Wednesday, January 22, 2014

An IPv6 Success Story (Galois)

The following article was contributed by Paul Heinlein, a systems administrator at Galois. Paul attended my full day IPv6 training course at USENIX LISA and just a couple of months later sent me a report of his successful deployment of IPv6. So I asked if he'd like to contribute an article on the topic.

It's great to hear of IPv6 success stories like this. (And of course, I'm glad folks are finding my courses useful). Significantly, his network is already seeing a very substantial amount of IPv6 traffic!

(A note: the version of iptables in Redhat Enterprise Linux6/CentOS 6 has fixed the stateful IPv6 inspection capability. We use it successfully at Penn).

You can find the slides from my IPv6 training course on my website.

-Shumon Huque



An IPv6 Success Story

Paul Heinlein


Galois is a software-engineering firm located in Portland, OR that specializes in the hard problems of computing trust and assurance.

One of our IT goals for 2014 is enabling IPv6 on all our current IPv4 subnets. I was pleased to see Shumon's full-day IPv6 tutorial on the LISA '13 schedule. I hoped he could fill the gaps in my limited
experience with IPv6 and provide me the knowledge I'd need to configure our network hardware and applications.

Full-day technical tutorials can sometimes test my patience, but Shumon's presentation moved quickly while remaining clear. I came away from the day thinking that I had enough basic knowledge to plan and implement our IPv6 rollout.

Returning to Portland, I had to upgrade upgrade a couple core switches and apply to our ISP for a netblock prior to enabling it on our network, but once the hardware was in place, everything went reasonably well.

Shumon's overview had done exactly what I'd hoped it would: allow me to interpret the various bits of vendor-specific and application-specific documentation and assemble a reasonable roll-out plan.

Our DMZ and client networks are now fully IPv6 enabled. (Internal development networks will take a bit more time due to VPN-related complexity.)

Along the way, I learned a couple things Shumon didn't explicitly cover in his presentation.

First, make sure that reverse DNS pointers are in place for any mail server before enabling IPv6. gmail (among others) will reject messages from any mail server without reverse DNS pointers in place.

Second, the ip6tables that ships with RHEL/CentOS 5 has a limited ability to do stateful packet inspection. The generic rule allowing packets from established or related sessions does not work:

   # this is broken in RHEL/CentOS 5
   -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

(We've only got one CentOS 5 machine in our DMZ, so this issue hasn't impacted us in any major way.)

Third, it was a lot of fun! Nearly all our DMZ services (NTP, DNS, Jabber, e-mail, www, ssh, host-based firewalls) needed updated configurations, so I learned a bunch. The day after I did the initial rollout, one of our engineers came into the office, turned off IPv4 on his Mac, and tested what percentage of Google result links he could follow. (He thought about 5%, though he said the queries he chose probably resulted in a higher success rate than might be normal.)

Finally, I've been mildly surprised at the quantity of IPv6 packets traversing our border firewall. Over the past week, IPv6 has comprised 38% of overall inbound traffic and 11% of outbound. The numbers are similar when scoped to the past month.

I'd like to express my thanks to Shumon for the talk and the LISA organizers for putting it on the schedule!

  -- Paul Heinlein <heinlein@galois.com>

Friday, January 17, 2014

World IPv6 Launch Measurements

From the Internet Society's most recent (January 16th 2014) round of IPv6 measurements, here again are the top 100 lists ranked by the two measures of (1) percentage of requests that used IPv6, and (2) total volume of IPv6 requests.

My past articles on this topic:
  * Measurements from December 12th 2013
  * Measurements from  September 17th 2013
  * Measurements from June 6th 2012

ISOC's blog post highlights that Deutsche Telekom, a large German telecommunications carrier, (of which T-Mobile US is a subsidiary*) has been experiencing very substantial IPv6 traffic growth. They've reached a figure of 15.5% of requests composed of IPv6 (to the select set of content providers providing measurement data). In terms of total volume of IPv6 requests, they are in 6th place behind five other large ISPs (See the second ranked list below). Comcast still leads the pack, followed by AT&T, KDDI, Free, and Verizon Wireless.

(*Note: T-Mobile's traffic is counted separately in the measurements from Deutsche Telekom)

Interestingly, while Verizon Wireless has a substantial IPv6 deployment, Verizon FIOS (their fiber-optic landline network) has made no visible progress in IPv6 deployment. Although many people, myself included, have noted this lack of deployment over the years, they were just recently taken sharply to task by folks on the NANOG (North American Network Operators Group) mailing list.

Looking at the rankings by proportion of IPv6 requests from each network, there is a new entry at the top - NYSERNet (a regional R&E network in New York State), coming in at a staggering 99.95%. On the Internet2 IPv6 working group list, I asked Bill Owens of NYSERNet if he wanted to comment. He claims that we shouldn't be too impressed because this is just the small NYSERNet office network and the backbone, with a relatively small population of clients. Regardless, I think it's a noteworthy achievement. As I've mentioned before, a number of universities and other educational organizations still show up prominently in this ranking. Two small american colleges, Gustavus Adolphus in Minnesota at 74.22% and Marist College in upstate New York at 65.77%! And Panamerican University, in Mexico City is at 66.22%.

Penn is slowly inching up at 45%. We'll have IPv6 deployed more extensively on our wireless network pretty soon, at which point I expect our numbers to go up noticeably.


World IPv6 Launch Measurements, by % IPv6 requests:
---------------------------------------------------

   1 NYSERNet 99.95%
   2 SpeedPartner GmbH 95.83%
   3 TOP-IX Consortium 86.99%
   4 Fundacao Parque Tecnologico Itaipu - Brasil 79.92%
   5 DirectVPS 78.63%
   6 interscholz Internet Services GmbH & Co. KG 75.49%
   7 Gustavus Adolphus College 74.22%
   8 Google Fiber 71.87%
   9 Universidad Panamericana 66.22%
  10 Marist College 65.77%
  11 University of Vermont 65.13%
  12 Virginia Tech 65.11%
  13 mur.at - Verein zur Frderung von Netzkwerkkunst 64.97%
  14 Association tetaneutral.net 55.67%
  15 Utility Line Italia srl 53.40%
  16 ThaiSarn 53.23%
  17 DegNet GmbH 52.84%
  18 Trunk Networks Limited 52.60%
  19 Ji?? ?trohalm 52.20%
  20 Alhambra Eidos 52.12%
  21 Louisiana State University 51.93%
  22 Ponto de Presen?a da RNP na Bahia 51.30%
  23 SuperInternet Access Pte Ltd 50.45%
  24 University of New Hampshire 50.44%
  25 Region 7 ESC 50.24%
  26 PREGINET 50.20%
  27 CICA/Junta de Andaluc?a 50.05%
  28 Tanzania Network Information Center 50.00%
  29 Karlsruhe Institute of Technology (KIT) 49.03%
  30 Maxiweb Internet Provider 48.76%
  31 Critical Colocation 48.23%
  32 University of Pennsylvania 45.38%
  33 SPAWAR 44.15%
  34 AMS-IX 42.99%
  35 University of Iowa 42.81%
  36 Kasetsart University 41.99%
  37 DreamHost 41.79%
  38 University of Minnesota 40.80%
  39 Rensselaer Polytechnic Institute 40.74%
  40 Bulgaria NREN 40.57%
  41 Verizon Wireless 40.03%
  42 CZ.NIC 39.02%
  43 guifi.net 37.86%
  44 Hughes Network Systems 35.60%
  45 Sauk Valley Community College 35.52%
  46 Tulane University 34.96%
  47 Free 34.28%
  48 ARNES 33.73%
  49 Greek Research & Technology Network 33.14%
  50 Leibniz Supercomputing Centre 32.71%
  51 Host Virtual, Inc 31.74%
  52 Netwerkvereniging Coloclue 28.41%
  53 Opera Software ASA 27.54%
  54 UNESP 27.26%
  55 UNINETT 27.13%
  56 FCCN 26.00%
  57 VOO 24.12%
  58 RCS & RDS 23.80%
  59 mc.net 23.37%
  60 UFSCar 22.96%
  61 EPT Luxembourg 22.43%
  62 FranTech Solutions 22.03%
  63 AAISP 21.22%
  64 Comcast 20.61%
  65 Chubu Telecommunications 18.90%
  66 Swisscom 18.66%
  67 XS4ALL 17.66%
  68 UFSC - Universidade Federal de Santa Catarina - Brazil 17.50%
  69 LENTEL 16.73%
  70 StarHub 16.28%
  71 Deutsche Telekom AG 15.50%
  72 NIIF/Hungarnet 14.56%
  73 LITNET 14.50%
  74 Red Acad?mica de Centros de Investigaci?n y Universidades Nacionales REACCIUN 13.85%
  75 Indiana University 13.68%
  76 ATT 13.53%
  77 SARENET 13.13%
  78 DMZGlobal 12.97%
  79 NetAssist 12.89%
  80 Academia Sinica Network 12.14%
  81 Cisco 11.95%
  82 Solcon 11.46%
  83 CESNET 11.04%
  84 Funet 10.94%
  85 PT. Wifian Solution 10.19%
  86 FidoNet 10.12%
  87 prgmr.com 9.89%
  88 T-Mobile USA 9.58%
  89 Monash University 9.28%
  90 OVH 9.26%
  91 KDDI 8.94%
  92 Spectrum Networks 8.30%
  93 AMRES - Serbian National Research and Education Network 7.84%
  94 Belnet 7.65%
  95 SWITCH 7.62%
  96 Hurricane Electric 7.58%
  97 M1 Limited 7.22%
  98 RedIRIS 6.96%
  99 Init7 6.93%
 100 CJSC Progressive Technologies 6.71%


World IPv6 Launch Measurements, by volume of IPv6:
--------------------------------------------------


   1 Comcast 20.61%
   2 ATT 13.53%
   3 KDDI 8.94%
   4 Free 34.28%
   5 Verizon Wireless 40.03%
   6 Deutsche Telekom AG 15.50%
   7 Time Warner Cable 3.88%
   8 RCS & RDS 23.80%
   9 Liberty Global 2.43%
  10 Swisscom 18.66%
  11 Telefonica del Peru 4.60%
  12 Hughes Network Systems 35.60%
  13 SoftBank BB 1.46%
  14 Chubu Telecommunications 18.90%
  15 Opera Software ASA 27.54%
  16 VOO 24.12%
  17 XS4ALL 17.66%
  18 StarHub 16.28%
  19 T-Mobile USA 9.58%
  20 Google Fiber 71.87%
  21 China Telecom 0.23%
  22 Forthnet 2.79%
  23 M1 Limited 7.22%
  24 Internode 3.94%
  25 EPT Luxembourg 22.43%
  26 Janet 3.81%
  27 its communications Inc.(iTSCOM) 2.64%
  28 CESNET 11.04%
  29 MediaCat Div./Community Netowork Center Inc. 6.58%
  30 Kasetsart University 41.99%
  31 NTT Communications 4.51%
  32 Belnet 7.65%
  33 ARNES 33.73%
  34 Leibniz Supercomputing Centre 32.71%
  35 LITNET 14.50%
  36 NIIF/Hungarnet 14.56%
  37 OVH 9.26%
  38 Cisco 11.95%
  39 BelWue 5.71%
  40 FCCN 26.00%
  41 UNINETT 27.13%
  42 Altibox AS 0.90%
  43 Monash University 9.28%
  44 SWITCH 7.62%
  45 TUBITAK ULAKBIM / ULAKNET 1.50%
  46 Australian Academic and Research Network (AARNet) 2.00%
  47 Indiana University 13.68%
  48 University of Minnesota 40.80%
  49 AAISP 21.22%
  50 UniNet 3.36%
  51 Xfone 018 0.96%
  52 Ji?? ?trohalm 52.20%
  53 Voxel / Internap 3.51%
  54 GITN Sdn Berhad 2.69%
  55 Louisiana State University 51.93%
  56 University of Pennsylvania 45.38%
  57 SuperCSI 1.69%
  58 JARING Communications Sdn Bhd 0.38%
  59 Solcon 11.46%
  60 CJSC Progressive Technologies 6.71%
  61 Starlink 1.88%
  62 inexio KGaA 2.44%
  63 Virginia Tech 65.11%
  64 green.ch AG 3.26%
  65 Hurricane Electric 7.58%
  66 Dhiraagu 0.60%
  67 Gustavus Adolphus College 74.22%
  68 LENTEL 16.73%
  69 DMZGlobal 12.97%
  70 DegNet GmbH 52.84%
  71 RedIRIS 6.96%
  72 Academia Sinica Network 12.14%
  73 GlobalConnect 1.44%
  74 University of Iowa 42.81%
  75 Funet 10.94%
  76 University of Wisconsin - Madison 6.16%
  77 Storm Internet 3.76%
  78 AMRES - Serbian National Research and Education Network 7.84%
  79 National Informatics Centre 2.32%
  80 SoftLayer Technologies 0.84%
  81 RENATER 4.57%
  82 Karlsruhe Institute of Technology (KIT) 49.03%
  83 guifi.net 37.86%
  84 Init7 6.93%
  85 Host Virtual, Inc 31.74%
  86 Rensselaer Polytechnic Institute 40.74%
  87 Choopa, LLC 0.55%
  88 NetAssist 12.89%
  89 Tulane University 34.96%
  90 DreamHost 41.79%
  91 Bulgaria NREN 40.57%
  92 FranTech Solutions 22.03%
  93 Greek Student Network 0.47%
  94 RESTENA 5.33%
  95 UNESP 27.26%
  96 iway AG 4.06%
  97 FX Networks 0.49%
  98 Tanzania Network Information Center 50.00%
  99 edpnet 1.11%
 100 ADDIX Internet Services 3.05%


Thursday, December 19, 2013

World IPv6 Launch Measurements

The Internet Society has posted their latest IPv6 measurements (December 12th 2013). Read the section titled "Notes on network operator measurements" to understand how the measurements are being made and which content providers (Google, Facebook, Yahoo!, Akamai) are providing the data.

I've pulled out some of the data, and put together ranked (top 100) lists of networks by two measures: (1) percentage of requests that used IPv6, and (2) total volume of IPv6 requests. As I've done a few times in the past, I'm going to continue periodically writing these entries to have a snapshots in time of IPv6 deployment progress.

Many networks are posting some pretty impressive numbers for IPv6 usage. For the leading network in the %v6 category (the 1st list below), TOP-IX Consortium, an Italian Internet Exchange point has 86% of their requests to the participating content providers using IPv6! Several universities in the US R&E community are doing well too, Gustavus Adolphus College at 74%, Virginia Tech at 62%, University of New Hampshire at 51% among them. The University of Pennsylvania (my own institution) is posting a respectable 40% - we'll have IPv6 fully deployed on our wireless network in early 2014, at which time our numbers should go up substantially. There's an interesting story about why Penn hasn't had IPv6 on its wireless network for so long - I'm planning to write a separate article on that topic in the near future.

In the total volume category (the 2nd list below) Comcast now leads. John Brzozowski, Comcast's chief IPv6 architect, has written a more detailed article on their leadership position in IPv6 deployment. They are followed by several other ISPs: AT&T (US), KDDI (Japan), Free (France), Verizon Wireless, (US) Deutsche Telekom (Germany), RCS & RDS (Romania), Time Warner Cable (US).


World IPv6 Launch Measurements, by % IPv6 requests:
---------------------------------------------------

   1 TOP-IX Consortium    86.27%
   2 Fundacao Parque Tecnologico Itaipu - Brasil    79.65%
   3 DirectVPS         77.66%
   4 ThaiSarn         76.62%
   5 Gustavus Adolphus College   17234    74.17%
   6 Google Fiber      70.22%
   7 Universidad Panamericana    13679    66.84%
   8 mur.at - Verein zur Frderung von Netzkwerkkunst    66.73%
   9 interscholz Internet Services GmbH & Co. KG     66.20%
  10 Virginia Tech     61.69%
  11 Trunk Networks Limited     56.99%
  12 Association tetaneutral.net    56.41%
  13 DegNet GmbH     51.91%
  14 Ponto de PresenC'a da RNP na Bahia     51.75%
  15 Critical Colocation   51.38%
  16 Jiri strohalm    51.29%
  17 SPAWAR     51.12%
  18 ITsjefen AS     51.08%
  19 SuperInternet Access Pte Ltd     50.88%
  20 University of New Hampshire     50.57%
  21 AIMES Grid Services CIC     50.38%
  22 Region 7 ESC     50.27%
  23 PREGINET 50.24%
  24 Maxiweb Internet Provider    50.20%
  25 CICA/Junta de AndalucC-a    50.04%
  26 DreamHost    49.41%
  27 Alhambra Eidos    49.32%
  28 Karlsruhe Institute of Technology (KIT)    48.85%
  29 Sauk Valley Community College     46.13%
  30 University of Minnesota           45.87%
  31 Marist College     45.83%
  32 AMS-IX     44.09%
  33 University of Iowa     42.90%
  34 Kasetsart University     41.31%
  35 Verizon Wireless     40.40%
  36 University of Pennsylvania     40.06%
  37 Bulgaria NREN     38.74%
  38 guifi.net     38.69%
  39 Rensselaer Polytechnic Institute    37.91%
  40 Louisiana State University     35.74%
  41 Leibniz Supercomputing Centre     35.17%
  42 Netwerkvereniging Coloclue     32.66%
  43 Free       31.03%
  44 UNESP       30.15%
  45 NetAssist       29.72%
  46 ARNES       28.98%
  47 Tulane University     28.88%
  48 Utility Line Italia srl     28.19%
  49 Host Virtual, Inc     27.79%
  50 Hughes Network Systems     27.28%
  51 FCCN   26.96%
  52 UFSCar     26.36%
  53 VOO     25.94%
  54 Opera Software ASA     25.69%
  55 Greek Research & Technology Network    24.94%
  56 UNINETT        24.58%
  57 LENTEL         23.48%
  58 Chubu Telecommunications    22.76%
  59 RCS & RDS     22.01%
  60 mc.net     20.20%
  61 Comcast    20.15%
  62 Monash University     19.82%
  63 Swisscom     19.64%
  64 UFSC - Universidade Federal de Santa Catarina - Brazil    19.25%
  65 XS4ALL 18.52%
  66 AAISP  18.13%
  67 SIDN   17.11%
  68 EPT Luxembourg    16.72%
  69 manitu GmbH    15.88%
  70 VentraIP Group (Australia) Pty Ltd    15.73%
  71 LITNET   15.09%
  72 Hurricane Electric    14.88%
  73 ATT     14.82%
  74 NIIF/Hungarnet    14.43%
  75 Funet        12.60%
  76 CESNET        12.33%
  77 Deutsche Telekom AG    12.28%
  78 Indiana University        12.14%
  79 OVH           11.63%
  80 FranTech Solutions    10.98%
  81 Red Academica de Centros de InvestigaciC3n y Universidades Nacionales REACCIUN    10.95%
  82 UniNet       10.48%
  83 Host.MD      10.35%
  84 Belnet       9.73%
  85 Cisco       9.70%
  86 CJSC Progressive Technologies    9.65%
  87 KDDI     8.87%
  88 Academia Sinica Network     8.22%
  89 SARENET  8.01%
  90 DMZGlobal     7.99%
  91 SWITCH     7.86%
  92 Init7     7.70%
  93 MediaCat Div./Community Netowork Center Inc.    7.52%
  94 AMRES - Serbian National Research and Education Network    7.10%
  95 RedIRIS      6.74%
  96 T-Mobile USA      6.49%
  97 Voxel / Internap     6.48%
  98 Defense Research and Engineering Network    6.41%
  99 prgmr.com      6.35%
 100 M1 Limited      6.29%


World IPv6 Launch Measurements, by volume of IPv6:
--------------------------------------------------

   1 Comcast    20.15%
   2 ATT    14.82%
   3 KDDI    8.87%
   4 Free     31.03%
   5 Verizon Wireless     40.40%
   6 Deutsche Telekom AG    12.28%
   7 RCS & RDS          22.01%
   8 Time Warner Cable     4.07%
   9 Liberty Global    2.52%
  10 Telefonica del Peru    5.14%
  11 Swisscom    19.64%
  12 SoftBank BB     1.65%
  13 Hughes Network Systems     27.28%
  14 Chubu Telecommunications     22.76%
  15 Opera Software ASA     25.69%
  16 VOO   25.94%
  17 XS4ALL     18.52%
  18 China Telecom    0.18%
  19 Janet         4.29%
  20 T-Mobile USA    6.49%
  21 Forthnet         3.35%
  22 StarHub        4.81%
  23 University of Minnesota     45.87%
  24 Indiana University        12.14%
  25 CESNET  12.33%
  26 Google Fiber     70.22%
  27 M1 Limited     6.29%
  28 Virginia Tech    61.69%
  29 Internode        4.53%
  30 FCCN        26.96%
  31 EPT Luxembourg     16.72%
  32 Cisco        9.70%
  33 Belnet        9.73%
  34 Louisiana State University     35.74%
  35 RedIRIS   6.74%
  36 UNINETT   24.58%
  37 Leibniz Supercomputing Centre    35.17%
  38 its communications Inc.(iTSCOM)     3.14%
  39 SWITCH     7.86%
  40 NIIF/Hungarnet     14.43%
  41 ARNES     28.98%
  42 MediaCat Div./Community Netowork Center Inc.    7.52%
  43 BelWue     5.87%
  44 LITNET     15.09%
  45 University of Pennsylvania    40.06%
  46 NTT Communications     4.38%
  47 RENATER     4.10%
  48 Kasetsart University     41.31%
  49 University of Iowa     42.90%
  50 TUBITAK ULAKBIM / ULAKNET     1.29%
  51 OVH     11.63%
  52 Tulane University    28.88%
  53 Monash University     19.82%
  54 UNESP  53166     30.15%
  55 AMRES - Serbian National Research and Education Network    7.10%
  56 Rensselaer Polytechnic Institute  37.91%
  57 UFSC - Universidade Federal de Santa Catarina - Brazil    19.25%
  58 University of Wisconsin - Madison      4.84%
  59 Gustavus Adolphus College 74.17%
  60 Funet       12.60%
  61 GARR       1.25%
  62 Marist College     45.83%
  63 SPAWAR     51.12%
  64 SURFnet     1.36%
  65 SuperCSI     2.71%
  66 Altibox AS     0.70%
  67 AAISP       18.13%
  68 Australian Academic and Research Network (AARNet)    2.32%
  69 Karlsruhe Institute of Technology (KIT)  48.85%
  70 Xfone 018       1.11%
  71 UFSCar       26.36%
  72 Voxel / Internap    6.48%
  73 Solcon         5.12%
  74 UniNet         10.48%
  75 CJSC Progressive Technologies    9.65%
  76 CICA/Junta de AndalucC-a     50.04%
  77 Starlink    1.47%
  78 Hurricane Electric     14.88%
  79 Greek Research & Technology Network     24.94%
  80 Jiri strohalm  51.29%
  81 JARING Communications Sdn Bhd    0.27%
  82 Defense Research and Engineering Network    6.41%
  83 GITN Sdn Berhad  3.11%
  84 Dhiraagu         0.85%
  85 Academia Sinica Network    8.22%
  86 green.ch AG         2.83%
  87 Louisiana Optical Network Initiative    5.04%
  88 LENTEL    23.48%
  89 Fundacao Parque Tecnologico Itaipu - Brasil    79.65%
  90 DegNet GmbH         51.91%
  91 National Informatics Centre    2.19%
  92 guifi.net     38.69%
  93 GlobalConnect     1.54%
  94 The Tertiary Education and Research Network of South Africa (TENET)    1.53%
  95 DMZGlobal      7.99%
  96 Init7      7.70%
  97 SoftLayer Technologies    1.40%
  98 Ponto de PresenC'a da RNP na Bahia    51.75%
  99 Storm Internet    5.40%
 100 inexio KGaA    1.15%


Sunday, December 1, 2013

EDU Top Level Domain statistics

Some DNS Top Level Domain (TLD) operators publish statistics about their DNS zones. Some others have a zone file access program that allows others to examine their data and publish statistics. Frederic Cambus (@fcambus on Twitter) maintains a site called statdns ( http://www.statdns.com/ ) that keeps statistics for several of the TLDs.

The EDU top level domain is conspicuously absent from the statdns site because the operators don't publish any statistics and also don't have a zone file access program in place. The EDU domain has a very complicated operational policy arrangement. It is managed by Educause (a higher education IT consortium), but operated by Verisign, under a contract with the United States Department of Commerce. I recently spoke with colleagues at Educause about current prospects for publishing some statistics or making the zone data available. The good news is that a zone file access program request is in fact in the queue to be approved by the Dept of Commerce. But it's stuck behind a few other requests, so it may still take some time to come to fruition.

In the meantime, to satisfy my own curiosity, I've been looking at other ways to obtain some statistics. In particular I'm interested in seeing how much DNSSEC deployment has happened so far, and how EDU compares with some of the other TLDs in this respect. One way to gain visibility into zone contents is to examine passive DNS databases. A number of folks and organizations run such databases that collect historical information seen from DNS responses at collections of resolvers. By searching records over a period of time in these databases, it's possible to reconstruct a substantial portion of the active records in a zone. I did this for EDU and analyzed the results recently.

The passive DNS database search managed to find about 7,158 second level domains under EDU. Of these, 6955 domains turned out to be valid (the others probably existed at one point but don't any more). EDU is known to have in the neighborhood of 7,000 delegations, so this is most probably a pretty good approximation of the active contents of the zone.

EDU Zone Statistics:

Number of Domains from passive DNS db: 7158
Number of Valid Domains: 6955

Total NS records: 19527
Unique NS records: 9757
Number of (glue) IPv4 address records: 4555
Number of (glue) IPv6 address records: 246

DNSSEC Specific Stats for EDU:

Number of DNSSEC Signed Zones: 94 (1.37%)
Number of NSEC3 Zones: 29 (30.1% of the signed zones)
Number of Zones with DS records: 76
Number of Zones with DLV records at dlv.isc.org: 7

As expected, only a very small fraction (1.37%) of domains have deployed DNSSEC. This compares with about 0.25% in .COM, 0.41% in .NET, and 0.30% in .ORG.

The 94 zones in EDU signed with DNSSEC are:

acadiana.edu
baker.edu
beloit.edu
berkeley.edu
bucknell.edu
cameron.edu
carnegiemellon.edu
catc.edu
chattanoogastate.edu
cltc.edu
cmu.edu
coloradomesa.edu
cookman.edu
csupomona.edu
cuhk.edu
desales.edu
drake.edu
example.edu
fhsu.edu
fhtc.edu
gfcmsu.edu
gsu.edu
gtc.edu
hfg.edu
highlands.edu
indiana.edu
indianatech.edu
internet2.edu
iu.edu
iub.edu
iup.edu
iupui.edu
jhuapl.edu
kestrel.edu
kiropraktik.edu
k-state.edu
ksu.edu
kutztown.edu
lctcs.edu
lsu.edu
ltc.edu
ma.edu
mansfield.edu
mcpherson.edu
merit.edu
mesa.edu
millikin.edu
mnsfld.edu
monmouth.edu
monterey.edu
mst.edu
nau.edu
northcentral.edu
northshorecollege.edu
nwltc.edu
okstate.edu
pacificu.edu
penn.edu
pitt.edu
psc.edu
richland.edu
rockefeller.edu
rose-hulman.edu
scl.edu
sdsmt.edu
sfcollege.edu
shoreline.edu
suu.edu
tbu.edu
tiasnimbas.edu
tilburguniversity.edu
tiss.edu
truman.edu
uaa.edu
ualr.edu
ucaid.edu
ucb.edu
ucberkeley.edu
ucdavis.edu
ucr.edu
uiowa.edu
umbc.edu
uni-stuttgart.edu
unt.edu
untsystem.edu
upenn.edu
upf.edu
usnwc.edu
uwm.edu
uwstout.edu
valencia.edu
waketech.edu
washjeff.edu
weber.edu

The 29 zones that use the NSEC3 variety of DNSSEC are:

csupomona.edu
cuhk.edu
gfcmsu.edu
internet2.edu
jhuapl.edu
kestrel.edu
kiropraktik.edu
k-state.edu
ksu.edu
lsu.edu
ma.edu
mansfield.edu
mcpherson.edu
millikin.edu
mnsfld.edu
pitt.edu
richland.edu
rose-hulman.edu
sdsmt.edu
suu.edu
tiasnimbas.edu
tilburguniversity.edu
ualr.edu
ucaid.edu
ucr.edu
uni-stuttgart.edu
unt.edu
untsystem.edu
washjeff.edu

There are 18 zones that do not have DS records published (not sure why):

beloit.edu
cameron.edu
cookman.edu
iup.edu
kiropraktik.edu
kutztown.edu
mansfield.edu
merit.edu
mnsfld.edu
okstate.edu
shoreline.edu
tbu.edu
tiasnimbas.edu
uaa.edu
usnwc.edu
uwm.edu
uwstout.edu
waketech.edu

There are also 7 zones with DLV records published at ISC's DLV registry, but this set is disjoint with the set that doesn't have DS records:

bucknell.edu
internet2.edu
k-state.edu
ksu.edu
ualr.edu
ucaid.edu
ucr.edu

-- Shumon Huque

Wednesday, November 20, 2013

New DNS Top Level Domains

If you follow DNS news, you may know that ICANN has put in place a program to introduce many new generic top level domains (GTLD) into the DNS. I haven't been a fan. ICANN says there is market demand for GTLD expansion (perhaps), and that it allows innovation in the DNS ecosystem (how?). It probably will have an effect of diluting the entrenched market power of the big TLD operators (.com, .org etc), which may be a good thing. But the system may end up being primarily a significant financial windfall for ICANN. Even Esther Dyson (original ICANN chair) has spoken out against the program.

There appear to be some trademark protection mechanisms built in to the new system. But it seems clear that many organizations will rush to defensively register their names under some of the new TLDs. Strictly speaking, DNS domain names have no intended or actual relation to trademarks, but we have to deal with the real world. My university's upper administration has already contacted the IT department to discuss the topic. A while back, we defensively registered "upenn.xxx" to protect against possible reputational damage (and no, I wasn't involved in that decision).

On a more technical note, one interesting and welcome feature of the new GTLDs, is that they must be deployed with DNSSEC. This should significantly increase the proportion of signed top level domains in the DNS. My dnsstat DNS monitoring site has been monitoring the TLDs for a while now, and I just updated it with the latest list of TLDs.

    http://www.huque.com/app/dnsstat/category/tld/

Since late August, 32 new TLDs have been introduced, 27 normal GTLDs, 5 IDN (Internationalized domains) TLDs. But 11 IDN TLDs have also disappeared. That's a net gain of 21 TLDs, bringing the total count to 339.

Some DNSSEC specific stats: 143 (or 42.2%) of the TLDs are signed with DNSSEC. Here's a breakdown of type key and zone signing algorithms in use for the signed TLDs:

Key Signing Keys (KSK):
RSASHA256 (8) = 119 (63.0%)
RSASHA512 (10) = 6 (3.2%)
RSASHA1 (5) = 16 (8.5%)
RSASHA1-NSEC3-SHA1 (7) = 48 (25.4%)

Zone Signing Keys (ZSK):
RSASHA256 (8) = 133 (62.4%)
RSASHA512 (10) = 8 (3.8%)
RSASHA1 (5) = 17 (8.0%)
RSASHA1-NSEC3-SHA1 (7) = 55 (25.8%)

Note: new GTLDs continue to be added, so the numbers in this article might be out of date soon.

Here are the added TLDs so far (as of November 20th 2013):

+ bike
+ camera
+ clothing
+ construction
+ contractors
+ diamonds
+ directory
+ enterprises
+ equipment
+ estate
+ gallery
+ graphics
+ guru
+ holdings
+ kitchen
+ land
+ lighting
+ photography
+ plumbing
+ sexy
+ singles
+ tattoo
+ technology
+ tips
+ today
+ ventures
+ voyage

Here are the new IDN TLDs:

+ xn--80asehdb
+ xn--80aswg
+ xn--mgba3a4f16a
+ xn--ngbc5azd
+ xn--unup4y

Here are the deleted IDN TLDs:

- xn--0zwm56d
- xn--11b5bs3a9aj6g
- xn--80akhbyknj4f
- xn--9t4b11yi5a
- xn--deba0ad
- xn--g6w251d
- xn--hgbk6aj7f53bba
- xn--hlcj6aya9esc7a
- xn--jxalpdlp
- xn--kgbechtv
- xn--zckzah

Note: one IDN TLD (xn--l1acc) has had a severely busted DNSSEC deployment for a while. My monitoring system detects that its DS records in the root of the DNS do not match any DNSKEY records in the zone, and furthermore, the signatures on the DNSKEY records have expired. I hope they get their act together soon.

--Shumon Huque

Saturday, November 16, 2013

Penn wins NSF Campus CyberInfrastructure Award

A while back in a blog article on our 100 Gigabit Ethernet campus upgrades, I mentioned that Penn had applied for a National Science Foundation (NSF) CC-NIE grant to enhance campus network infrastructure for research purposes.

We did in fact win an award. Here's the official notice from NSF. It's about $500,000 which will be used to deploy a dedicated high performance router for researchers and bump up our external connectivity to Internet2 to 100 Gbps. I hope to provide more updates as we begin deploying the necessary pieces of equipment.

--Shumon Huque

An excerpt from the award notice:

ABSTRACT

The University of Pennsylvania's central computing organization is partnering with leading campus researchers in engineering, physics, biology, pathology, genomics, bioinformatics, and computer science to optimize the campus network in support of big data research and high-performance computing. This project establishes a 100 Gbps-capable Science DMZ that is distinct from the general purpose campus network and is engineered for research applications. Additionally, it extends 10 Gbps connectivity to select research projects and increases Penn's connection to Internet2 from 1 Gbps to 100 Gbps, while also extending that connection to the Science DMZ. The project also lays the foundation for further enhancements to research networking infrastructure by extending IPv6 capabilities; upgrading network monitoring tools such as perfSONAR; and enhancing Penn's ability to support experimental networks and network architectures, including OpenFlow and Software Defined Networking.

The project will benefit a range of scientifically meritorious research. It will provide support for the large-scale data transfer, processing, and storage needs of researchers across Penn, while supporting intra- and inter-institutional collaborations and the broad dissemination of research results. Rather than focusing on the logistics of data storage and transfer, researchers will be able to concentrate on the transformation of these data into the information that will drive new discoveries and the creation of new technologies, drugs, therapies, and cures. Network enhancements will also support Penn's commitment to integrating research and education by supporting the network needs of the cross-disciplinary Penn Institute for Computation Science that where faculty actively integrate computation-based research with the training of future generations of STEM researchers.

Wednesday, October 23, 2013

TLSA Record Generator

Last year I wrote a blog article on DNSSEC and Certificates. Occasionally I get questions from folks who've tried to follow my instructions to create the content of TLSA records, but have failed because they are using a version of openssl that is too old to generate SHA-256 and SHA-512 hashes.

I've written a small web application to help generate TLSA records. I hope this is of use to some folks:

        https://www.huque.com/bin/gen_tlsa

(I apologize in advance for my rather primitive webpage design skills!)

Here is a screenshot of it in action to generate the TLSA record for my own website:


And the resulting TLSA record that was generated:



-- Shumon Huque

Tuesday, October 22, 2013

IPv6 and DNSSEC at LISA in DC

LISA '13

Once again, I'm teaching a couple of courses at the USENIX LISA conference, this time in Washington, DC. The first is a half day course on DNSSEC on Sunday, November 3rd. And the second is a full day course on IPv6 on Monday, November 4th. I hope to see you there if you're interested in learning or talking about these topics. Early bird registration discounts for the conference end on October 22nd (sorry for the short notice).

Matt Simmons (@standaloneSA) interviewed me about both classes: DNSSEC and IPv6.

-- Shumon Huque

Thursday, October 3, 2013

Singh Nanotechnology Center

The grand opening of Penn's new Singh Center for Nanotechnology is tomorrow (Friday, October 4th). Computing directors in my department got to see it a week early when we held a special meeting in the Forum room.

This post contains a few photos from my visit - of the building exterior, hallways, and conference rooms. The labs weren't open yet. The full set can be found at Google Plus.

The Nanotech center has been featured in some recent articles:

* Philadelphia Inquirer - "Changing Skyline - Inga Saffron"
* The Daily Pennsylvanian
* Philadelphia Inquirer - "Penn going all out for small science"

Building exterior, from Walnut Street close to the 33rd Street intersection, looking east:




This cantilevered section houses a conference room - the Glandt Forum room.


The Forum room, where our meeting was held.


At the edge of the cantilevered section.


Looking westward along Walnut St towards the rest of campus. Directly in front (right side) is the Laboratory for Research on the Structure of Matter (LRSM). To the left is the David Rittenhouse Lab.


View from the green rooftop terrace.


Rooftop terrace.


Hallways.


"We Lost" sculpture by Tony Smith.





Wednesday, October 2, 2013

Latest World IPv6 Launch Measurements

The Internet Society recently published results of their latest round (September 17th 2013) of IPv6 measurements. The measurement data is provided by Google, Facebook, Yahoo!, and Akamai. From the description on the website: "We present measurements of network operator participants in World IPv6 Launch, based on data received from major website participants, as described in more detail below. We present a simple average of the data received, and list all networks with measurements from at least two sources, with a simple average above 0.1%."

I find it instructive to sort the results by the percentage of requests from each participating network that are composed of IPv6. This is a pretty good indicator of how extensively these networks have deployed IPv6 to their end users.

Note: the measurements are only done for networks that have signed up as participants in World IPv6 Launch. If you've deployed IPv6 to your users, you should consider registering your network to take part in these measurements.

Here's a ranked list of these networks sorted by percentage of IPv6 requests of the total from each.

     1    interscholz Internet Services GmbH & Co. KG    81.22%
     2    Sauk Valley Community College                  71.23%
     3    ThaiSarn                                       69.41%
     4    Rensselaer Polytechnic Institute               61.25%
     5    Virginia Tech                                  59.54%
     6    Universidad de Carabobo                        58.50%
     7    Sistemas Fratec S.A.                           58.19%
     8    Universidad Panamericana                       57.89%
     9    Bayu Krisnawan                                 56.64%
    10    Dedicated Zone Inc                             56.55%
    11    Google Fiber                                   55.64%
    12    REACCIUN                                       52.41%
    13    NETIS TELECOM                                  52.17%
    14    Gustavus Adolphus College                      46.64%
    15    DreamHost                                      46.32%
    16    Alhambra Eidos                                 45.37%
    17    VOO                                            45.32%
    18    SPAWAR                                         45.28%
    19    Greek Research & Technology Network            43.96%
    20    Karlsruhe Institute of Technology (KIT)        43.51%
    21    AIMES Grid Services CIC                        42.37%
    22    Host Virtual, Inc                              42.24%
    23    ARNES                                          41.90%
    24    FCCN                                           40.95%
    25    Marist College                                 40.89%
    26    guifi.net                                      39.97%
    27    University of Pennsylvania                     38.94%
    28    Zimcom Internet Solutions, Inc                 35.75%
    29    Verizon Wireless                               35.73%
    30    NIIF/Hungarnet                                 29.92%
    31    LITNET                                         29.07%
    32    DirectVPS                                      29.05%
    33    Jiri strohalm                                  28.56%
    34    Hughes Network Systems                         28.00%
    35    DegNet GmbH                                    26.76%
    36    Louisiana State University                     26.61%
    37    University of Minnesota                        26.44%
    38    iway AG                                        25.73%
    39    RedIRIS                                        25.39%
    40    University of Iowa                             22.56%
    41    Universidade Federal de Santa Catarina, Brazil 22.26%
    42    Cisco                                          22.14%
    43    Monash University                              21.82%
    44    Hurricane Electric                             21.80%
    45    RENATER                                        21.55%
    46    TUBITAK ULAKBIM / ULAKNET                      21.46%
    47    Aristotle University of Thessaloniki           20.89%
    48    DataChambers                                   20.28%
    49    UNESP                                          19.85%
    50    Chubu Telecommunications                       19.06%
    51    Swisscom                                       18.83%
    52    Indiana University                             18.08%
    53    Free                                           18.04%
    54    FranTech Solutions                             17.69%
    55    Tulane University                              17.55%
    56    University of New Hampshire                    17.45%
    57    Leibniz Supercomputing Centre                  16.60%
    58    HEAnet                                         16.59%
    59    US Dept of Transportation                      16.55%
    60    GARR                                           16.27%
    61    XS4ALL                                         16.14%
    62    Defense Research and Engineering Network       15.24%
    63    DMZGlobal                                      14.26%
    64    PCextreme B.V.                                 13.80%
    65    RCS & RDS                                      13.25%
    66    PowerTech Information Systems AS               12.24%
    67    SURFnet                                        12.07%
    68    BIT BV                                         11.93%
    69    ATT                                            11.52%
    70    Academia Sinica Network                        11.34%
    71    Honesty Net Solutions (I) Pvt Ltd               9.85%
    72    UNINETT                                         9.48%
    73    Storm Internet                                  9.25%
    74    CESNET                                          9.18%
    75    University Of Lampung                           9.12%
    76    AAISP                                           8.88%
    77    prgmr.com                                       8.61%
    78    KDDI                                            8.49%
    79    Voxel / Internap                                8.29%
    80    Init7                                           8.19%
    81    AMRES - Serbian National R&E Network            8.06%
    82    Comcast                                         7.95%
    83    CJSC Progressive Technologies                   7.92%
    84    MediaCat Div./Community Network Center Inc.     7.17%
    85    green.ch AG                                     7.02%
    86    StarHub                                         6.68%
    87    OVH                                             6.30%
    88    UniNet                                          6.26%
    89    CORPORACION NACIONAL DE TELECOMUNICACIONES      6.02%
    90    National Technical University of Athens         5.91%
    91    Forthnet                                        5.81%
    92    Deutsche Telekom AG                             5.18%
    93    EPT Luxembourg                                  5.11%
    94    Energy Group Networks                           4.62%
    95    M1 Limited                                      4.56%
    96    Internode                                       4.33%
    97    BelWue                                          4.32%
    98    Quonix Networks                                 4.26%
    99    SMELLY BLACK DOG                                4.22%
   100    LENTEL                                          4.15%