Just a guy in Vermont trying to connect all the dots...
Author's posts
Sep 30
Lesson Learned The Hard Way – Google+ Hangouts On Air …
(Good lesson that I shouldn't be posting articles at 1:00am! But leaving this post up here for a bit because there are now social media links out there pointing to this URL...)
Sep 30
Live Streaming ION Krakow Over IPv6 – Using Google+ Hangouts or YouTube Live
We’re doing something a little different (and risky) with our live streaming of ION Krakow today out of Krakow, Poland. Instead of using our “regular” method of live streaming using the Internet Society’s Livestream.com account, we’re trying out a Google+ Hangout On Air (HOA) which will simultaneously broadcast the session live on our Deploy360 YouTube channel. You should be able to watch the live webcast on either:
Why are we doing this? Primarily because we accepted the challenge by Wes George on Twitter to “eat our own dogfood” and see if we could get livestreaming going out over IPv6.
Live streaming over IPv6
Livestream.com is currently IPv4-only and so we went looking at other options. Without setting up our own server infrastructure, the two possible options that we’ve found seem to be:
I say “possible” because this will be our first test and we’re not honestly entirely sure whether the broadcast will go out over IPv6. It turns out that PLNOG only has an IPv4 network and so our connection back to Google’s servers will be IPv4. In theory, Google’s content distribution network (CDN) should then serve the video streams out over IPv4 or IPv6. We’ll see (and we’d like your help – see below).
As far as the two services, YouTube Live was of most interest to me when testing because it allows us to schedule an event in advance and promote that URL – and then have the video go live at that URL at the appointed time. However, I was unable to get my software to work consistently with YouTube Live (and didn’t have a whole lot of time to test).
I’m going instead with a Google+ Hangout On Air because the video chain worked well and it also broadcasts over on our YouTube channel. So people should be able to see the livestream on either Google+ or on YouTube – and shouldn’t have to login to see the stream, at least on YouTube.
The downside of a Google+ HOA is that you can’t set up a URL that you can promote in advance. We have to wait until we go live this afternoon here to have a URL we can publicize. So instead we have to tell people to watch our Google+ page and YouTube channel… which is okay but not ideal.
How You Can Help – Show Us It’s IPv6
We’d like to prove that today’s live stream is going out over IPv6… but we’re here at PLNOG on a IPv4 network, so we have no way of knowing. What we’d love is if some of you out there who are running the IPvFoo or IPvFox browsers add-ons/extensions could capture some screenshots and let us know as a reply to a post on our Google+ page. What I am looking for is something like this:
That can show which of the various connections are using IPv6.
If you are interested in helping, please monitor this post on our Google+ page so that you can see if others have already sent some in. We would appreciate several different screenshots (but we don’t need 100!
).
And if it turns out that we don’t see any streaming over IPv6… well… it will be worth the attempt – and we will figure this out eventually!
The Technical Setup
For those curious, I’m using a Canon Vixia camera connected via HDMI to a Blackmagic Intensity Extreme box that connects into my MacBook Pro. On my MBP I’m running Wirecast software as an encoder that will then broadcast out to Google+. I also have a Logitech HD webcam ready as a standby. I have a feed coming into my camera from the house audio so that I’m getting the event microphones. I’m then monitoring the audio from headphones connected to my MBP.
And, being paranoid about ensuring I capture the content, I’m recording the video stream locally on my MBP as a backup.
We’ll see… let the grand experiment begin in about 3.5 hours…
Sep 30
FIR #723 – 9/30/13 – For Immediate Release
Sep 26
How To Securely Transfer A DNSSEC-Signed Domain Between DNS Operators – SIDN’s EPP Keyrelay
What happens if you want to transfer a DNSSEC-signed domain from one DNS operator to another? Perhaps you are consolidating domains into one operator… or the new operator has better security… or is less expensive…
It turns out that there has not been an easy way to do this while ensuring that the DNSSEC “chain-of-trust” remains intact. If the old DNS operator (often referred to as the “losing operator” when talking about domain transfers) just stops serving DNS records, the new DNS operator (referred to as the “gaining operator“) can start serving DNS records – but there will be a time delay while a new DS record is recorded in the registry for the top-level domain (TLD) for whatever domain is being transferred. During that time, validation would fail because the DNSSEC records being served would not match the DS record contained in the TLD registry. This might only be a brief period of time… but as we start using DNSSEC more widely – and particularly for services like DANE that provide added integrity to SSL interactions – keeping the domain “always secure” will become increasingly important.
One solution that has been suggested – and successfully demonstrated! – is that of “EPP keyrelay” proposed by SIDN, the registry operator for .NL. Antoin Verschuren from SIDN Labs wrote up this solution in a document titled “EPP keyrelay: solving the last obstacle for DNSSEC deployment” (PDF). The mechanism has also been submitted as an Internet Draft to the IETF as: draft-gieben-epp-keyrelay.
Essentially, the mechanism introduces a new command into the Extensible Provisioning Protocol (EPP) used by DNS operators, registrars and registries and uses registry as a broker to transfer DNSSEC key information from the new DNS operator to the old DNS operator as part of the transfer process.
The document and Internet-Draft do indeed present an interesting solution to this challenge of domain transfer. Both are being discussed within the larger DNSSEC and DNS community – and I know that Antoin and the team at SIDN Labs would welcome further feedback – and implementation, of course! It’s great to have SIDN Labs providing a solution and we look forward to seeing how this work evolves – we definitely do need to ensure that domains can remain “always secure”, even when being transfered.
Sep 26
TDYR #038 – Heading To Poland And Ukraine For ION Krakow And ENOG 6
Sep 26
Renesys Chronicles Today’s Internet Blackout in the Sudan (Now Restored) (Featured Blog)
Sep 25
2 Excellent New Tutorials On IPv6 Address Planning From ISOC and SURFnet
How should you plan out your IPv6 addresses? What is the best way to allocate IPv6 address blocks to your various networks and subnets? What factors should you be considering when mapping out a plan for how best to use your IPv6 addresses? These are all great questions and were in fact topics I covered in two recent IPv6 webinars – but we’re very pleased to announce two recent documents that go into this topic in great detail (and we’ve added both to our new IPv6 Address Planning page):
IPv6 Address Planning: Guidelines for IPv6 address allocation
The first IPv6 address planning document is one written for our Deploy360 site by Tim Rooney at BT Diamond IP after he was reviewing our IPv6 content roadmap and contacted us about writing this document for our web portal. It’s a brand new document that we’re publishing for the first time today. Tim does an excellent job walking through the issues around why you need an IPv6 address plan, how you should set one up, suggestions for how to number subnets and then several examples of exactly how you could allocate addresses to subnets based on a plan. He concludes with some recommendations and observations.
It’s a solid document that I think will be quite useful for anyone starting out with IPv6. We greatly appreciate Tim’s contribution to our site and thank him for the time he spent on the document. (And we’re always open to new contributors!)
SURFnet: Preparing An IPv6 Address Plan
In a bit of synchronicity, the great team over at SURFnet came out with a new version of their IPv6 address planning document last week. They first came out with this document in 2011 and with the help of RIPE NCC made it available in both Dutch and English. In this new and improved version they’ve changed the flow of the text a bit and added in more information. The document starts out with a brief review of IPv6 addressing and then gets into the details of creating an address plan. It provides some excellent suggestions and recommendations and includes some detailed examples of how you could structure an address plan. The document also contains sections around how you manage the assignment of IPv6 addresses out to end devices (hosts).
This document, too, is an outstanding document for anyone getting started with IPv6. Thanks to the SURFnet team for coming out with this new version!
While the two documents cover similar ground, they both offer provide different and useful perspectives on how to create an IPv6 address plan. The combination of the two documents will be quite helpful for anyone looking to get started with IPv6.
We strongly encourage you to read both documents (and please do share them with others!) and provide any comments and feedback back to the authors. We’ve added them to a new IPv6 Address Planning page where we will also be adding other resources on this topic (and please let us know if you are aware of some resources we should consider adding). Now… let’s get those IPv6 networks deployed!
Sep 25
SURFnet: Preparing An IPv6 Address Plan
The team at SURFnet has created an excellent document called “Preparing an IPv6 Address Plan” that walks through the many different steps and concerns that you need to consider when creating a plan. The September 2013 version of the document is available from SURFnet’s website.
After briefly touching on the basics of IPv6 addressing and also the idea of simply not having an IP address plan, the document gets into a very detailed description of how you might go about creating an IPv6 addressing plan. It includes several examples and some excellent recommendations. The document concludes with some good suggestions around managing and addressing hosts (end-user devices) now that you have your address plan.
It’s an excellent document and it is great that SURFnet has made this available and has continued to update it with the latest information.
Please visit our IPv6 Address Planning page for other similar resources that can assist with developing an IPv6 address plan.
Sep 25
How To Get IPv6 Addresses
If you want to obtain IPv6 addresses for your network the process to do so depends upon the type of network you operate. If you are a home user or operator of a business network, you will want to start with the local Internet Service Provider (ISP) who provides your access to the Internet. If they are unable to provide you with IPv6 addresses, you will need to explore one of the various IPv6 transition mechanisms such as IPv6 tunneling.
If you are an Internet Service Provider or a large enterprise network operator and want to obtain large blocks of IPv6 addresses, you will need to contact the Regional Internet Registry (RIR) that services the geographic region in which you are based. Information can be found at these links:
- AFRINIC (Africa)
- ARIN (North America)
- APNIC (Asia Pacific)
- LACNIC (Latin and South America)
- RIPE NCC (Europe and eastern/northern Asia)
More information about the IPv6 programs and policies of the Regional Internet Registries may be found at the Numbering Resource Organization (NRO).


