IPv6: Ready or Not

With a government mandate and Vista support, IPv6 is here-security gotchas, missing support and all.

Way to go, vendors of low-end routers and intrusion detection and prevention systems—youre a stumbling block on Bechtels path to the next-generation Internet.

"Were doing [both IPv4 and the next-generation IPv6 networks], and we anticipate doing both for a number of years," said Fred Wettling, a Bechtel Fellow who manages technology standards and is sponsoring the enterprise IPv6 challenge within Bechtel. "This creates a challenge from the security standpoint of making sure the security mechanisms will do tracking [and] protection on both v4 and v6 concurrently."

The problem, he said, is that "some people making security products are not quite there yet," with "there" meaning product support of native IPv6 connectivity. "Thats kind of frustrating."

Why does Bechtel want IPv6? Imagine the company rapidly deploying employees to New Orleans in the wake of Hurricane Katrina, which the construction outfit in fact did. With the vast IP addressing space IPv6 has ushered in—its main draw—and its ability to turn every notebook, cell phone or other IP-enabled gadget into a server on the peer-to-peer network that IPv6s endpoint-to-endpoint architecture enables, post-Katrina recovery would have been markedly different. For example, trailers could have been connected to each other dynamically once the IP cloud was established, with no work required from Bechtels IT people.

Its not pie in the sky. IPv6 is here, now. Europe and Asia are roughly tied in the total number of IPv6 addresses they have per capita, said Wettling, based in Oak Ridge, Tenn., and a member of the North American IPv6 Task Force and executive director of the IPv6 Business Council. Also, the U.S. governments Office of Management and Budget has mandated that the federal government—including agencies and contractors—transition by June 2008.

Perhaps most notably for North American enterprises that havent yet dabbled in IPv6, Microsoft is serving up the technology in Windows Vista and "Longhorn," with a protocol to tunnel IPv6 traffic over IPv4—a transition technology to compensate for security and network perimeter device vendors lag time in supporting the new protocol.

IPv6 is now here, and so are its security issues. It is a nightmare scenario for any security officer, according to multiple sources, including Charles Lee, chief technology officer for Verizon Federal—the group within Verizon Business dedicated to serving federal government customers.

"I think that the tipping point has been reached," said Lee in Washington. "What I point to as the killer app is VOIP [voice over IP]. There are huge market forces around untethered voice service: PDA-enabled cell phones and so on. Untethered assets are a real market force. In order for those applications to behave well and work in a broad environment, they need v6 capability. V6 is here. The cell phone folks have already set up address allocations: Nokia reserved 500,000 addresses for itself, [and the] chips have been introduced [that] will enable the next generation of services."

/zimages/3/28571.gifeWEEK Labs Cameron Sturdevant says the switch to IPv6 will be an onerous transition for most IT managers. Click here to read more.

In other words, consumers are either using it now or will use it in the next 12 to 18 months, Lee said. What that will look like to your network is this, he said: "You can do P2P so much easier. Instead of me having to directly access some central repository, I may be able to send information from my cell phone to yours, bypassing any other tracking or storage device in the middle of the network, and thereby have complete security in the course of moving this information."

Yes, IPv6 brings security—or obfuscation, as the case may be—to moving information. One notable feature of IPv6 is that it puts encryption into the hands of the user. Were an IPv6 user to illicitly collect data, he or she could pass it off, without network perimeter security checks able to look inside its encrypted contents, to another peer on IPv6—an accomplice who could be anywhere. "And youve just laid out the nightmare scenario for any security officer," Lee said.

The industry already is facing those challenges, Lee said. "Its not uncommon for security people to be very concerned with data integrity and keeping proprietary data under lock and key, and often we miss the fact that the guy who just walked in has a camera in his cell phone," he said.

The security challenges P2P presents exist today, but theyll be more obvious when IPv6 walks through your enterprises door, Lee said, because "new generations of capabilities will be sitting on peoples hips."

Tunneling is another security implication. Symantec in November first brought up the security implications of Microsofts Vista and the upcoming Longhorn server using the Teredo protocol for tunneling IPv6 over IPv4 networks. Again, the potential security implications of Teredo concern the inability of perimeter devices to see inside packets. IDSes (intrusion detection systems) are generally good at inspecting TCP and UDP (User Datagram Protocol) traffic, which are the traditional protocols that transport Web and e-mail requests. If attacks on a system are tunneled, however, theyll be invisible to IDSes.

/zimages/3/28571.gifClick here to read more about Symantecs fears that Vistas use of Teredo is potentially insecure.

"Any security device needs to be aware of Teredo in order to look into it and analyze traffic traveling over it," said Oliver Friedrichs, director at Symantecs Security Response team, in Mountain View, Calif. "For enterprises, this presents, obviously, a serious concern. Attackers can, for one, tunnel through perimeter devices without being seen and tunnel attacks over [Teredo] without being seen by perimeter devices."

Such perimeter devices include firewalls and low-end routers, such as those from Linksys. "The firewall is traditionally there to filter traffic, but with Teredo its rendered in many cases ineffective," he said.

Next Page: Bechtel wont touch Teredo.