What Does IPv6 Change
Actually, from the users' and routers' perspectives, little things change between IPv4 and IPv6. As Figure 7-1 shows, IPv4 and IPv6 can coexist in the same host or router. Both can run on Ethernet (different packet types multiplex them on the same data link), and both support the usual Layer 4 protocols, such as TCP or User Datagram Protocol (UDP). It is also easy for applications to support both protocols at the same time, such as Firefox or Microsoft Internet Explorer. Both browsers can simultaneously browse to IPv4 and IPv6 websites.
Figure 7-1 IPv4 and IPv6 Dual Stacks
IPv4 and IPv6 Dual Stack
IPv6 Enabled Application
IPv4
IPv6
0x0800
0x86dd
Data Link (Ethernet)
Introduction to IPv6 123
Many differences exist between IPv4 and IPv6, however. One main difference is that the IPv6 header format is 40 bytes; IPv4's header format is only 20 bytes. Larger IPv6 addresses cause this size increase. IPv6 addresses are 128 bits instead of 32 bits, so there are more addresses in IPv6 than in IPv4. Figure 7-2 shows the IPv6 header.
Figure 7-2 IPv6 Packet Header
32 bits
Version
Traffic class
Flow label
Payload length
Next Header
Hop limit
Source Address (128 bits)
Destination Address (128 bits)
The differences between the IPv4 and IPv6 headers are as follows:
• Destination Address and Source Address. IPv6 addresses are now 128 bits, so a huge amount of IPv6 addresses exist (2128). With this number of IPv6 addresses, IPv6 will not face an address shortage any time soon.
• Traffic Class. New name for the Type of Service (ToS) field (also known as Differentiated Services Code Point [DSCP]), it conveys traffic priority for quality of service (QoS).
• Flow Label. When combined with the source address, the flow label identifies all packets in a single application flow. RFC 3697 specifies how the combination of source address and flow label can be used for QoS instead of relying on the Layer 4 ports; therefore, QoS can be enforced even if the Layer 4 ports are unavailable (for example, they are encrypted or exist in a different fragment).
• Payload Length. New name for Total Length.
• Next Header. New name for Protocol; that is, it identifies the next header or the upper protocol, such as 6 for TCP. Another major change in IPv6 is the concept of header chaining, which is described next.
• Hop Limit. New name for Time to Live (TTL); that is, it's decremented by 1 for each router until it reaches 0, and then the packet is discarded. It prevents packets from forever looping in a network.
• Fragmentation Fields. No more fragmentation fields (identification, flags, and fragment offset) exist because fragmentation data is moved to a specific header after the IPv6 header. Moreover, fragmentation can be done only by the transmitting host— never by an intermediate router.
Ever wonder why there are no more options within the IPv6 header? The reason is simple: To make IPv6 header parsing easier for routers, options headers replace all IPv4 options. Because there can be several headers (one per IPv4 option, such as source routing, fragmentation, and so on), a specific mechanism called header chaining allows for multiple headers in a single IPv6 datagram. Figure 7-3 shows an example of IPv6 header chaining.
Figure 7-3 IPv6 Packet Header Chaining
Figure 7-3 IPv6 Packet Header Chaining
In Figure 7-3, the IPv6 packet consists of (from left to right):
• IPv6 Header. The 40 bytes header previously described, the Next Header field contains 43, which is the identifier of the Routing Header.
• Routing Header. Equivalent of source routing in IPv4; that is, the originator uses it to specify the route that the datagram must follow. It also has a Next Header field with a value of 44, which is the identifier of the Fragmentation Header.
• Fragmentation Header. Allows for packet fragmentation by the source and reassembly by the destination.
Besides the preceding differences, routing protocols, such as Routing Information Protocol (RIP) or Open Shortest Path First (OSPF), exist in IPv6 with minor differences.
Upper layer protocols, such as TCP or UDP, are unchanged except for Internet Control Message Protocol (ICMP), which is relied on for more functions than in IPv4:
• Echo request and echo reply. Same debugging functions as in IPv4.
• No route to destination. Similar to IPv4; a router uses it to indicate that a packet cannot be routed because the destination network is unreachable.
• Packet too big. Identical to IPv4; it is generated by a router to tell the source that its packet cannot be routed because it is larger than the maximum transmission unit (MTU) of the next link. Path MTU discovery relies on this ICMPv6 message.
Introduction to IPv6 125
• Time exceeded. Comes from the IPv4 world; when a router receives a packet whose Hop Limit reaches 0, the packet is dropped, and this ICMP message is sent to the source.
• Multicast listener. Used for multicast group membership; it is the equivalent of Internet Group Management Protocol (IGMP).
• Neighbor solicitation and advertisement. ICMPv6 messages are a major change; they are the equivalent of ARP. They discover the Ethernet address of an IPv6 address.
Because the IPv6 addresses are large, they are written in hexadecimal format by fields of 16 bits—that is, by blocks of four hexadecimal numbers separated by colons, as shown here:
2001:0DB8:130F:0000:0000:09C0:876A:130B
Because IPv6 addresses often contain many 0s, you can remove leading 0s:
2001:DB8:130F:0:0:9C0:876A:130B
Moreover, successive fields of 0 are represented as :: (but only once per address to avoid ambiguity):
2001:DB8:130F::9C0:876A:130B
To understand all the security issues related to IPv6's use of Ethernet, you must understand an IPv6 address' format. In IPv6, all nodes can have multiple IPv6 addresses at the same time. One is called the link local address, which can be used only to communicate with nodes on the same physical link (physical network, such as being on the same Ethernet segment). This is a new concept in IPv6. Other addresses have a site or a global scope and are routable.
The most significant 64 bits of a routable address is the network prefix or subnet, while the least significant 64 bits are the host portion, which is called the interface identification (interface ID). Figure 7-4 shows the two parts of an IPv6 address.
Figure 7-4 IPv6 Interface ID
|
Subnet |
Interface ID |
|
64 bits |
|
The interface ID must be unique within a subnet. It can be
• Statically defined. Network manager decides the value of the interface ID (for example, 1 for a router).
• Derived from the Ethernet address. This is the extended unique identifier on 64 bits (EUI-64) format where the 64 bits of the interface ID are derived from the 48 bits Ethernet address by adding a well known 16 bits value to the Ethernet address. The EUI-64 address can lead to a privacy issue because websites might track their users' habits by tracking the interface ID, which will never change, even if the mobile computer changes from one network to another one.
• Privacy extension address. To protect privacy, the interface ID can be randomly generated periodically, such as every hour or even on each new connection.
An interface's link local address is always formed by using FE80:0000:0000:0000 as the most significant 64 bits and the EUI-64 host identifier derived from the interface's MAC address. Here is an example of a link local address (using the abbreviated form of collapsing multiple adjacent 0000s):
fe80::215:58ff:fe27:83dc
Continue reading here: Stateless Configuration with Router Advertisement
Was this article helpful?