IPv6 on the dotted line

 

Connecting state and local government leaders

The time is right for RFPs to address IPv6; here's what you need for the transition.

When it comes to implementing Uncle Sam's next-generation Internet, the clock is ticking.The Office of Management and Budget has mandated that the Internet backbone for every federal agency must be able to run Internet Protocol version 6 by June 30, 2008. By now, agencies are required to have created an IPv6 transition team, completed an inventory of all backbone-dependent hardware and software, and submitted an analysis of how the transition to IPv6 will impact their organizations.No matter where they are in this timeline, the next step will be to procure the products and services for actual implementation.'We've seen a few fresh contracts in a few arcane areas,' said Walt Grabowski, senior director of telecommunications for SI International, a contractor overseeing the Defense Department's transition to IPv6. 'The Air Force Communications Agency actually had a procurement about a year ago and [Veterans Affairs] is planning something soon for transition support. So it's been spotty ... but in general, the support that agencies get right now comes from the contractor base they already have in place.'Experts say that could change, in part because agencies are being asked to make changes more quickly than they're used to. But it's also because IPv6 has the potential to affect how government operates in ways no one can yet predict, said Peter Tseronis, director of network services for the Education Department.'It's like the Internet was back in 1993,' Tseronis said. 'Back then, you'd never have imagined you'd be using it to do your banking. IPv6's mobility, end-to-end security and ad hoc networking capabilities sound wonderful, but the truth is, we don't really know yet what it will ultimately enable us to do.'DOD is leading the pack in IPv6 adoption. But some agencies are struggling to meet OMB's unfunded mandate. Transitioning to IPv6 involves more than merely refreshing network infrastructure; it touches everything from training and testing to consulting services and software development. In fact, IPv6 could impact every technology RFP an agency writes for the next 10 years.Observers say the money to accomplish agencies' immediate IPv6 goals is just starting to shake loose. 'I don't see agencies having the expertise to do this themselves,' said Dave Nelson, a consultant for Input Inc. of Reston, Va., and former deputy CIO at NASA. 'Even DOD has found it's a little harder than they thought.'Major networking vendors such as Cisco and Juniper have been shipping IPv6-compatible gear for several years now. Microsoft Corp.'s upcoming Vista operating system is designed with it in mind. But other hardware and software might not be ready yet. And even if a vendor's routers and switches run IPv6, its hardware firewalls and security appliances might not.'There's still a lot of brochure-ware out there,' said Tom Patterson, CEO of Command Information, an IPv6 services company in Herndon, Va. 'A number of companies advertise their products as v6-capable, but when you try to buy them, you find out that v6 support is still in the pipeline.'Several groups have tried to help agencies define 'IPv6-capable' as it applies to the products they must be using. Juniper Networks published a report in May, IPv6 Capable: A Guide for Federal Agencies [GCN.com/647]. That same month, DOD released a detailed document, IPv6 Standard Profiles for IPv6 Capable Products.If the hardware you're buying today isn't IPv6-compatible, you'd better have an agreement with the vendor to include the upgrade in the purchase price, said Tseronis.But the transition from today's IPv4 to IPv6 won't happen overnight. Agencies will need to operate dual IPv4 and IPv6 networks for many years to come, until all their hardware and applications is IPv6-compliant. Even then, they'll need to communicate with devices on the Net that still use IPv4'either by translating from IPv6 to IPv4 and back again, or 'tunneling' IPv6 packets through the older network.Many agencies will likely run a dual stack, where both protocols run simultaneously on the same equipment, Grabowski said. But agencies shouldn't assume all IPv6 networking gear can run two stacks right out of the box.'If I were acquiring network equipment, I'd ask the vendors to demonstrate that their systems can operate in a dual-stack environment,' Grabowski said. 'I'd ask what's required to run in a dual stack. Do I need to increase router memory because of the dual stack? Will they work with my existing devices? Show me that upgrading my device is not going to lead me to a dead end in a v6 world.'Another key issue is interoperability among IPv6 devices from different manufacturers, said Grabowski.Though various agencies may have lists of approved IPv6 equipment, there's no guarantee an IPv6-compliant router from Company A will work seamlessly with a switch from Company B.'It's not that vendors want to be incompatible,' he said. 'It's just that whenever you have a new standard, vendors have to interpret what it is, and sometimes they do it differently. Most v6 devices should be almost interoperable, but 'almost' isn't where an agency wants to be.'So far, a handful of vendors have qualified under the IPv6 Ready logo program, bestowed by the IPv6 Consortium and the University of New Hampshire's Interoperability Lab [see , GCN.com/645]. The logo signifies that a vendor's equipment conforms to IPv6 requirements and can interoperate with at least two other hosts or routers.'There's not a 100-percent guarantee all of the boxes on our list will interoperate, but I'd be surprised if they didn't,' said Benjamin Schultz, managing engineer of UNH's Interoperability Lab.Compliance and compatibility testing will need to be a key part of any transition plan, and agencies will probably need help in testing products and making sure everything works together.Whether they choose their networking vendors, system integrators, outside consultants or some combination of the three help depends largely on the vendor agreements already in place, said Tim LeMaster, director of systems engineering for Juniper Federal Systems.'Some agencies may find their maintenance support contracts with Integrator X or Service Provider Y already provide v6 transition services,' LeMaster said. 'If they don't, they may want to look toward an outside consultant.'System integrators may also offer ad hoc software development'providing the 'glue code' that allows everything to work seamlessly, Patterson said. For example, Command Information recently completed a universal translator for DOD that allows any Net-enabled remote device'whether it's a mobile phone or a sensor embedded in the walls of a warehouse'to tunnel across the IPv4 network and communicate with DOD's IPv6 backbone.According to a June 2006 survey by Cisco Systems and Market Connections Inc., roughly half of 200 government IT managers surveyed said they wouldn't be moving to IPv6 if OMB weren't forcing the issue. In other words, they either don't see the benefits of IPv6 or don't believe the benefits are worth the costs.'I think a big problem right now is that program managers are in compliance mode,' said Gunderson. 'There's probably a standard clause in every RFP that says the vendor's products must be IPv6 compliant. But instead of making it merely a compliance issue, they should go to the technologists in their organizations and ask, 'How do we expand the RFP?' 'In fact, a search of the contract database of market research firm Input Inc. turns up only about 25 vehicles, either in the proposal or execution phases, that spell out IPv6 requirements. Only one contract, a Veterans Affairs Department RFP that's due out next year, deals specifically with the current IPv6 migration.In the meantime, agencies would do well to set aside a portion of their budget for IPv6 training and education, and not just for network administrators, said Command Information's Patterson, whose firm also operates an IPv6 education center.Agency managers need to get up to speed on IPv6 so they can plan for applications that take advantage of the benefits the next-generation Internet will bring. And other personnel need to know what the new network will look like so they can do their jobs better.The key is finding instructors who have experience working with actual IPv6 networks, said Patterson. And that means looking overseas, where IPv6 development is generally much further along.'This is not something you can just read out of a book and go teach,' Patterson said. 'The good news is that other parts of the world have been doing v6 a lot longer than we have. We've hired a number of people who worked on IPv6 projects in Korea, China, Japan and France.'A mistake many organizations make is trying to create an RFP based on generic requirements, or things they've read about but don't really need, said Juniper's LeMaster.'The most important part of creating an RFP is to understand your network and write requirements that support it,' he said. 'Don't add requirements just because Agency X is planning to deploy a certain service.'Agencies should look for vendors who take a lifecycle approach to the IPv6 transition and will support them over the long haul, said Prem Jadhwani, senior product manager for GTSI, a systems aggregator in Chantilly, Va.Because moving to IPv6 typically involves a long-term investment, he suggests cash-strapped agencies might even ask vendors if they're willing to help with financing.Most important, agency managers must understand that making their backbones IPv6-compliant is only the beginning of a long process that will eventually bring their networks into the 21st century.'This isn't going to end on June 30, 2008, and it's a mistake to think it will,' warns Tseronis. 'We've got at least 10 more years of development to go on IPv6. We've got to get the energy behind it.'

IPv6 transition

Agencies may be a bit behind in their transition to IPv6, but if they're going to meet the June 2008 deadline, the time for seeking help is now. 'Figure it takes about six months to plan the transition and a year to finish it,' said Ray Williams, manager of networks and enterprise architectures at Northrop Grumman IT. Working backward, that means heavy engagement starts now. Here are some issues that agencies should be considering as they draft requests for proposals.

  • Ask your vendors and contractors if they offer technical training or other educational curricula as part of the service contract. Do they offer training for just network administrators, or are there courses aimed at nontechnical personnel? Do their instructors have experience installing an IPv6 network?

  • How does the vendor define IPv6-capable [GCN.com, GCN.com/647]? Does that definition jibe with government's definition, such as DOD's [GCN.com/637]?

  • Odds are you'll be operating in a dual IPv4/IPv6 environment for many years to come. How do the vendor's routers and switches perform in a dual-stack environment?

  • Will dual-stack machines require more memory in order to avoid throughput issues? Do they interoperate easily with both IPv4 and IPv6 devices and applications?

  • Does your vendor offer devices that enable you to translate from IPv4 to IPv6 and back again, or tunnel through IPv4 networks?

  • Has the gear been certified by an agency-approved testing service? Does it carry the IPv6 Ready logo [GCN.com/645]?

  • If the gear is for a military application, can the vendor demonstrate that it meets the Defense Department's Net Ready Key Performance Parameters?

  • Ask vendors how your approach to security will change with respect to IPv6. Does its gear conform to IPsec requirements?

  • Does your vendor offer hardware firewalls and intrusion detection systems that are IPv6-compliant? If not, does the vendor have a road map toward IPv6 compatibility?

  • Look for a systems integrator that approaches the IPv6 transition from a lifecycle management perspective, offering a full range of services from initial planning to implementation to support.

  • Does your systems integrator provide compatibility or interoperability testing? Does it offer software development services?

  • Does the contractor have the right certifications for the equipment you'll be buying?

  • Ask your vendor what business process improvements you should be looking for from IPv6.

  • If your budget is constrained, ask vendors if they're willing to help the agency finance the purchase of new equipment and services.
















  • Gearing up




















    GCN.com,

    No guarantees



















    A high-speed education



















    Dan Tynan is author of Computer Privacy Annoyances (O'Reilly Media, 2005).

    NEXT STORY: Apps are put to the test

    X
    This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
    Accept Cookies
    X
    Cookie Preferences Cookie List

    Do Not Sell My Personal Information

    When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

    Allow All Cookies

    Manage Consent Preferences

    Strictly Necessary Cookies - Always Active

    We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

    Sale of Personal Data, Targeting & Social Media Cookies

    Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

    If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

    Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

    Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

    If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

    Save Settings
    Cookie Preferences Cookie List

    Cookie List

    A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

    Strictly Necessary Cookies

    We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

    Functional Cookies

    We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

    Performance Cookies

    We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

    Sale of Personal Data

    We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

    Social Media Cookies

    We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

    Targeting Cookies

    We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.