{"id":2607,"date":"2016-08-10T06:00:54","date_gmt":"2016-08-10T06:00:54","guid":{"rendered":"https:\/\/live-infoblox-blog.pantheonsite.io\/?p=2607"},"modified":"2020-05-06T10:28:05","modified_gmt":"2020-05-06T17:28:05","slug":"could-sd-wan-change-ipv6-adoption-in-enterprises","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/","title":{"rendered":"Could SD-WAN Change IPv6 Adoption in Enterprises?"},"content":{"rendered":"<p>Using a hybrid-WAN may change your IPv6 addressing plan<\/p>\n<h2 id=\"toc-hId-649906454\">Internet Edge IPv6 Deployment<\/h2>\n<p>Typical enterprise networks connect to the Internet at their perimeter and this is the logical place to start an\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/IPv6\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">IPv6<\/a>\u00a0deployment.\u00a0 This is the part of the network topology that touches the Internet through various upstream ISP connections and this is the place to start to bring the IPv6 Internet connectivity into the enterprise.\u00a0 This \u201c<a href=\"http:\/\/www.networkworld.com\/article\/2221687\/cisco-subnet\/internet-edge-ipv6-deployment.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Internet Edge<\/a>\u201d model of IPv6 deployment has been recommended for years by\u00a0<a href=\"https:\/\/www.arin.net\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">ARIN<\/a>\u00a0and the other RIRs as well as the IPv6 community at large.\u00a0 Companies are encouraged to start by IPv6-enabling their public-facing web applications, their e-mail servers, and their authoritative external DNS servers.\u00a0 This has been the guidance that the\u00a0<a href=\"http:\/\/www.internetsociety.org\/deploy360\/blog\/2012\/07\/us-government-released-updated-ipv6-roadmap\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">U.S. Federal Government<\/a>\u00a0has given their departments and agencies.\u00a0 The IETF has also documented this recommendation with their Enterprise IPv6 Deployment Guidelines (<a href=\"https:\/\/tools.ietf.org\/html\/rfc7381\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">RFC 7381<\/a>) as the \u201cExternal Phase.\u201d\u00a0 Even Cisco provides guidance on\u00a0<a href=\"http:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/solutions\/Enterprise\/Borderless_Networks\/Internet_Edge\/InternetEdgeIPv6.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Deploying IPv6 in the Internet Edge<\/a>.<\/p>\n<p>After an enterprise has obtained their IPv6 addressing resources from their RIR and IPv6-enabled their Internet perimeter, the next step would be to bring IPv6 inward to the end-users.\u00a0 Paul Saab of Facebook gave a presentation at\u00a0<a href=\"https:\/\/www.nanog.org\/meetings\/nanog64\/agenda\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">NANOG64<\/a>\u00a0titled \u201c<a href=\"https:\/\/www.youtube.com\/watch?v=EfjdOc41g0s\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">The benefits of deploying IPv6 only<\/a>\u201c and on\u00a0<a class=\" bf_ungated_init\" href=\"https:\/\/www.nanog.org\/sites\/default\/files\/meetings\/NANOG64\/1033\/20150602_Huston_The_Benefits_Of_v3.pdf\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">slide 17 he showed a graph<\/a>\u00a0of daily IPv4 traffic compared to IPv6 traffic (see graph below).\u00a0 The reason that these traffic graphs look different is that end-users likely have IPv6 Internet connectivity on their mobile devices and at their home broadband Internet link, but they use an IPv4-only network during the day at \u00a0work.\u00a0 Even though most ISPs have IPv6 connectivity ready for enterprises and many content providers are enabling IPv6, corporate enterprises do not have IPv6 deployed to their internal users.\u00a0 Because IPv6 can perform better than IPv4 in some cases (see\u00a0<a href=\"https:\/\/community.infoblox.com\/t5\/IPv6-Center-of-Excellence\/Can-IPv6-Really-Be-Faster-than-IPv4-Part-1\/ba-p\/6419\" target=\"_blank\" rel=\"noopener noreferrer\">Part 1<\/a>,\u00a0<a href=\"https:\/\/community.infoblox.com\/t5\/IPv6-Center-of-Excellence\/Can-IPv6-Really-Be-Faster-than-IPv4-Part-2\/ba-p\/6748\" target=\"_blank\" rel=\"noopener noreferrer\">Part 2<\/a>), organizations will want to provide their end-users IPv6 Internet access sooner rather than later in their deployment schedule.<\/p>\n<p><span class=\"lia-message-image-wrapper lia-message-image-actions-narrow lia-message-image-actions-below\"><img decoding=\"async\" class=\"lia-media-image\" tabindex=\"0\" title=\"IB - SD-WAN and IPv6 Adoption - Paul Saab graph 3.jpg\" src=\"https:\/\/cixhp49439.i.lithium.com\/t5\/image\/serverpage\/image-id\/715i6FCA4911F13FDF67\/image-size\/original?v=v2&amp;px=-1\" alt=\"IB - SD-WAN and IPv6 Adoption - Paul Saab graph 3.jpg\" border=\"0\" \/><i class=\"lia-fa lia-fa-search-plus lia-media-lightbox-trigger\" tabindex=\"0\" aria-label=\"Enlarge image\"><\/i><\/span><\/p>\n<p>As an organization starts to bring IPv6 internally from their Internet DMZ, they advance IPv6 one layer-3 hop at a time inward to maintain IPv6 contiguity.\u00a0 Initially this starts by enabling IPv6 on the inside of their firewalls and then proceeding to IPv6-enable the core network.\u00a0 Eventually, the enterprise will have to implement IPv6 across the WAN and to the wired and wireless remote office access networks.\u00a0 This is what the IETF\u00a0<a href=\"https:\/\/tools.ietf.org\/html\/rfc7381\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">RFC 7381<\/a>\u00a0refers to as the \u201cInternal Phase\u201d.\u00a0 The following picture shows an organization that has received Provider Independent (PI)\u00a0<a href=\"http:\/\/www.iana.org\/assignments\/ipv6-address-space\/ipv6-address-space.xhtml\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">global unicast IPv6 addresses<\/a>\u00a0and advertises this \/36 prefix using\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Border_Gateway_Protocol\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">BGP<\/a>\u00a0to multiple upstream ISPs.\u00a0 The enterprise uses this global IPv6 addresses (2AAA:BBBB:C000::\/36) for all its DMZs and internal systems.\u00a0 Eventually, enterprises will IPv6-enable their end-users at their offices. That would mean deploying IPv6 across the corporate MPLS WAN.\u00a0 The same IPv6 prefix is used for corporate headquarters sites and branch offices.<\/p>\n<p><span class=\"lia-message-image-wrapper\"><img decoding=\"async\" class=\"lia-media-image\" tabindex=\"0\" title=\"IB - SD-WAN and IPv6 Adoption - Pic 1.jpg\" src=\"https:\/\/cixhp49439.i.lithium.com\/t5\/image\/serverpage\/image-id\/716i78E125009CD55CB6\/image-size\/original?v=v2&amp;px=-1\" alt=\"IB - SD-WAN and IPv6 Adoption - Pic 1.jpg\" border=\"0\" \/><i class=\"lia-fa lia-fa-search-plus lia-media-lightbox-trigger\" tabindex=\"0\" aria-label=\"Enlarge image\"><\/i><\/span><\/p>\n<h2 id=\"toc-hId-678535605\">Software-Defined WAN<\/h2>\n<p>Over the past few years, the networking industry has seen innovation taking place in the WAN and enterprises are exploring the potential cost savings of using a hybrid-WAN architecture.\u00a0 Enterprises that have maintained\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Multiprotocol_Label_Switching\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">MPLS WANs<\/a>\u00a0for decades have found them to be expensive, inflexible, limited in their ability to provide management visibility, and suffering from vendor lock-in.\u00a0 Enterprises have been exploring how they can use\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Internet_access\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Direct Internet Access<\/a>\u00a0(DIA) to augment their bandwidth and reduce installation times for new offices.\u00a0 Over the last decade, the cost of broadband Internet has fallen while the reliability has simultaneously increased to the point where it is suitable for most businesses.\u00a0 If enterprises use broadband Internet connectivity as another WAN connection to their branch offices, then they need solutions to help make the WAN secure, control application traffic flows over the diverse links, and manage and streamline the deployment.\u00a0 These advanced software features and tunnel overlays added to hybrid-WAN features have led to the coining of the term\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/SD-WAN\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Software-Defined WAN<\/a>.\u00a0 There are\u00a0<a href=\"http:\/\/www.networkworld.com\/article\/3045230\/software-defined-networking\/5-reasons-to-move-to-an-sd-wan.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">many reasons<\/a>\u00a0why an enterprise would want to use an SD-WAN system like this.\u00a0 You can read Gartner\u2019s \u201c<a href=\"https:\/\/www.gartner.com\/doc\/3173719\/market-guide-softwaredefined-wan\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Market Guide for Software-Defined WAN<\/a>\u201d to get an overview of the benefits of an SD-WAN and the major vendors offering SD-WAN connectivity devices and services.<\/p>\n<p>When an organization deploys SD-WAN, more often than not, Direct Internet Access (DIA) is involved.\u00a0 That typically means that the enterprise has purchased a business class of broadband Internet service (maybe for a larger office), or they purchased a residential subscriber class of broadband Internet connectivity (maybe for a small office, home office, or retail store).\u00a0 When a hybrid-WAN is deployed, as seen in the picture below, the branch will be connected both to the traditional corporate WAN and to the Internet.\u00a0 When it comes to addressing the branch, the organization will not want to have to re-address the network and systems in the branch to move to this new architecture.\u00a0 The enterprise will likely continue to use private IPv4 in the branch office, but lack of NAT66 will require the branch to use global IPv6 in the office.\u00a0 In the hybrid model, the IPv4 traffic from the branch, could use the branch router\u2019s routing tables to either forward the traffic across the WAN to the headquarters or through a NAT to the broadband ISP.\u00a0 However, the IPv6 traffic from the branch can only traverse the WAN to the headquarters to reach the Internet.<\/p>\n<p><span class=\"lia-message-image-wrapper\"><img decoding=\"async\" class=\"lia-media-image\" tabindex=\"0\" title=\"IB - SD-WAN and IPv6 Adoption - Pic 2.jpg\" src=\"https:\/\/cixhp49439.i.lithium.com\/t5\/image\/serverpage\/image-id\/717i3D178627486D8C81\/image-size\/original?v=v2&amp;px=-1\" alt=\"IB - SD-WAN and IPv6 Adoption - Pic 2.jpg\" border=\"0\" \/><i class=\"lia-fa lia-fa-search-plus lia-media-lightbox-trigger\" tabindex=\"0\" aria-label=\"Enlarge image\"><\/i><\/span><\/p>\n<h2 id=\"toc-hId-707164756\">SD-WAN and IPv6 Addressing<\/h2>\n<p>Now that we can visualize how SD-WAN might change an enterprise\u2019s IPv6 addressing plan, we should consider the possibilities and consider alternatives.\u00a0 Enterprises will not want to change the addressing at the branch office and we know that user\u2019s devices will have both IPv4 and IPv6 addresses as well as a desire for dual-protocol Internet connectivity.\u00a0 In the diagram below, the scenario where the branch only has Direct Internet Access (DIA) changes things slightly.\u00a0 With IPv4, the branch continues to use NAT when traffic goes to the Internet.\u00a0 There may well be a secure tunnel overlay across the Internet to join the branch to the headquarters location.\u00a0 With IPv4, the branch can continue to use internal addresses that follow the internal private IPv4 address plan.\u00a0 The IPv6 address space allocated by their RIR that is used at the corporate headquarters will be their global IPv6 address block.<\/p>\n<p>&nbsp;<\/p>\n<p><span class=\"lia-message-image-wrapper\"><img decoding=\"async\" class=\"lia-media-image\" tabindex=\"0\" title=\"IB - SD-WAN and IPv6 Adoption - Pic 3.jpg\" src=\"https:\/\/cixhp49439.i.lithium.com\/t5\/image\/serverpage\/image-id\/718iFB60D84D68B424FF\/image-size\/original?v=v2&amp;px=-1\" alt=\"IB - SD-WAN and IPv6 Adoption - Pic 3.jpg\" border=\"0\" \/><i class=\"lia-fa lia-fa-search-plus lia-media-lightbox-trigger\" tabindex=\"0\" aria-label=\"Enlarge image\"><\/i><\/span><\/p>\n<p>When these broadband Internet connections are used for the branch office, there isn\u2019t any\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Border_Gateway_Protocol\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">EBGP<\/a>\u00a0used to advertise the IPv6 address that the enterprise site may be using.\u00a0 Instead, these DIA connections imply that it is a small site and the IPv6 addresses for the site will come from the Provider Assigned (PA) block of IPv6 addresses that \u201cbelongs\u201d to the ISP.\u00a0 The problem here is that this creates a vendor lock-in situation when the branch uses PA IPv6 address space from the ISP.\u00a0 Since there isn\u2019t any NAT66 specification (not to mention a general recommendation to avoid it), the branch will not be able to use their corporate global IPv6 address space internally to NAT those IPv6 addresses to the broadband ISP\u2019s IPv6 address space.\u00a0 And most if not all organizations would want to\u00a0<a href=\"https:\/\/community.infoblox.com\/t5\/IPv6-Center-of-Excellence\/The-headache-of-IPv6-readdressing-and-the-potential-for-ULA\/ba-p\/6279\" target=\"_blank\" rel=\"noopener noreferrer\">avoid IPv6 re-addressing<\/a>.\u00a0 As mentioned before, the enterprise could still use the corporate global IPv6 address for the inside of the branch site along with a tunnel that traverses the Internet back to HQ.\u00a0 The branch nodes could reach the IPv6 Internet through the headquarters over the backhauled tunnel overlay, but the IPv6-enabled nodes at the branch would lack direct IPv6 Internet connectivity.<\/p>\n<p>One solution might be to use IPv6 Unique Local Addresses (ULA) (<a href=\"https:\/\/tools.ietf.org\/html\/rfc4193\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">RFC 4193<\/a>) and perform NPTv6 (<a href=\"https:\/\/tools.ietf.org\/html\/rfc6296\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">RFC 6296<\/a>) to avoid vendor lock-in.\u00a0 However, as Tom Coffeen has taught us, there are multiple ways to ruin our future networks using IPv6 ULA (see\u00a0<a href=\"https:\/\/community.infoblox.com\/t5\/IPv6-Center-of-Excellence\/3-Ways-to-Ruin-Your-Future-Network-with-IPv6-Unique-Local\/ba-p\/5663\" target=\"_blank\" rel=\"noopener noreferrer\">Part 1<\/a>,\u00a0<a href=\"https:\/\/community.infoblox.com\/t5\/IPv6-Center-of-Excellence\/3-Ways-to-Ruin-Your-Future-Network-with-IPv6-Unique-Local\/ba-p\/6177\" target=\"_blank\" rel=\"noopener noreferrer\">Part 2<\/a>).\u00a0\u00a0<a href=\"https:\/\/community.infoblox.com\/t5\/IPv6-Center-of-Excellence\/IPv6-ULA-and-NAT-Is-It-Better-Than-Global-Unicast\/ba-p\/3369\" target=\"_blank\" rel=\"noopener noreferrer\">Ed Horley has also compared the use of ULA<\/a>\u00a0and\u00a0<a href=\"http:\/\/www.howfunky.com\/2012_02_01_archive.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">NPTv6<\/a>\u00a0with IPv6 Global Unicast Addresses (GUA).\u00a0 Even though, historically, perimeter security products offered limited availability of NPTv6 features, more firewalls are starting to include NPTv6 as a standard feature.<\/p>\n<p>Furthermore, an enterprise may have two different ISPs at the branch office to add redundancy.\u00a0 In this situation, the branch will have multiple \/48s of PA IPv6 addresses.\u00a0 Enterprises would then be faced with the decision as to whether they want the internal branch office nodes to have two IPv6 addresses; i.e., one from each \/48 of PA IPv6 address space.\u00a0 IPv6 nodes can have multiple IPv6 addresses, but they will use the IPv6 address associated with the default route to source packets (<a href=\"https:\/\/tools.ietf.org\/html\/rfc6724\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">RFC 6724<\/a>).\u00a0 During a fail-over event, the nodes simply change to using the default gateway of the available ISP connection.<\/p>\n<p>One possibility would be to address the branch with the global IPv6 address space the enterprise was allocated and to disaggregate a \/48 for that \u201csite\u201d then ask the broadband ISP to re-advertise that site\u2019s \/48 into the Internet routing tables.\u00a0 If an enterprise has purchased a business-class service and not a residential-class of service, the ISP may be willing to do this.\u00a0 However,\u00a0<a href=\"https:\/\/community.infoblox.com\/t5\/IPv6-Center-of-Excellence\/Only-You-Can-Prevent-IPv6-Prefix-Disaggregation\/ba-p\/4201\" target=\"_blank\" rel=\"noopener noreferrer\">you want to avoid completely disaggregating<\/a>\u00a0your IPv6 \/36 of PI address space into \/48s for all of your branches.<\/p>\n<h2 id=\"toc-hId-735793907\">IPv6 Support in SD-WAN<\/h2>\n<p>As we have said before \u201c<a href=\"https:\/\/community.infoblox.com\/t5\/IPv6-Center-of-Excellence\/Making-a-New-Product-Make-it-Dual-Protocol\/ba-p\/3421\" target=\"_blank\" rel=\"noopener noreferrer\">If you are making a new product or service, it should be dual-protocol from the start<\/a>.\u201d\u00a0 Unfortunately, we do see new products launched in 2016 with IPv4-only connectivity.\u00a0 While, we prefer products have \u201c<a href=\"https:\/\/community.infoblox.com\/t5\/IPv6-Center-of-Excellence\/Mind-the-Gap-Feature-versus-Functional-Parity-in-IPv6\/ba-p\/3882\" target=\"_blank\" rel=\"noopener noreferrer\">functional parity<\/a>\u201d between their IPv4 and IPv6 capabilities, we may not always get what we want from a vendor.\u00a0 Along these lines, there may be a serious problem if an enterprise has already purchased an SD-WAN device and the manufacturer does not support IPv6.\u00a0 Soon, when the enterprise attempts to deploy IPv6 to the end-users at their branch offices, they will be unable to do so.\u00a0 Following is some information about SD-WAN vendors and their support of IPv6.<\/p>\n<ul>\n<li>Cisco offers their\u00a0<a href=\"http:\/\/www.cisco.com\/c\/en\/us\/solutions\/enterprise-networks\/intelligent-wan\/index.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Intelligent WAN<\/a>\u00a0(IWAN) hybrid-WAN solution. IWAN uses DMVPN for the secure tunnel overlay and\u00a0<a href=\"http:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/ios-xml\/ios\/sec_conn_dmvpn\/configuration\/15-s\/sec-conn-dmvpn-15-s-book\/ip6-dmvpn.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">DMVPN works over IPv4 or IPv6<\/a>, and IWAN leverages\u00a0<a href=\"http:\/\/docwiki.cisco.com\/wiki\/PfR3:Solutions:IWAN\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Performance Routing v3<\/a>\u00a0(PfRv3) for intelligent path control, but unfortunately\u00a0<a href=\"http:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/ios-xml\/ios\/pfrv3\/configuration\/15-mt\/pfrv3-15-mt-book\/pfrv3.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">PfRv3 does not support IPv6<\/a>.<\/li>\n<li>Citrix Cloudbridge claims that in\u00a0<a href=\"https:\/\/www.citrix.com\/blogs\/2014\/08\/14\/cloudbridge-7-3-where-visibility-automation-and-hybrid-cloud-meet-wan-optimization\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">version 7.3<\/a>\u00a0and in\u00a0<a class=\" bf_ungated_init\" href=\"http:\/\/docs.citrix.com\/content\/dam\/docs\/en-us\/cloudbridge\/7-4\/downloads\/en.cloudbridge.cb-wrapper-74-con.pdf\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">version 7.4<\/a>\u00a0that they support WAN optimization for IPv4 and IPv6.<\/li>\n<li>Riverbed\u2019s SteelConnect does have some IPv6 capabilities. Their\u00a0<a href=\"https:\/\/supportkb.riverbed.com\/support\/index?page=content&amp;id=S28010&amp;actp=LIST\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">documentation indicates<\/a>\u00a0that you can configure a SteelConnect Gateway to send an IPv6 RA.\u00a0 The\u00a0<a href=\"https:\/\/support.riverbed.com\/bin\/support\/download?did=hgc5k5odj0e955sd2uk2qr4ir5\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">SteelConnect Manager User Guide<\/a>\u00a0(version 1.20) also shows several other IPv6 configuration options. \u00a0Riverbed acquired\u00a0Ocedo, which offers a SD-WAN system that has cloud management and control. Their\u00a0<a class=\" bf_ungated_init\" href=\"https:\/\/cdn.ocedo.com\/media\/Datasheet.pdf\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">product datasheets<\/a>\u00a0lists that IPv6 is one of their features and\u00a0<a class=\" bf_ungated_init\" href=\"https:\/\/cdn.ocedo.com\/media\/Whitepaper.pdf\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">their documentation<\/a>\u00a0lists layer(3) functionality with IPv6.<\/li>\n<\/ul>\n<p>There are many other SD-WAN vendors in the market and asking them what their current and roadmap support plan for IPv6 should be part of your due diligence. \u00a0Remember, as IPv6 becomes increasingly important, having true feature parity in a SD-WAN solution will become a deciding factor for which vendor solution you select.<\/p>\n<h2 id=\"toc-hId-764423058\">Conclusions<\/h2>\n<p>As your enterprise embarks on its IPv6 deployment, you will obtain your IPv6 addresses from your RIR and start to create a\u00a0<a href=\"http:\/\/shop.oreilly.com\/product\/0636920033622.do\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">corporate-wide IPv6 addressing plan<\/a>.\u00a0 As an enterprise, you will want to use Provider-Independent (PI) global IPv6 addresses to prevent vendor lock-in.\u00a0 As your enterprise also moves forward with a hybrid-WAN deployment model, you should consider how this might change your IPv6 addressing plan.\u00a0 You will want to prevent vendor lock-in from using Provider-Assigned (PA) IPv6 address space for your branches, but as you disconnect branches from the private MPLS WAN you might not have a choice.\u00a0 Depending on the nature of your organizations, you may prefer one of these scenarios.<\/p>\n<ul>\n<li>If your organization is a large enterprise and you use business-class direct Internet for your large branches, then you would prefer to use your RIR-allocated IPv6 addresses for all your sites and have the ISPs route the individual \/48s to your sites.<\/li>\n<li>If your organization has Internet-edge devices at the branch sites that have NPTv6 capabilities, then you can use your own RIR-allocated IPv6 addresses for each branch.<\/li>\n<li>In both of the above cases, you could use your own RIR-allocated IPv6 addresses for your VPN tunnel overlay networks and for site-to-site communications as well as Internet communications.<\/li>\n<li>If your organization has very small branches, then using the PA IPv6 addresses from the ISP connecting your branches may be acceptable. Re-addressing a small office when switching providers may not be a significant burden.<\/li>\n<\/ul>\n<p>Over time, your organization may transition from a private WAN to a hybrid-WAN to a fully Internet-based WAN.\u00a0 Regardless of your design choices based on your requirements and constraints, you should have plenty of IPv6 addresses to change your design as your WAN continues to evolve over the coming decades.\u00a0 Use of global IPv6 addresses will help you overcome the challenges of NAT and allow for\u00a0<a href=\"https:\/\/community.infoblox.com\/t5\/IPv6-Center-of-Excellence\/Can-IPv6-Really-Be-Faster-than-IPv4-Part-2\/ba-p\/6748\" target=\"_blank\" rel=\"noopener noreferrer\">improved end-user Internet experience<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Using a hybrid-WAN may change your IPv6 addressing plan Internet Edge IPv6 Deployment Typical enterprise networks connect to the Internet at their perimeter and this is the logical place to start an\u00a0IPv6\u00a0deployment.\u00a0 This is the part of the network topology that touches the Internet through various upstream ISP connections and this is the place to [&hellip;]<\/p>\n","protected":false},"author":321,"featured_media":2608,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[17],"tags":[38,31,114],"class_list":{"0":"post-2607","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-ipv6-coe","8":"tag-ipv6","9":"tag-networking","10":"tag-sdn","11":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Could SD-WAN Change IPv6 Adoption in Enterprises?<\/title>\n<meta name=\"description\" content=\"Using a hybrid-WAN may change your IPv6 addressing plan\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Could SD-WAN Change IPv6 Adoption in Enterprises?\" \/>\n<meta property=\"og:description\" content=\"Using a hybrid-WAN may change your IPv6 addressing plan\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2016-08-10T06:00:54+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-05-06T17:28:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/image001-3.png\" \/>\n\t<meta property=\"og:image:width\" content=\"660\" \/>\n\t<meta property=\"og:image:height\" content=\"454\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Scott Hogg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Scott Hogg\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/\"},\"author\":{\"name\":\"Scott Hogg\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/ee71ac61fe2ea349f6e991e628d22f4c\"},\"headline\":\"Could SD-WAN Change IPv6 Adoption in Enterprises?\",\"datePublished\":\"2016-08-10T06:00:54+00:00\",\"dateModified\":\"2020-05-06T17:28:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/\"},\"wordCount\":2132,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/image001-3.png\",\"keywords\":[\"IPv6\",\"Networking\",\"SDN\"],\"articleSection\":[\"IPv6 CoE\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/\",\"name\":\"Could SD-WAN Change IPv6 Adoption in Enterprises?\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/image001-3.png\",\"datePublished\":\"2016-08-10T06:00:54+00:00\",\"dateModified\":\"2020-05-06T17:28:05+00:00\",\"description\":\"Using a hybrid-WAN may change your IPv6 addressing plan\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/image001-3.png\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/image001-3.png\",\"width\":660,\"height\":454,\"caption\":\"Could SD-WAN Change IPv6 Adoption in Enterprises?\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/could-sd-wan-change-ipv6-adoption-in-enterprises\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"IPv6 CoE\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/ipv6-coe\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Could SD-WAN Change IPv6 Adoption in Enterprises?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/ee71ac61fe2ea349f6e991e628d22f4c\",\"name\":\"Scott Hogg\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_321_1574118215-96x96.jpg\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_321_1574118215-96x96.jpg\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_321_1574118215-96x96.jpg\",\"caption\":\"Scott Hogg\"},\"description\":\"Scott Hogg has 30 years of network and security experience and is president of Hogg Networking with. Scott Hogg specializes in teaching Internet Protocol version 6 (IPv6) and providing implementation guidance. Scott is CCIE #5133 (Emeritus) and CISSP #4610. Scott is Chair Emeritus of the Rocky Mountain IPv6 Task Force (RMv6TF), a member of the IPv6 Center of Excellence (COE), and co-author of the Cisco Press book on IPv6 Security.\",\"sameAs\":[\"https:\\\/\\\/hexabuild.io\"],\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/scott-hogg\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Could SD-WAN Change IPv6 Adoption in Enterprises?","description":"Using a hybrid-WAN may change your IPv6 addressing plan","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/","og_locale":"en_US","og_type":"article","og_title":"Could SD-WAN Change IPv6 Adoption in Enterprises?","og_description":"Using a hybrid-WAN may change your IPv6 addressing plan","og_url":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/","og_site_name":"Infoblox Blog","article_published_time":"2016-08-10T06:00:54+00:00","article_modified_time":"2020-05-06T17:28:05+00:00","og_image":[{"width":660,"height":454,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/image001-3.png","type":"image\/png"}],"author":"Scott Hogg","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Scott Hogg","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/"},"author":{"name":"Scott Hogg","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/ee71ac61fe2ea349f6e991e628d22f4c"},"headline":"Could SD-WAN Change IPv6 Adoption in Enterprises?","datePublished":"2016-08-10T06:00:54+00:00","dateModified":"2020-05-06T17:28:05+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/"},"wordCount":2132,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/image001-3.png","keywords":["IPv6","Networking","SDN"],"articleSection":["IPv6 CoE"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/","url":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/","name":"Could SD-WAN Change IPv6 Adoption in Enterprises?","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/image001-3.png","datePublished":"2016-08-10T06:00:54+00:00","dateModified":"2020-05-06T17:28:05+00:00","description":"Using a hybrid-WAN may change your IPv6 addressing plan","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/image001-3.png","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/image001-3.png","width":660,"height":454,"caption":"Could SD-WAN Change IPv6 Adoption in Enterprises?"},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/could-sd-wan-change-ipv6-adoption-in-enterprises\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"IPv6 CoE","item":"https:\/\/www.infoblox.com\/blog\/category\/ipv6-coe\/"},{"@type":"ListItem","position":3,"name":"Could SD-WAN Change IPv6 Adoption in Enterprises?"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/ee71ac61fe2ea349f6e991e628d22f4c","name":"Scott Hogg","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_321_1574118215-96x96.jpg","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_321_1574118215-96x96.jpg","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_321_1574118215-96x96.jpg","caption":"Scott Hogg"},"description":"Scott Hogg has 30 years of network and security experience and is president of Hogg Networking with. Scott Hogg specializes in teaching Internet Protocol version 6 (IPv6) and providing implementation guidance. Scott is CCIE #5133 (Emeritus) and CISSP #4610. Scott is Chair Emeritus of the Rocky Mountain IPv6 Task Force (RMv6TF), a member of the IPv6 Center of Excellence (COE), and co-author of the Cisco Press book on IPv6 Security.","sameAs":["https:\/\/hexabuild.io"],"url":"https:\/\/www.infoblox.com\/blog\/author\/scott-hogg\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/2607","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/321"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=2607"}],"version-history":[{"count":1,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/2607\/revisions"}],"predecessor-version":[{"id":2609,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/2607\/revisions\/2609"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/2608"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=2607"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=2607"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=2607"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}