Showing posts with label Teredo. Show all posts
Showing posts with label Teredo. Show all posts

Friday, July 20, 2012

Understanding IPv6, Third Edition is now available!

Microsoft Press has released the new book Understanding IPv6, Third Edition by my friend Joseph Davies. I was fortunate enough to be asked by Joe to be the technical editor of the book and I am very excited about it now being available. Joe has done a great job covering some pretty difficult topics around IPv6 and if you are an IT Pro and doing Microsoft infrastructure architecture, design and deployment you really need to get this book. Why?

First, it has been updated for Windows 8 and Windows Server 2012 and some of the specific IPv6 behavior those two OS's will have verse previous versions of Windows. Second, it has updated recommendations on best practices for deployment in DirectAccess environments and also updated references to RFC's. The last point isn't trivial as the RFC landscape around IPv6 is actually changing and has been moving around a lot within the last 3 years or so.

Finally, you will need a good technical reference around the IPv6 protocol and how it is implemented in Windows and this is the ONLY book that provides that. It was written by someone who has intimate access to the Windows COSD team (they write the network stack for Windows) and I think Joe does a wonderful job making a rather difficult subject matter something that can be understood quickly. Best of all, you don't have to read it end to end, it was designed to be read in chapters as they are relevant to you and what you are trying to do.

It is available from Amazon and at the O'Reilly / Microsoft Press site. The first chapter is available as a sample download too.

The book chapters are:
Chapter 1: Introduction to IPv6
Chapter 2: IPv6 Protocol for Windows
Chapter 3: IPv6 Addressing
Chapter 4: The IPv6 Header
Chapter 5: ICMPv6
Chapter 6: Neighbor Discovery
Chapter 7: Multicast Listener Discovery and MLD Version 2
Chapter 8: Address Autoconfiguration
Chapter 9: IPv6 and Name Resolution
Chapter 10: IPv6 Routing
Chapter 11: IPv6 Transition Technologies
Chapter 12: ISATAP
Chapter 13: 6to4
Chapter 14: Teredo
Chapter 15: IP-HTTPS
Chapter 16: NAT64/DNS64
Chapter 17: IPv6 Security Considerations
Chapter 18: DirectAccess
Chapter 19: Deploying IPv6 on an Intranet
Chapter 20: IPv6 on the Microsoft Corporate Network
Appendix IPv6 RFC Index
Appendix Testing for Understanding Answers
Appendix Setting Up an IPv6 Test Lab
Appendix IPv6 Reference Tables
Appendix Link-Layer Support for IPv6
Appendix Windows Sockets Changes for IPv6
Appendix Mobile IPv6
Appendix Teredo Protocol Processes

So there you have it, my shameless book plug. Honestly, I really do believe you will get great value from Joe's book if you have to do any work around IPv6 and Windows at all. Given everything that is happening on the Internet that should be a LOT of people!
- Ed

Thursday, February 18, 2010

Quick update on Microsoft Teredo

I got my chance to meet with Joe Davies (CableGuy) with Microsoft yesterday and outline my items regarding Teredo. He is going to follow up with Sean Siler and others regarding the behavior of Teredo, the ability to manage Teredo and what exactly is collected (if anything) at teredo.ipv6.microsoft.com.

So, as soon as I hear back from Joe and Sean I will put up a post (assuming it isn't NDA) and hopefully clear up some of these items.

I also had a bunch of questions regarding ISATAP and what Microsoft has for a roadmap in terms of support and deployment around ISATAP. I've expressed my distaste for ISATAP due to the lack of management tools for it to determine where issues are within your network. That being said, I asked specifically for a written policy and guide around ISATAP so hopefully we will get something!
- Ed

Wednesday, February 17, 2010

Should Microsoft have a different policy on the default behavior of their Teredo client?

Now with Windows 7 increasing in deployments there is a legitimate concern if Microsoft has the best policy regarding non domain joined client machines having Windows Teredo enabled but not active as a default setting. There are many forum and security posts saying that even minor changes in the OS activate the Teredo client service turning it on and enable it. While the new Advanced Firewall certainly is IPv6 ready and had a good default posture it concerns many people that the Teredo client is going out to teredo.ipv6.microsoft.com automatically and obtaining a legitimate routable IPv6 address.

I personally have not seen this behavior on Windows 7 clients I have used but I tend to use clients that are joined to a domain and are not stand alone clients. The behavior of non domain joined machines seems to be different then domain joined ones and this is likely to address the home/smb market and the different behavior that Microsoft wanted those people to experience than an Enterprise deployment.

For Enterprise and SMB's that are a concerned about client machines accessing Microsoft's Teredo relay server it is easy enough to write a GPO that would disable the teredo client, I covered much of the commands to do this in a previous post. What is more interesting from a security standpoint is if someone is able to exploit a client and then turn on the teredo service to register the client machine via IPv6 to a third party Teredo relay. They could easy pass all the command control portions over IPv6, have unfiltered access to the machine and have unrestricted access to many networks behind commercial firewalls providing NAT/PAT services.

I hope the days of people thinking that NAT/PAT devices provide any security are quickly at an end (finally) due to the transition technologies like Teredo that make bypassing a NAT/PAT device just way to easy. All the major torrent services use similar methods so anyone who thinks you can't share content this way is ignoring the facts. Application aware firewalls and host based firewalls are the only way to control traffic now. Microsoft has done the first step to address this with the Advanced Firewall and AD GPO policy pushes. They are introducing the second phase next with their Forefront client software suite to allow even more management and policy options through System Center. I think this will be critical for enterprises, especially those that are adopting virtualization and remote desktop configurations.

So, what are the benefits of running Teredo services? Why would Microsoft have enabled the service and let applications decide when they need unfettered access to the IPv6 network? I believe it is to address the needs of home users trying to connect multiple devices behind NAT/PAT home consumer grade network devices (Linksys, Netgear and the like) and then wanting to share the content and access their network from the public Internet. While perhaps this is awhile off in terms of a common deployment many companies are already providing similar services. Slingbox, GoToMyPC, torrents, and other file sync sites all could leverage Teredo and IPv6 to make the process work easier than it current is doing today. Instead of having a central proxy control server hosts could be directly connected with the home or work host they need content from, a novel idea. In addition, a machine could have a consistent IPv6 address all the time via the Teredo server regardless of what IPv4 network it is on, not a bad function in terms of getting content from a host and knowing you have the right one.

What I am not happy with is the lack of any intuitive interface within the GUI to tell you if Teredo is actually on or not. There is no way outside of command line that I am aware of to know if Teredo is enabled. It would seem like a simple enough process to add a small control applet to let people know if Teredo is enabled/disabled and if it is currently being used or not. This would go a long way to allowing folks to control this basic transition service.

I guess I will ask what Microsoft was thinking regarding this while I have their ear over the next few days and report back.
- Ed

Friday, February 12, 2010

Follow up from last night's EBCUG - IPv6 and Teredo

At last nights EBCUG meeting there was a very lively debate regarding Microsoft and Teredo and what the OS's are and are not doing by default with Teredo. To clear up some of the items I wanted to provide some links and information.

First, Microsoft has some pretty good write ups on IPv6 and Teredo specifically and what they have implemented. As you can see on the Teredo page they specifically outline when IPv6 and Teredo are enabled by default and when they are not. The Teredo write up is quite extensive and goes over all the methods for NAT traversal. You can also find a good transitions document from Microsoft regarding all the IPv6 transition technologies. To clear up what is and is not on by default the document says the following:
"Teredo support is included and is disabled by default. Teredo support is included with Windows Server 2008, Windows Server 2003 Service Pack 1 and later, Windows XP with SP2 and later, and Windows XP with SP1 and the Advanced Networking Pack for Windows XP, and is disabled by default. Teredo support is also included with Windows Vista and is enabled but inactive by default. "

For those with Windows XP SP2 that are concerned about running Teredo the Windows Firewall does protect against unsolicited incoming IPv6 traffic just like for IPv4. To set up Teredo on Windows XP SP2 you need to install IPv6 with the netsh interface ipv6 install command and then enable Teredo with the netsh interface ipv6 set teredo client command. But by default Teredo is not enabled on XP.

For Windows Vista and 7 (and Windows Server 2008 and 2008R2) it is possible to disable IPv6 (not uninstall it) by using the instructions at this KB article.

If you are running Windows Vista, 7 or Server 2008 then switch to powershell commands. If you want to see what Teredo is doing you can issue under powershell netsh interface teredo show state which should have output something like:
PS C:\> netsh interface teredo show state
Teredo Parameters
---------------------------------------------
Type : client
Server Name : teredo.ipv6.microsoft.com.
Client Refresh Interval : 30 seconds
Client Port : unspecified
State : offline
Error : client is in a managed network

You can also use the netsh interface ipv6 show teredo powershell command to see the same information.

If you want to set the state for Teredo you can do netsh interface teredo set state disabled to turn off Teredo. Sample command parameters are:
PS C:\> netsh interface teredo set state ?

Usage: set state [[type]=disabled|client|enterpriseclient|server|default]
[[servername=]||default]
[[refreshinterval=]|default]
[[clientport=]|default]
[[servervirtualip=]|default]

Parameters:

Tag Value
type - One of the following values:
disabled: Disable the Teredo service.
client: Enable the Teredo client.
enterpriseclient: Skip managed network detection.
server: Enable the Teredo server.
default: default state is client.
servername - Name or IPv4 address of the Teredo server.
refreshinterval - Client refresh interval (in seconds).
clientport - Client's UDP port (otherwise chosen by system).
servervirtualip - IPv4 address of the server virtual ip.
Not applicable if running as teredo client.

Remarks: Sets Teredo state.
A 'default' argument to a parameter sets it to the system default.
The 'type=server' option only works on server skus.

Examples:

set state disable
set state client teredo.ipv6.microsoft.com 60 34567

For a lot more details about the netsh commands check out this Technet Library entry.

It is true that the default Teredo servername parameter is set to teredo.ipv6.microsoft.com which is actually a CNAME which points to teredo.ipv6.microsoft.com.nsatc.net. which resolves to 65.55.158.80. If you are truly concerned about any hosts on your network building out Teredo services to Microsoft without your knowledge simply block traffic to that IP address. You can also optionally poison the DNS name in your local name servers.

For IT professionals running AD you can set up a GPO to disable Teredo though I believe by default Teredo will stay in a disabled state if it sees that your machine is domain joined.

Hope that helps clear up and provide some resources on Teredo. It was a great meeting and very interesting talking to everyone about IPv6 and what is happening with it.
- Ed