Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


December 06, 2006

Look Before You Leap into IPv6 with Teredo

RSS
Subscribe to Windows IT Pro | See More Protocols Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

We're told that the future of the Internet revolves around the IPv6 protocol. Meanwhile, the majority of computers on the Internet still use IPv4. The two protocols are different enough that key software packages that are designed for IPv4 are unable to properly handle IPv6 traffic. This is of course one of the major hurdles for IPv6 adoption.

To help with this problem, Microsoft developed the open Teredo protocol, which tunnels IPv6 traffic over IPv4 networks when IPv6 clients are behind some sort of Network Address Translation (NAT) device that doesn't understand IPv6. If you're interested in the technical specifications for Teredo, you can read RFC 4380, "Teredo: Tunneling IPv6 over UDP through Network Address Translations (NATs)," at the URL below.

http://www.rfc-editor.org/rfc/rfc4380.txt

Because Teredo is an open specification, Teredo software packages are available for a variety of platforms, including Mac OS X, Linux, BSD, and Sun Microsystems Solaris. One such package is Miredo, at the URL below.

http://www.simphalempin.com/dev/miredo

For Windows, Teredo first appeared in service packs for Windows XP and Windows Server 2003. It's also a standard part of Windows Vista and will be a standard part of Longhorn when it's released. Teredo is a decent idea, however you should understand some security implications before you jump into using the technology.

Last week, Symantec published a white paper titled "The Teredo Protocol: Tunneling Past Network Security and Other Security Implications," written by Dr. James Hoagland, principal security researcher with Symantec Advanced Threat Research. The white paper presents an examination of real and potential security problems. For example, Hoagland explains how worms that use network layer 3 or 4 could use Teredo to escape a contained IPv6 network and reach remote IPv6 networks. You recall that the Slammer worm was able to propagate itself by using only one UDP packet.

Hoagland also writes that security devices such as intrusion detection and prevention systems (IDSs/IPSs) that are designed for IPv4 don't understand IPv6 traffic. Thus, the IPv4 devices can't enforce adequate security controls on IPv6 traffic encapsulated in IPv4 packets.

Another problem is that Teredo might allow unwanted traffic into the IPv6 or IPv4 network. Other potential security problems relate to the possibilities of creating a Denial of Service (DoS) condition in both Teredo clients and servers and the ability for remote systems to traverse the NAT in ways that are probably undesirable.

If you're interested in using Teredo, by all means download a copy of Symantec's white paper (at the URL below) and read it over carefully. It might save you many headaches and answer a lot of questions before they even arise as a result of oddities in your network. http://www.symantec.com/avcenter/reference/Teredo_Security.pdf

Keep in mind that the white paper discusses Teredo in general and is based on the associated RFC. Hoagland said that Symantec intends to look specifically at Teredo in Windows Vista sometime in the future. So keep an eye out for that white paper to become available.

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
What You Need to Know About Microsoft's x64 Server Product Plans

What do Longhorn Server, Windows Compute Cluster Server, and Windows Vista have in common? The x64 platform. ...

Anti-Virus Vendors Prepare for War with Microsoft ... Again

When Microsoft announced its Windows Live OneCare security and PC health product over five years (as MSN OneCare), Symantec, McAfee, and the other consumer-oriented security vendors reacted with stunning vigor. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Security Whitepapers Sustainable Compliance: How to reconnect compliance, security and business goals

The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Related Events Security Summit

Cutting Costs with Client Management

Top 10 Email Security Challenges and Solutions

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format

Test Drive IT Solutions and Get Free Music Downloads
Solve your toughest IT problems with these free downloads and receive 5 free music downloads!


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home asp.netPRO Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement | Reprints and Licensing