Elective Advanced Networking with IPv6

Advanced Networking with IPv6Unit 611 min read

IPv4/IPv6 Transition: Mechanisms, Tunnels, Dual Stacks

Unit 6 of Advanced Networking with IPv6 covers how IPv4 and IPv6 networks coexist and migrate, focusing on dual-stack, tunneling (6to4, ISATAP, Teredo), translation (NAT64, DNS64), and real-world deployment challenges like eSewa’s payment routing and Ncell’s mobile data handoffs.

TAKEAWAYS:

  • IPv4/IPv6 transition mechanisms enable backward compatibility while deploying IPv6, using techniques like dual-stack, tunneling, and translation.
  • Dual-stack runs both protocols simultaneously on hosts/routers, while tunneling encapsulates IPv6 in IPv4 (or vice versa) for transport.
  • Translation (NAT64/DNS64) bridges IPv4-only services (e.g., legacy web servers) to IPv6 clients without full IPv6 deployment.
  • 6to4, ISATAP, and Teredo are tunneling protocols with trade-offs in scalability, security, and NAT traversal.
  • Real-world examples include eSewa’s payment gateways (dual-stack for legacy bank integrations) and Ncell’s mobile networks (NAT64 for IPv4-only towers).
  • Exam questions test mechanism selection, packet encapsulation traces, and configuration scenarios (e.g., configuring a 6to4 tunnel).

Core Concepts: Why Transition?

IPv4’s 32-bit address exhaustion (4.3 billion addresses) and IPv6’s 128-bit scalability (340 undecillion) demand coexistence. Transition mechanisms solve three key problems:

  1. Backward compatibility: IPv6-only devices must communicate with IPv4-only networks.
  2. Gradual deployment: Organizations cannot rip-and-replace overnight.
  3. Cost efficiency: Avoid deploying new infrastructure before IPv6 is widely adopted.

The Transition Spectrum

Transition methods fall into three categories:

mindmap
  root((IPv4/IPv6 Transition))
    Dual-Stack
      "Both protocols run side-by-side"
      "Hosts/routers support IPv4 and IPv6"
    Tunneling
      "Encapsulate IPv6 in IPv4 (or vice versa)"
      6to4["6to4: IPv6 over IPv4 (public anycast relays)"]
      ISATAP["ISATAP: IPv6 over IPv4 (private intranets)"]
      Teredo["Teredo: IPv6 over UDP (NAT traversal)"]
    Translation
      "Convert between IPv4 and IPv6"
      NAT64["NAT64: IPv4 <-> IPv6 address/port mapping"]
      DNS64["DNS64: Synthetic IPv4 addresses for IPv6 clients"]

1. Dual-Stack: Running Both Protocols

Definition: A host or router simultaneously supports IPv4 and IPv6, allowing communication with both networks. No translation or tunneling is needed between the two stacks.

How It Works

  • Hosts: Applications bind to IPv4 or IPv6 sockets (e.g., socket(AF_INET6) in Linux).
  • Routers: Forward packets based on protocol (IPv4 or IPv6 headers).
  • No encapsulation: Packets travel natively in their protocol.

Real-World Example: eSewa’s Payment Gateway

eSewa’s backend servers use dual-stack to:

  1. Accept IPv6 payments from modern mobile apps (Nepal Rastra Bank’s IPv6-enabled POS).
  2. Route legacy IPv4 transactions to older bank systems (e.g., NMB Bank’s IPv4-only servers).
  3. Worked Example:
    • A user pays via Khalti (IPv6) → eSewa’s dual-stack server forwards the request to Global IME Bank (IPv4) using the IPv4 stack.
    • Response travels back via IPv6 to the user’s device.

Advantages/Disadvantages

Pros Cons
Simple to implement Requires dual-stack infrastructure
No packet overhead IPv4 exhaustion still a risk
Full performance for both protocols Legacy devices may not support IPv6

Configuration Example (Linux)

# Enable IPv6 on an interface
sudo ip -6 addr add 2001:db8::1/64 dev eth0

# Test connectivity to an IPv6-only server (e.g., Google DNS)
ping6 2001:4860:4860::8888

dual stack networking diagramDual-stack router forwarding IPv4 and IPv6 packets side-by-side. (Image: AKRAM.ABOU, CC BY-SA 3.0, via Wikimedia Commons)


2. Tunneling: Encapsulating IPv6 in IPv4

Definition: IPv6 packets are encapsulated inside IPv4 packets (or vice versa) to traverse IPv4-only networks. Used when full dual-stack isn’t feasible.

Three Key Tunneling Methods

A. 6to4 (RFC 3056)

  • Purpose: Automatically create IPv6-over-IPv4 tunnels using anycast relays.
  • How it works:
    1. IPv6 address format: 2002:<IPv4_address_in_hex>::/48 (e.g., 2002:c058:6301::/48 for IPv4 192.88.99.1).
    2. Packets are sent to 6to4 relays (e.g., 192.88.99.1 for Google’s relay).
    3. Relays decapsulate and route IPv6 packets globally.
  • Use Case: ISPs or enterprises with IPv4 infrastructure but needing IPv6 connectivity.

B. ISATAP (Intra-Site Automatic Tunnel Addressing)

  • Purpose: IPv6-over-IPv4 tunneling within a private network (e.g., corporate intranet).
  • How it works:
    1. IPv6 address format: fe80::<IPv4_address> (e.g., fe80::192.168.1.1).
    2. Uses broadcast/multicast to discover ISATAP routers.
    3. Encapsulates IPv6 in IPv4 for internal routing.
  • Use Case: Microsoft Windows networks transitioning to IPv6.

C. Teredo (RFC 4380)

  • Purpose: IPv6-over-UDP for NAT traversal (e.g., home users behind NAT).
  • How it works:
    1. Uses UDP port 3544 to bypass NAT.
    2. IPv6 address format: 2001:<32-bit_UDP_port>:<32-bit_UDP_port>:<32-bit_interface_ID>.
    3. Relies on Teredo servers (e.g., Microsoft’s tunnel.teredo.net).
  • Use Case: Gamers or remote workers needing IPv6 behind NAT (e.g., Pathao drivers using IPv6 apps).

Comparison Table

Feature 6to4 ISATAP Teredo
Scope Public internet Private intranet NAT traversal
Address Format 2002::/16 fe80::/64 2001::/32
Relay Needed Yes (anycast) No (router-based) Yes (Teredo servers)
NAT Support No No Yes
Security Vulnerable to MITM Secure (private) Encrypted (optional)

Worked Example: 6to4 Tunnel Setup

Scenario: A university lab (IPv4: 192.168.1.0/24) wants IPv6 connectivity.

  1. Assign a 6to4 IPv6 prefix: 2002:c0a8:100::/48 (derived from 192.168.1.0).
  2. Configure a 6to4 relay (e.g., Google’s 192.88.99.1).
  3. Encapsulate an IPv6 packet from 2002:c0a8:100::1 to 2001:db8::1:
    • IPv4 header: 192.88.99.1 (relay) → 192.168.1.100 (lab router).
    • Payload: Original IPv6 packet (2002:c0a8:100::1 → 2001:db8::1).


3. Translation: Bridging IPv4 and IPv6

When full dual-stack or tunneling isn’t possible, translation converts addresses/ports between protocols.

A. NAT64 (Network Address Translation)

  • Purpose: Allow IPv6-only clients to access IPv4-only servers (and vice versa).
  • How it works:
    1. IPv6 address is translated to a synthetic IPv4 address (e.g., 64:ff9b::192.0.2.1 → 192.0.2.1).
    2. Ports are mapped to ensure return traffic reaches the correct client.
    3. Uses DNS64 to rewrite DNS responses (see below).

Real-World Example: Ncell’s Mobile Data

Ncell’s 4G towers are mostly IPv4-only, but newer devices use IPv6. NAT64 enables:

  • IPv6 smartphones → NAT64 → IPv4 tower → Internet.
  • Worked Example:
    • A user on an IPv6 phone visits http://example.com (IPv4-only).
    • DNS64 returns 64:ff9b::192.0.2.46 (synthetic IPv6 for 192.0.2.46).
    • NAT64 translates the request to IPv4 and forwards it to the server.

B. DNS64

  • Purpose: Extend DNS to return synthetic IPv6 addresses for IPv4-only services.
  • How it works:
    1. IPv6 client queries DNS for example.com (A record).
    2. DNS64 returns a AAAA record in the format 64:ff9b::<IPv4_address>.
    3. Client sends traffic to NAT64, which translates it to IPv4.

NAT64/DNS64 Workflow

sequenceDiagram
    participant IPv6Client
    participant DNS64
    participant NAT64
    participant IPv4Server
    IPv6Client->>DNS64: Query AAAA for example.com
    DNS64-->>IPv6Client: Return 64:ff9b::192.0.2.46
    IPv6Client->>NAT64: Send packet to 64:ff9b::192.0.2.46
    NAT64->>IPv4Server: Translate to IPv4 (192.0.2.46)
    IPv4Server-->>NAT64: Reply
    NAT64-->>IPv6Client: Translate back to IPv6

Advantages/Disadvantages

Pros Cons
No need for dual-stack everywhere Performance overhead
Works with legacy IPv4 services Complex configuration
Enables gradual IPv6 adoption Limited to TCP/UDP (not ICMP)


4. Transition Mechanism Selection Guide

Choose a mechanism based on network scope, cost, and requirements:

Scenario Recommended Mechanism Why?
Enterprise with IPv4 infrastructure Dual-stack + 6to4 Scalable, no NAT issues
Home user behind NAT Teredo NAT traversal support
Private corporate intranet ISATAP No public relays needed
Public ISP needing IPv6 Dual-stack + native IPv6 Future-proof, no tunneling overhead
Legacy IPv4-only services NAT64 + DNS64 Bridges IPv6 clients to IPv4 servers

5. Real-World Deployment Challenges

Case Study: Nepal’s NTC and IPv6

Nepal Telecom (NTC) deployed IPv6 in phases:

  1. Dual-stack on core routers: Handled both IPv4 (for legacy NLDs) and IPv6 (for new 4G/5G).
  2. 6to4 for rural areas: Used anycast relays to provide IPv6 to IPv4-only villages.
  3. NAT64 for VoIP: Enabled IPv6 smartphones to call IPv4-only PSTN lines.
  4. Challenge: Some ISPs (e.g., Smart Telecom) resisted due to additional hardware costs.

Case Study: Daraz’s Global Logistics

Daraz’s Nepal warehouse uses:

  • Dual-stack for internal tracking systems (IPv6 for IoT sensors, IPv4 for legacy ERP).
  • NAT64 to connect IPv6-enabled delivery drones to IPv4 GPS servers.
  • 6to4 for backup connectivity during IPv4 outages.


Exam Tip: How This Unit Is Tested

  1. Mechanism Identification:

    • Given a scenario (e.g., "A home user behind NAT wants IPv6"), select the correct transition method (Teredo).
    • Common traps:
      • Confusing 6to4 (public) with ISATAP (private).
      • Forgetting NAT64 requires DNS64.
  2. Packet Traces:

    • Draw or describe how a packet travels through a tunnel (e.g., 6to4 encapsulation).
    • Example question:

      "Show the encapsulation of an IPv6 packet 2001:db8::1 → 2001:db8::2 over a 6to4 tunnel. What is the outer IPv4 destination?" Answer: Outer IPv4 header uses 192.88.99.1 (6to4 relay) as destination.

  3. Configuration Questions:

    • Write commands to enable dual-stack or configure NAT64 (Linux/Cisco).
    • Example:
      # Enable NAT64 on Linux (using `dnsmasq`):
      echo "port=53" >> /etc/dnsmasq.conf
      echo "enable-ra" >> /etc/dnsmasq.conf
      echo "dhcp-range=::100,constructor:eth0,ra-only" >> /etc/dnsmasq.conf
      
  4. Comparison Tables:

    • Compare 6to4 vs. ISATAP vs. Teredo (address format, use case, relay dependency).
    • Compare NAT64 vs. Dual-Stack (performance, compatibility).
  5. Scenario-Based:

    • "Ncell wants to provide IPv6 to its IPv4-only towers. Which mechanism is best and why?"
    • Answer: NAT64 + DNS64 (bridges IPv6 clients to IPv4 towers without dual-stack).

Top 3 Exam Pitfalls to Avoid

  1. Assuming all tunneling methods work behind NAT: Only Teredo supports NAT traversal.
  2. Ignoring DNS64 for NAT64: NAT64 alone won’t work without DNS64 rewriting AAAA queries.
  3. Overlooking security: Tunneling (e.g., 6to4) is vulnerable to MITM attacks unless encrypted (e.g., IPsec).

Based on the TU BSc CSIT syllabus for Advanced Networking with IPv6, unit 6.

Discussion

Loading…