
- •For Web Developers
- •Contents at a Glance
- •Table of Contents
- •List of Figures
- •List of Tables
- •Foreword
- •Why Does Microsoft Care About IPv6?
- •Preface
- •Acknowledgments
- •Introduction
- •Who Should Read This Book
- •What You Should Know Before Reading This Book
- •Organization of This Book
- •Appendices of This Book
- •About the Companion CD-ROM
- •System Requirements
- •IPv6 Protocol and Windows Product Versions
- •A Special Note to Teachers and Instructors
- •Disclaimers and Support
- •Technical Support
- •Limitations of IPv4
- •Consequences of the Limited IPv4 Address Space
- •Features of IPv6
- •New Header Format
- •Large Address Space
- •Stateless and Stateful Address Configuration
- •IPsec Header Support Required
- •Better Support for Prioritized Delivery
- •New Protocol for Neighboring Node Interaction
- •Extensibility
- •Comparison of IPv4 and IPv6
- •IPv6 Terminology
- •The Case for IPv6 Deployment
- •IPv6 Solves the Address Depletion Problem
- •IPv6 Solves the Disjoint Address Space Problem
- •IPv6 Solves the International Address Allocation Problem
- •IPv6 Restores End-to-End Communication
- •IPv6 Uses Scoped Addresses and Address Selection
- •IPv6 Has More Efficient Forwarding
- •IPv6 Has Support for Security and Mobility
- •Testing for Understanding
- •Architecture of the IPv6 Protocol for Windows Server 2008 and Windows Vista
- •Features of the IPv6 Protocol for Windows Server 2008 and Windows Vista
- •Installed, Enabled, and Preferred by Default
- •Basic IPv6 Stack Support
- •IPv6 Stack Enhancements
- •GUI and Command-Line Configuration
- •Integrated IPsec Support
- •Windows Firewall Support
- •Temporary Addresses
- •Random Interface IDs
- •DNS Support
- •Source and Destination Address Selection
- •Support for ipv6-literal.net Names
- •LLMNR
- •PNRP
- •Literal IPv6 Addresses in URLs
- •Static Routing
- •IPv6 over PPP
- •DHCPv6
- •ISATAP
- •Teredo
- •PortProxy
- •Application Support
- •Application Programming Interfaces
- •Windows Sockets
- •Winsock Kernel
- •Remote Procedure Call
- •IP Helper
- •Win32 Internet Extensions
- •Windows Filtering Platform
- •Manually Configuring the IPv6 Protocol
- •Configuring IPv6 Through the Properties of Internet Protocol Version 6 (TCP/IPv6)
- •Configuring IPv6 with the Netsh.exe Tool
- •Disabling IPv6
- •IPv6-Enabled Tools
- •Ipconfig
- •Route
- •Ping
- •Tracert
- •Pathping
- •Netstat
- •Displaying IPv6 Configuration with Netsh
- •Netsh interface ipv6 show interface
- •Netsh interface ipv6 show address
- •Netsh interface ipv6 show route
- •Netsh interface ipv6 show neighbors
- •Netsh interface ipv6 show destinationcache
- •References
- •Testing for Understanding
- •The IPv6 Address Space
- •IPv6 Address Syntax
- •Compressing Zeros
- •IPv6 Prefixes
- •Types of IPv6 Addresses
- •Unicast IPv6 Addresses
- •Global Unicast Addresses
- •Topologies Within Global Addresses
- •Local-Use Unicast Addresses
- •Unique Local Addresses
- •Special IPv6 Addresses
- •Transition Addresses
- •Multicast IPv6 Addresses
- •Solicited-Node Address
- •Mapping IPv6 Multicast Addresses to Ethernet Addresses
- •Anycast IPv6 Addresses
- •Subnet-Router Anycast Address
- •IPv6 Addresses for a Host
- •IPv6 Addresses for a Router
- •Subnetting the IPv6 Address Space
- •Step 1: Determining the Number of Subnetting Bits
- •Step 2: Enumerating Subnetted Address Prefixes
- •IPv6 Interface Identifiers
- •EUI-64 Address-Based Interface Identifiers
- •Temporary Address Interface Identifiers
- •IPv4 Addresses and IPv6 Equivalents
- •References
- •Testing for Understanding
- •Structure of an IPv6 Packet
- •IPv4 Header
- •IPv6 Header
- •Values of the Next Header Field
- •Comparing the IPv4 and IPv6 Headers
- •IPv6 Extension Headers
- •Extension Headers Order
- •Hop-by-Hop Options Header
- •Destination Options Header
- •Routing Header
- •Fragment Header
- •Authentication Header
- •Encapsulating Security Payload Header and Trailer
- •Upper-Layer Checksums
- •References
- •Testing for Understanding
- •ICMPv6 Overview
- •Types of ICMPv6 Messages
- •ICMPv6 Header
- •ICMPv6 Error Messages
- •Destination Unreachable
- •Packet Too Big
- •Time Exceeded
- •Parameter Problem
- •ICMPv6 Informational Messages
- •Echo Request
- •Echo Reply
- •Comparing ICMPv4 and ICMPv6 Messages
- •Path MTU Discovery
- •Changes in PMTU
- •References
- •Testing for Understanding
- •Neighbor Discovery Overview
- •Neighbor Discovery Message Format
- •Neighbor Discovery Options
- •Source and Target Link-Layer Address Options
- •Prefix Information Option
- •Redirected Header Option
- •MTU Option
- •Route Information Option
- •Neighbor Discovery Messages
- •Router Solicitation
- •Router Advertisement
- •Neighbor Solicitation
- •Neighbor Advertisement
- •Redirect
- •Summary of Neighbor Discovery Messages and Options
- •Neighbor Discovery Processes
- •Conceptual Host Data Structures
- •Address Resolution
- •Neighbor Unreachability Detection
- •Duplicate Address Detection
- •Router Discovery
- •Redirect Function
- •Host Sending Algorithm
- •References
- •Testing for Understanding
- •MLD and MLDv2 Overview
- •IPv6 Multicast Overview
- •Host Support for Multicast
- •Router Support for Multicast
- •MLD Packet Structure
- •MLD Messages
- •Multicast Listener Query
- •Multicast Listener Report
- •Multicast Listener Done
- •Summary of MLD
- •MLDv2 Packet Structure
- •MLDv2 Messages
- •The Modified Multicast Listener Query
- •MLDv2 Multicast Listener Report
- •Summary of MLDv2
- •MLD and MLDv2 Support in Windows Server 2008 and Windows Vista
- •References
- •Testing for Understanding
- •Address Autoconfiguration Overview
- •Types of Autoconfiguration
- •Autoconfigured Address States
- •Autoconfiguration Process
- •DHCPv6
- •DHCPv6 Messages
- •DHCPv6 Stateful Message Exchange
- •DHCPv6 Stateless Message Exchange
- •DHCPv6 Support in Windows
- •IPv6 Protocol for Windows Server 2008 and Windows Vista Autoconfiguration Specifics
- •Autoconfigured Addresses for the IPv6 Protocol for Windows Server 2008 and Windows Vista
- •References
- •Testing for Understanding
- •Name Resolution for IPv6
- •DNS Enhancements for IPv6
- •LLMNR
- •Source and Destination Address Selection
- •Source Address Selection Algorithm
- •Destination Address Selection Algorithm
- •Example of Using Address Selection
- •Hosts File
- •DNS Resolver
- •DNS Server Service
- •DNS Dynamic Update
- •Source and Destination Address Selection
- •LLMNR Support
- •Support for ipv6-literal.net Names
- •Peer Name Resolution Protocol
- •References
- •Testing for Understanding
- •Routing in IPv6
- •IPv6 Routing Table Entry Types
- •Route Determination Process
- •Strong and Weak Host Behaviors
- •Example IPv6 Routing Table for Windows Server 2008 and Windows Vista
- •End-to-End IPv6 Delivery Process
- •IPv6 on the Sending Host
- •IPv6 on the Router
- •IPv6 on the Destination Host
- •IPv6 Routing Protocols
- •Overview of Dynamic Routing
- •Routing Protocol Technologies
- •Routing Protocols for IPv6
- •Static Routing with the IPv6 Protocol for Windows Server 2008 and Windows Vista
- •Configuring Static Routing with Netsh
- •Configuring Static Routing with Routing and Remote Access
- •Dead Gateway Detection
- •References
- •Testing for Understanding
- •Overview
- •Node Types
- •IPv6 Transition Addresses
- •Transition Mechanisms
- •Using Both IPv4 and IPv6
- •IPv6-over-IPv4 Tunneling
- •DNS Infrastructure
- •Tunneling Configurations
- •Router-to-Router
- •Host-to-Router and Router-to-Host
- •Host-to-Host
- •Types of Tunnels
- •PortProxy
- •References
- •Testing for Understanding
- •ISATAP Overview
- •ISATAP Tunneling
- •ISATAP Tunneling Example
- •ISATAP Components
- •Router Discovery for ISATAP Hosts
- •Resolving the Name “ISATAP”
- •Using the netsh interface isatap set router Command
- •ISATAP Addressing Example
- •ISATAP Routing
- •ISATAP Communication Examples
- •ISATAP Host to ISATAP Host
- •ISATAP Host to IPv6 Host
- •Configuring an ISATAP Router
- •References
- •Testing for Understanding
- •6to4 Overview
- •6to4 Tunneling
- •6to4 Tunneling Example
- •6to4 Components
- •6to4 Addressing Example
- •6to4 Routing
- •6to4 Support in Windows Server 2008 and Windows Vista
- •6to4 Host/Router Support
- •6to4 Router Support
- •6to4 Communication Examples
- •6to4 Host to 6to4 Host/Router
- •6to4 Host to IPv6 Host
- •Example of Using ISATAP and 6to4 Together
- •Part 1: From ISATAP Host A to 6to4 Router A
- •Part 2: From 6to4 Router A to 6to4 Router B
- •Part 3: From 6to4 Router B to ISATAP Host B
- •References
- •Testing for Understanding
- •Introduction to Teredo
- •Benefits of Using Teredo
- •Teredo Support in Microsoft Windows
- •Teredo and Protection from Unsolicited Incoming IPv6 Traffic
- •Network Address Translators (NATs)
- •Teredo Components
- •Teredo Client
- •Teredo Server
- •Teredo Relay
- •Teredo Host-Specific Relay
- •The Teredo Client and Host-Specific Relay in Windows
- •Teredo Addresses
- •Teredo Packet Formats
- •Teredo Data Packet Format
- •Teredo Bubble Packets
- •Teredo Indicators
- •Teredo Routing
- •Routing for the Teredo Client in Windows
- •Teredo Processes
- •Initial Configuration for Teredo Clients
- •Maintaining the NAT Mapping
- •Initial Communication Between Teredo Clients on the Same Link
- •Initial Communication Between Teredo Clients in Different Sites
- •Initial Communication from a Teredo Client to a Teredo Host-Specific Relay
- •Initial Communication from a Teredo Host-Specific Relay to a Teredo Client
- •Initial Communication from a Teredo Client to an IPv6-Only Host
- •Initial Communication from an IPv6-Only Host to a Teredo Client
- •References
- •Testing for Understanding
- •IPv6 Security Considerations
- •Authorization for Automatically Assigned Addresses and Configurations
- •Recommendations
- •Protection of IPv6 Packets
- •Recommendations
- •Host Protection from Scanning and Attacks
- •Address Scanning
- •Port Scanning
- •Recommendations
- •Control of What Traffic Is Exchanged with the Internet
- •Recommendations
- •Summary
- •References
- •Testing for Understanding
- •Introduction
- •Planning for IPv6 Deployment
- •Platform Support for IPv6
- •Application Support for IPv6
- •Unicast IPv6 Addressing
- •Tunnel-Based IPv6 Connectivity
- •Native IPv6 Connectivity
- •Name Resolution with DNS
- •DHCPv6
- •Host-Based Security and IPv6 Traffic
- •Prioritized Delivery for IPv6 Traffic
- •Deploying IPv6
- •Set Up an IPv6 Test Network
- •Begin Application Migration
- •Configure DNS Infrastructure to Support AAAA Records and Dynamic Updates
- •Deploy a Tunneled IPv6 Infrastructure with ISATAP
- •Upgrade IPv4-Only Hosts to IPv6/IPv4 Hosts
- •Begin Deploying a Native IPv6 Infrastructure
- •Connect Portions of Your Intranet over the IPv4 Internet
- •Connect Portions of Your Intranet over the IPv6 Internet
- •Summary
- •References
- •Testing for Understanding
- •Basic Structure of IPv6 Packets
- •LAN Media
- •Ethernet: Ethernet II
- •Ethernet: IEEE 802.3 SNAP
- •Token Ring: IEEE 802.5 SNAP
- •FDDI
- •IEEE 802.11
- •WAN Media
- •Frame Relay
- •ATM: Null Encapsulation
- •ATM: SNAP Encapsulation
- •IPv6 over IPv4
- •References
- •Added Constants
- •Address Data Structures
- •in6_addr
- •sockaddr_in6
- •sockaddr_storage
- •Wildcard Addresses
- •in6addr_loopback and IN6ADDR_LOOPBACK_INIT
- •Core Sockets Functions
- •Name-to-Address Translation
- •Address-to-Name Translation
- •Using getaddrinfo
- •Address Conversion Functions
- •Socket Options
- •New Macros
- •References
- •General
- •Addressing
- •Applications
- •Sockets API
- •Transport Layer
- •Internet Layer
- •Network Layer Security
- •Link Layer
- •Routing
- •IPv6 Transition Technologies
- •Chapter 1: Introduction to IPv6
- •Chapter 2: IPv6 Protocol for Windows Server 2008 and Windows Vista
- •Chapter 3: IPv6 Addressing
- •Chapter 4: The IPv6 Header
- •Chapter 5: ICMPv6
- •Chapter 6: Neighbor Discovery
- •Chapter 8: Address Autoconfiguration
- •Chapter 9: IPv6 and Name Resolution
- •Chapter 10: IPv6 Routing
- •Chapter 11: IPv6 Transition Technologies
- •Chapter 12: ISATAP
- •Chapter 13: 6to4
- •Chapter 14: Teredo
- •Chapter 15: IPv6 Security Considerations
- •Chapter 16: Deploying IPv6
- •IPv6 Test Lab Setup
- •CLIENT1
- •ROUTER1
- •ROUTER2
- •CLIENT2
- •IPv6 Test Lab Tasks
- •Performing Link-Local Pings
- •Enabling Native IPv6 Connectivity on Subnet 1
- •Configuring ISATAP
- •Configuring Native IPv6 Connectivity for All Subnets
- •Using Name Resolution
- •Configuring an IPv6-Only Routing Infrastructure
- •Overview
- •Mobile IPv6 Components
- •Mobile IPv6 Transport Layer Transparency
- •Mobile IPv6 Messages and Options
- •Mobility Header and Messages
- •Type 2 Routing Header
- •Home Address Option for the Destination Options Header
- •ICMPv6 Messages for Mobile IPv6
- •Modifications to Neighbor Discovery Messages and Options
- •Mobile IPv6 Data Structures
- •Binding Cache
- •Binding Update List
- •Home Agents List
- •Correspondent Registration
- •Return Routability Procedure
- •Detecting Correspondent Nodes That Are Not Mobile IPv6–Capable
- •Mobile IPv6 Message Exchanges
- •Data Between a Mobile Node and a Correspondent Node
- •Binding Maintenance
- •Home Agent Discovery
- •Mobile Prefix Discovery
- •Mobile IPv6 Processes
- •Attaching to the Home Link
- •Moving from the Home Link to a Foreign Link
- •Moving to a New Foreign Link
- •Returning Home
- •Mobile IPv6 Host Sending Algorithm
- •Mobile IPv6 Host Receiving Algorithm
- •References
- •Glossary
- •Index
- •About the Author
- •System Requirements

456 Understanding IPv6, Second Edition
Mobile IPv6 Messages and Options
Mobile IPv6 requires the use of the following messages and message options:
■A new Mobility extension header with a set of Mobile IPv6 messages
■A set of mobility options to include in mobility messages
■A new Home Address option for the Destination Options header
■A new Type 2 Routing header
■New Internet Control Message Protocol for IPv6 (ICMPv6) messages to discover the set of home agents and to obtain the prefix of the home link
■Changes to router discovery messages and options, and additional Neighbor Discovery options
Mobility Header and Messages
To facilitate the sending of messages between mobile nodes, correspondent nodes, and home agents for the purposes of managing the set of bindings between home addresses and care-of addresses, the Internet Engineering Task Force (IETF) has defined a new Mobility extension header. This new header can contain one of several defined mobility messages to perform specific functions. Some mobility messages can contain one or more options.
Mobility Header
The new Mobility extension header is dedicated to carrying mobility messages and has the structure shown in Figure F-2. Setting the previous header’s Next Header field to the value of 135 identifies the Mobility extension header.
Payload Protocol
Header Length
MH Type
Reserved
Checksum
Message Data
• • •
Figure F-2 Structure of the Mobility extension header
Within the Mobility extension header, you will find the following settings:
■The Payload Protocol field, equivalent to the Next Header field in the IPv6 header, is always set to the value of 59 to indicate that the Mobility header is the last header in the packet.
■The MH Type field identifies the specific type of mobility message.
■The Message Data field contains a mobility message.
Appendix F Mobile IPv6 |
457 |
The following types of mobility messages are defined:
■Binding Refresh Request Sent by a correspondent node or home agent to request the current binding from a mobile node. If a mobile node receives a binding refresh request, it responds with a binding update. A correspondent node sends a binding refresh request when a binding cache entry is in active use and the lifetime of the binding cache entry approaches expiration. A home agent sends a binding refresh request when the lifetime of its binding cache entry approaches expiration.
■Home Test Init (HoTI) Sent by the mobile node during the Return Routability procedure to test the indirect path from a mobile node to a correspondent node via the home agent. For more information, see the “Return Routability Procedure” section of this appendix.
■Care-of Test Init (CoTI) Sent by the mobile node during the Return Routability procedure to test the direct path from a mobile node to a correspondent node.
■Home Test (HoT) Sent by the correspondent node during the Return Routability procedure to respond to the HoTI message.
■Care-of Test (CoT) Sent by the correspondent node during the Return Routability procedure to respond to the CoTI message.
■Binding Update Sent by a Mobile IPv6 node that is away from home to update another node with its new care-of address. The Binding Update option is used for the following:
To update the home agent with a new primary care-of address. This is known as a home registration binding update. The home agent uses the home address in the Home Address option and the care-of address in an Alternate Care-of Address mobility option to update its Home Address/Primary Care-of Address binding cache entry for the mobile node.
To update a Mobile IPv6–capable correspondent node with which the mobile node is actively communicating with a binding that maps the home address of the mobile node to its care-of address. This is known as a correspondent registration binding update. The correspondent node uses the home address in the Home Address option and the source address of the packet to update its Home Address/ Care-of Address binding cache entry for the mobile node.
■Binding Acknowledgement Sent by a home agent or a correspondent node to acknowledge the receipt of a Binding Update message. Included in the binding acknowledgement is an indication of how long the node will cache the binding. For home agents, this lifetime indicates how long the home agent will be in service as the home agent for the mobile node. To refresh the binding, either the mobile node sends a new binding update or the correspondent nodes and home agent send Binding Refresh Request messages. The binding acknowledgement also includes an indication of how often the mobile node should send binding updates.
■Binding Error Sent by a correspondent node to report errors in a binding update.

458 Understanding IPv6, Second Edition
Mobility messages can contain mobility message options. RFC 3775 defines the following options:
■Pad1 Option Used to insert a single byte of padding
■PadN Option Used to insert 2 or more bytes of padding
■Binding Refresh Advice Option Used in a Binding Acknowledgement sent from a home agent to indicate how long before the mobile node should send a new home registration
■Alternate Care-of Address Option Used to indicate the care-of address in the Binding Update message
■Nonce Indices Option Used to indicate information needed to determine binding keys
■Binding Authorization Data Option Used to contain cryptographic information from which the receiver can verify that the binding message originated from a node with which a Return Routability procedure has occurred
Type 2 Routing Header
Mobile IPv6–capable correspondent nodes use a new Type 2 Routing header when sending a packet directly to a mobile node that is away from home to indicate the mobile node’s home address. Correspondent nodes set the Destination Address field in the IPv6 header to the mobile node’s care-of address when performing direct delivery.
Figure F-3 shows the structure of the new Type 2 Routing header.
Next Header
Header Extension Length = 2
Routing Type = 2
Segments Left = 1
Reserved
Home Address
Figure F-3 The structure of the new Type 2 Routing header
During the processing of a packet with a Type 2 Routing header, the mobile node replaces the Destination Address field with the value in the Home Address field. The Home Address field in the Type 2 Routing header is the actual destination address of the mobile node to which the packet has been sent. (The care-of address stored in the Destination Address field of the IPv6 header is merely an intermediate delivery address.)
The Type 2 Routing header is different from the Type 0 Routing header defined in RFC 2460 in that it can store only a single address and is specified for use only with Mobile IPv6. The

Appendix F Mobile IPv6 |
459 |
Type 0 Routing header can store multiple addresses and is processed by routers for generalized source routing. Using a different routing type allows firewalls to treat source-routed packets differently from packets sent directly by Mobile IPv6–capable correspondent nodes to mobile nodes that are away from home.
Home Address Option for the Destination Options Header
The Home Address option in the Destination Options extension header is used to indicate the home address of the mobile node. It is included in binding updates sent to home agents and packets sent directly to Mobile IPv6–capable correspondent nodes by a mobile node when it is away from home when a binding exists. When a mobile node sends a packet, the source address in the IPv6 header is set to the care-of address. If the source address in the IPv6 header were set to the home address, the router on the foreign link might discard the packet because the source address does not match the prefix of the link on which the mobile node is located. To help minimize Internet attacks in which the source address of attack packets is spoofed with an address that is not assigned to the attacking computer, peripheral routers can implement ingress filtering and silently discard packets that do not have topologically correct source addresses. Ingress in this instance is defined relative to the Internet for packets entering the Internet, rather than packets entering an intranet from the Internet.
Figure F-4 shows the structure of the Home Address destination option.
Option Type = 201
Option Length = 16
Home Address
Figure F-4 The structure of Home Address destination option
By using the care-of address as the source address in the packet (a topologically correct address on the foreign link) and including the Home Address destination option, the router on the foreign link forwards the packet to its destination. When the packet is received at the destination, the correspondent node processes the Destination Options header and logically replaces the source address of the packet with the address in the Home Address option before passing the payload to the upper-layer protocol. To the upper-layer protocol, the packet was sent from the home address.
In contrast to the Home Address field in the Type 2 Routing header, the Home Address field in the Home Address destination option is the actual source address of the mobile node from which the packet was sent. (The care-of address stored in the Source Address of the IPv6 header is merely an intermediate address.)
The Home Address option is also included with the binding update so that the home address for the binding is indicated to the receiving node.