.255.0
network RFC 3171
description - IANA Guidelines for IPv4 Multicast Address Assignments
224.0.0.0 224.0.0.0 (covers 224.0.0.0 through 255.255.255.255)
network RFC 3927
description - Dynamic Configuration of IPv4 Link-Local Addresses - in 5735 above
169.254.0.0 255.255.0.0
network RFC 5735 (update of RFC 3330)
description - this rfc really collects all the other rfc with special use (reserved and limited IPv4 blocks) in a single doc, these is only a partial listing
192.0.2.0 255.255.255.0
169.254.0.0 255.255.0.0
224.0.0.0 224.0.0.0
14.0.0.0 255.0.0.0 (may be reallocated - use the bogon list instead just in case)
network RFC 5736
description - IPv4 Special Purpose Address Registry
192.0.0.0 255.255.255.0
network RFC 5737
description - reserved for test net
198.51.100.0 255.255.255.0
203.0.113.0 255.255.255.0
Here are some reference URL's to get you started to determine what you should apply for your needs.
Wikipedia
IANA
Team CYMRU
In addition to using IP address list filters there are other protections you can take at the edge. You should consider putting more aggressive ICMP filters in and also filter specific IP protocol numbers from coming in or going out. I'll post more about that another time.
- Ed
This is not a new or unique solution but it is more commonly done at the service provider and larger enterprise level because those type of operations pay attention to the rfc's but also because they recieve much higher traffic loads on average traditionally. I believe that this technique is still useful for much smaller operations to use and is relatively simple to set up and maintain.
Here is a short list of rfc's to put in your firewall or edge router of addresses you should not be seeing from the Internet and ones that you should consider filtering out before sending traffic out to the Internet.
network RFC 1112
description - Host Extensions for IP Multicasting - in RFC 1700 also
240.0.0.0 240.0.0.0
network RFC 1700
description - assigned numbers - multicast, current, host, and reserved
224.0.0.0 240.0.0.0
240.0.0.0 240.0.0.0
0.0.0.0 255.0.0.0
127.0.0.0 255.0.0.0
network RFC 1797
description - Class A Subnet Experiment - may get reallocated - use the bogon list instead
39.0.0.0 255.0.0.0
network RFC 1918
description - reserved private IPv4 addresses
10.0.0.0 255.0.0.0
172.16.0.0 255.240.0.0
192.168.0.0 255.255.0.0
network RFC 2544
description - Benchmarking Methodology for Network Interconnect Devices
198.18.0.0 255.254.0.0
network RFC 3068
description - IPv4 reserved 6to4 IPv6 gateway services
192.88.99.0 255.255.255.0
network RFC 3171
description - IANA Guidelines for IPv4 Multicast Address Assignments
224.0.0.0 224.0.0.0 (covers 224.0.0.0 through 255.255.255.255)
network RFC 3927
description - Dynamic Configuration of IPv4 Link-Local Addresses - in 5735 above
169.254.0.0 255.255.0.0
network RFC 5735 (update of RFC 3330)
description - this rfc really collects all the other rfc with special use (reserved and limited IPv4 blocks) in a single doc, these is only a partial listing
192.0.2.0 255.255.255.0
169.254.0.0 255.255.0.0
224.0.0.0 224.0.0.0
14.0.0.0 255.0.0.0 (may be reallocated - use the bogon list instead just in case)
network RFC 5736
description - IPv4 Special Purpose Address Registry
192.0.0.0 255.255.255.0
network RFC 5737
description - reserved for test net
198.51.100.0 255.255.255.0
203.0.113.0 255.255.255.0
Here are some reference URL's to get you started to determine what you should apply for your needs.
Wikipedia
IANA
Team CYMRU
In addition to using IP address list filters there are other protections you can take at the edge. You should consider putting more aggressive ICMP filters in and also filter specific IP protocol numbers from coming in or going out. I'll post more about that another time.
- Ed
Subscribe to:
Posts (Atom)

