Solved

Do we still need DMZ and VPN in IPv6 world

Posted on 2011-09-05
5
697 Views
Last Modified: 2012-05-12
We create DMZ and VPN in IPv4 to protect and to access our internal network. When we are in IPv6, how do we create a DMZ or VPN do we need them?
0
Comment
Question by:tommym121
  • 3
5 Comments
 
LVL 69

Accepted Solution

by:
Qlemo earned 250 total points
ID: 36485971
Strange question. IPv6 does nothing in regard of security or privacy, so yes, we will still need both DMZ and VPN.

A VPN does not only build a tunnel between two peers or networks, the traffic is authenticated and encrypted. Both can be very important parts of the tunnel.

A DMZ isolates a network from another one. The DMZ network usually isn't protected that much, and whenever access to the LAN is necessary, firewalling is asked for, to protect from malicious content.

Further, you can still have your private IPv6 addresses, which are not routable in the Internet - still you will need some kind of NAT for that. The "only" advantage of IPv6 directly visible is that the addresses will not get exhausted for the next decades.
0
 
LVL 19

Assisted Solution

by:bevhost
bevhost earned 250 total points
ID: 36486044
A DMZ will make your firewall rules a lot simpler.  It's not *required* though.  if you did it with IPv4 you will probably continue to do it with IPv6, unless it was there just because of the IPv4 NAT.

Also NAT in IPv6 is poorly supported and difficult to implement and is generally a bad idea.

The VPN won't add any value unless it has some sort of encryption.

The methods for creating VPN and DMZ are similar in IPv6 and IPv4.

0
 
LVL 19

Expert Comment

by:bevhost
ID: 36486047
0
 
LVL 19

Expert Comment

by:bevhost
ID: 36486049
0
 

Author Closing Comment

by:tommym121
ID: 36488055
Thanks
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Routing between two networks? 10 56
VPS for routing recomendations 3 50
Use of vpn-filter value  in S2S VPN 2 35
IPSec Site to Site VPN Topology 6 24
#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question