
IPB195: Start Network Automation with IPv6!
About this episode
Interactive timestamps
Jump to segmentGet every episode summarized
Each time The Everything Feed - All Packet Pushers Pods publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
190 searchable segments. Every word is indexed and playable.
Full transcript
The Everything Feed - All Packet Pushers Pods — IPB195: Start Network Automation with IPv6!. Machine-transcribed; use the interactive transcript above to jump the player to any line.
0:00Welcome to the IPv6 Buzz, where we dare to dive into the 128-bit address-based wormhole I'm Ed Orley. And I'm Nick Baraleo. We discuss everything IPv6 on the show from strategy, design, deployment, operations, and even internet standards. And I'm Tom Koffee. We've spent 20 plus years working with the IPv6 protocol. We work on getting IPv6 working. And we're here to share some lessons learned and how to avoid common mistakes. Hey, hey, welcome back to the IPv6 Buzz. And Tom is out on assignment this time around. So you just have Nick and I. That's more than enough probably in most situations. Yep, Tom's out doing good work on assignment. I love that. So we wanted to talk this episode really around IPv6 and automation. And probably a little bit different tax than how most folks are thinking about it.
1:02Because I think automation is one of the things that many now engineers are probably thinking about or actively working on or trying to figure out how it's going to fit within their workflow, their process, and how they do network engineering. But they're probably having a lot of difficulty figuring out where to start. Not just around the tooling and what platforms to potentially use around automation. Are you going to buy commercial product like potential or are you going to start building your own with Python or you're going to use something like Ansible, although I seems like Ansible has fallen out of favor a little bit. But your approach on that side is very much around like, oh, I have to figure out how to touch my production network or touch my lab and figure out the things that I want to try and standardize across support. And I would like to present a different option. And maybe one that makes a lot more sense when you think about it and step back and think about it, I would like to use IPv6 as a rationale for why you would want to automate.
2:06And we can go through the sort of cadre list of things that I think are going to be easier to do with automation when you're trying to do work with IPv6. But I think really the rationale behind it is that you want to be able to work on your equipment. You want to be able to use automation to be able to change and configure stuff. But you don't necessarily want to be changing your IPv4 related information because it might have some sort of surface impact on you. But you're trying to learn how to automate things, right? So you want to be able to communicate with the router, communicate with the switching, communicate with your firewalls. But maybe do changes that really may or may not have direct impact on your production environment of the way that you could be adverse. And I think V6 is a great opportunity to actually do that because they're two different protocols, they're shipping the night. There's very few things you can do in one that will negatively impact the other. There are a few changes so you can do around that. But hopefully you're not doing those sorts of changes. And you can start very simply. It also allows you to work very,
3:13very much on building clean libraries and resources to be able to do the right thing with addresses. And I don't know, Nick, do you think this is a good idea or do you think I'm going to completely crazy? We already know I'm completely crazy, but we'll see if this idea is completely crazy. That's the point. That's beside the point. No, I do think this is an interesting take on it that makes a lot of sense. And it sort of highlights a couple of things, or I'm going to highlight a couple of things that you said without really saying. So you have a network, right? You've got an existing network legacy, whatever, right? Maybe it's been around a year, maybe it's been around with 30. But it works, right? Because if it wasn't working, you'd be fixing it. So you have this existing presumably IPv4 network. And you want to add something to it, right? It's not, it's a change in so much that it's, you know, you're literally changing something, but you're adding something in parallel rather than changing something that already works. So there is an element of
4:22lower risk, I think, especially if you're an enterprise network and you're running something like OSPF as your IGP, OSPF3 is a completely separate, you know, you're going to configure that separately, then you do your legacy OSPF. So, you know, your IGP is going to be a little bit safer to change that. It's going to be safer to, you know, to add IPv6 addressing onto network elements and onto hosts and stuff. Yeah, obviously there's considerations involved there, but I do think that this is a good opportunity to consider how you can make it, you know, how you can do it more easily. And and you're going to do it over the existing network, right? So you're not, you're not, you know, changing the measurement by measuring it kind of situation. Yeah, you're not, you're not trying to change the wheels on the car as you're driving a race. Yeah. And I think that's an important
5:28distinction. And I think it's, it's also a safe bet to assume that even if you make technical mistakes within your configuration for IPv6, it should have low to no impact on the existing forwarding plan and configuration of your V4 related network. And this gives you the sort of chops to start learning what the change and workflow needs to be within automation environment that you're, that you're sort of testing and trying to build out. And so it gives you a lot more sort of practical feedback with a lot less potential, you know, I guess, um, blast zone for impact in terms of mistakes or configuration mistakes or scripting errors or even, even errors around, um, maybe loop prevention and other things of, of you going in and writing too much stuff to, to particular device that now that can still have
6:28impact on on both V4 and V6 depending on who resources you starve. Yeah, I mean, you create a loop then, I mean, but that's, you know, you're talking Spanish with this layer too, right? I mean, you create a routing loop, sure. Yeah. Or even loops within your, your automation where you're trying to go in and figure something in and then it's just chewing up resources and starving out the, you know, the control plan because you, yeah, I'm gonna try to do something strange. So, but you have control plan policing on your devices, right? Never. I'm getting sweaty thinking about it. So I think, so I think it's a really good opportunity because you get, you get sort of the best of sort of two operational things that you might have to do, which is adopting IPv6 and adopting some sort of network automation within your environment. So I think it's a, it's a low impact, um, you know, sort of, you know, lower risk event to be able to go ahead and make use of V6 for the purpose of getting automation started within your network.
7:34So I think it's, it's, it's, um, you know, it's, it's mixing your, your peanut butter and chocolate and ending up with something better. Mm-hmm. Indeed. So, so I think I'm a proponent of doing this. I've done this with several projects and I think it's a great way to start. And I think there's a couple other side benefits that you get out of this. And one of the things that I've noticed from building a lot of proof of concept labs is that typing V6 addresses is very, very prone to type of mistakes, just in general. And, um, even with cut and taste, I've noticed that, um, if you don't quite catch the prefix correctly or you don't have the right number of nibbles that are caught within, within the set up, you might, you might be short one nibble and not realize it. Or you clip off the very first number. Very first number. It's a set of 2600. It's just 600. 600? Yes. So, uh, not that we've ever lived this before.
8:36And, and, and suddenly, you know, you can control this a lot better by using, you know, standard templating and, and, and, and string validations and things of that nature to be able to make sure that your, your addresses are correct and, uh, and the syntax works. And you can also make use of common Python libraries to be able to make things better for you in terms of validating and checking inputs. So, even if you're providing an alternate method to, to input the information, maybe it's a CSV or something else that you're structurally sort of organizing, uh, that you're going to import and run through, um, you can still do validation checks on the address at the time that you're taking it. Um, I don't, I don't know, Nick, if that's something that you do within any of the, any of the stuff that you do or if you're more of the wild man, and you just take any input and go ahead and, and apply it. Um, I don't currently do, and so I'm sort of automation to Jason, like, I'll do my own stuff to make my life easier, you know, kind of like, I've always done, but I'm not like, you know, I'm not like a Chris Cummings or, you know,
9:39somebody like that that he is an automate, you know, has been an automation engineer. Like, all right. Um, you know, I can do it. I understand it. I'm in favor of it, um, but it isn't my core competency. And so I don't really do, when I'm doing it, I rely on tooling. Like if I want a new address, I just use the code to ask the net box API or, you know, IPAM of your choice, I typically use net box to just give me the next one, right? And there's, I guess there's a little bit of validation code in there because I have it set to never give me colon colon, never give me colon, got your colon colon one. And then, you know, go on from there. So, you know, there's a little bit, yeah, a little bit of bounce checking just to make sure you're very little. I, we all have to now test the IPv6 army site to see how many, how much bounce checking, oh, God. It's, it's a challenge. But I think what's great is that this will give you a tremendous
10:45amount of opportunity to go through things like input validations, output validations to work through that with your tooling sets. If you're using ginger two templates or, or your, you're making use of Python and Python libraries to, to really sort of help you along, maybe, maybe you're using netmico. So, you know, shout out to Kirkbiers and, and, and, and the stuff that's, he's been working on. I think there's a lot of, of opportunity to build up a skill set and clearly you can do all this for IPv4 in addition. So it's not like it's exclusive to an IPv6 thing. But what I'm saying is, if you want to be able to learn and practice with low, relatively low impact and not everyone has a proof of concept lab, not everyone has a lab to use. Everyone's, everyone's got a production environment, which is everyone's lab, right? So that's the reason that this is, this is the other alternative angle that this is coming. I'm gasping, I'm gasping. I know, I'm very spoiled in the
11:46amount of toys I have to play with. But, you know, I, until you until you start actively adding posts in, you can do whatever you want to the backbone. I mean, I've famously said this multiple times, but a million years ago, I renumbered a statewide backbone to be six addressing in the middle of the day. And nobody knew I did it because nothing went now. Right. I mean, we had to move it. I wrote some really crummy shell scripts. It was done in like 90 minutes. Yep. Yeah, this is sort of the unique space and opportunity. And you can still use these, these principle sets for even, if you're doing things in like, I don't know, even GE or or any other, you know, sort of, you know, GNS3 or any of this sort of classic lab environments, you can do that. Obviously doing a container lab and a net lab is a little different because those things configure those things for you. So not as much of a worry. So you're just going
12:49to do and see you am or work and you're off to the races, right? So they're automating it for you. So yeah, doing your automation already. It's, it does make things a lot easier. And I think having a chance to sort of test that out and get an environment built is pretty cool. So when I think that's, I think, technically, I think really you should be doing all that on lacks on the Linux side, right? Because while there's in theory, possibility of doing a macOS, I don't think there's, I don't think there's I don't think there's builds really for the R-map architecture for many of the, the virtual device types to be able to run. So you're pretty much needing GNS. Yeah, I don't know. I, you know, I have a feeling that this is, you know, I love to use the let them eat cake attitude term. But I always feel like when I say this, it's like, I don't like to do stuff like that on my main workstation. Like I like to have a Linux box over here that I
13:54just get into and do stuff. And that way I can be on a Chromebook or a Mac or whatever, right? I tend to keep my workstations relatively clean of that kind of stuff. You know, you don't want to do, and just for everyone on the Python side, when I say pip, I mean pip three, but yeah, you can just do all your pip installs. And this is why I hate Python so much. I hate it so much. Yeah, when I run everything in isolation, right? Yeah, there's, so I mentioned Chris Cummings earlier, he was telling me just the other day, there's a, there's a better way to, like the virtual VNV, the EMV stuff is no longer like, yeah, there's a better way to do it now, and I'm just like, I don't care. I'm going to write it and go if I can. So funny. Yeah. Well, I do, I think we'll keep this one short, but I do recommend that everyone, if the discussion comes up around, hey, we wanted to start figuring out automation with
14:54in our environment, but we feel like it's maybe it's, it's pretty risky for, for what we need to do as an organization, maybe starting with V6 within that small portion of your network that you're willing to, to experiment on is, is a safe bet because of the fact that really isn't going to impact anything on a production basis. And so you might have an easier time selling and working through that, especially if you don't have clients that are connected, realistically, you're just going to be testing from node to node, from a network basis, and just to validate that you're doing things like, you know, you're routing protocols for up, or you're able to ping from one side to the other, et cetera. And so I think that's a really great way to start off and a great way to be able to learn, you know, a lot of syntax functions within Python, a lot of things that you might want to be able to sort of test in terms of, you know, templating and other things of that nature. And if you can get it working in V6, I guarantee you can get it working in V4. Yeah. Yeah. Yeah. I mean, you're not wrong. Like I've been fighting with that kind of thing all
15:55week. And as much as I hate to admit it, some stuff is just easier in legacy IP. Yeah. For sure. And there's just a lot more bounce controls that are put in for, you know, IPv4. There was a lot more work that was done just just a hundred years of history behind it, you know, however many, 50 years of history. So yeah, it's, and it's got a lot more just maturity in terms of the tooling and libraries that people have written. So I think there's an advantage there, but the reality is is you may or may not be allowed to touch your network with automation tools to make those sorts of changes. And it may be a much higher risk. And so, you know, putting in V6 may be actually easier to do. With that, I say, go forth and deploy. Yes. Crossword. Learn all this. Make everything a 64. Everything's a slash 64. Except for, except for your net six four. Yeah, it's a 96.
16:57But there's a good rationale for that one. Well, there's a there's a rationale. There's a the RFC says so. That's what I think that's what I've sticking to pretty much. Cool. Why? I think I think we'll put a pen in it and say like, hey, just if you're looking for that excuse to try something out in the automation category, but you're a little nervous about which, you know, making changes on networks and trying to figure out what is low risk. I actually think V6 is pretty low risk in terms of, in terms of, you know, the opportunity to learn that stuff. So I would say use it as the excuse to go ahead and do that. Automate all the things. And the first thing is V6. Yes. Thanks for joining us for this episode of IPv6 buzz. If you've got feedback or follow up on this topic, send us a message at packupusures.net slash fu where fu stands for follow up. We'd love to hear from you and continue the conversation. Also at packupusures.net, you'll find a range of other deep dive technical podcasts for IT
18:00pros. There's a whole lot more on the packupusures site as well, such as tutorial videos and a community Slack channel where you can talk with industry peers and experts. So whether you're deep in your career or just starting up, packupusures is the place to go to grow both your skills and your personal network. So long and until next time, we'll see you on the IPv6 internet.
More episodes
More from The Everything Feed - All Packet Pushers Pods

TNO071: The Network Team Is Drowning. Is AI the Life Raft? (Sponsored)
The Everything Feed - All Packet Pushers Pods

HN840: How to Make a Technology Buying Decision
The Everything Feed - All Packet Pushers Pods

IPB207: Flying Blind: Monitoring Might Not See IPv6
The Everything Feed - All Packet Pushers Pods

N4N063: Link Layer Discovery Protocol
The Everything Feed - All Packet Pushers Pods