Thus, the web services that rely on these public cloud services have been relegated to being IPv4-only sites. The organizations who are using these cloud providers for their public web-based applications have been unable to take advantage of the performance benefits of IPv6 that other IPv6-enabled platforms enjoy. In other words, the IPv6 deployment delays of the CSPs has delayed other downstream organizations from deploying IPv6.
AWS Simple Storage Service (S3) is an Internet-reachable durable object file storage service available through a web interface. A few months ago, in August of 2016, AWS announced IPv6 support for Amazon S3. Now, if you store files in S3 and your bucket and Identity and Access Management (IAM) policies allow it, you can reach your files over IPv6 transport. To reach your S3 bucket over IPv6, you would simply refer to the URL using the “dualstack” keyword as shown below.
A couple of months ago, in October of 2016, AWS announced IPv6 capabilities for three related Internet edge services: CloudFront, WAF, and S3 transfer acceleration. CloudFront is AWS’s own CDN service that provides for Internet caching of web application contents for improved performance. AWS also offers a Web Application Firewall (WAF) service for adding security to vulnerable web front-ends. The AWS S3 transfer acceleration provides better file transfer performance levering the caching functionality of CloudFront’s distributed edge locations. To enable CloudFront for IPv6, you must check the box in the service settings through the AWS Management Console. IPv6 addresses will now appear in the X-Froward-For HTTP header field capturing the source IP address for client connections. The AWS customer logs then must take this into consideration and be aware that a client can be reaching your CloudFront web content over IPv6.
AWS’s Route53 service is their highly scalable and reliable DNS web service. Up until 2 months ago, it was an IPv4-only service, but now it is IPv6-capable. The Route53 service can now perform DNS resolutions over IPv6 transport and can contain AAAA records and IPv6 PTR records.
There were many exciting AWS announcements made at their annual re:Invent conference held in Las Vegas, NV November 27th through December 1st. One of the most exciting to the IPv6 community is that AWS now has IPv6 support for EC2 instances in Virtual Private Clouds (VPCs). VPCs are AWS’s virtual networking service that connects EC2 compute instances to subnets and can connect to various gateways for external connectivity.
Previously, VPCs did not support IPv6 and prevented customers from using IPv6 and connecting to the IPv6 Internet. VPCs also facilitate connectivity to and from AWS using Internet Gateways (IGWs) or using you own private network. VPCs can now have IPv6 routes and Network Access Control Lists (NACLs) as well as security groups are now IPv6-capable. AWS VPC Peering is also IPv6 capable and VPC Flow Logs can gather information about IPv6 network traffic. IPv6-enabled VPCs allow your internal EC2 instances to use DHCPv6 to obtain their IPv6 address and to reach the Internet via a default gateway route. IPv6 is supported over Direct Connect, but IPv6 is not yet supported for Virtual Private Gateway (VGW) VPN connections.
Since IPv6 does not need a NAT function, the global IPv6 addresses used for your VPC can traverse gateways without translation, therefore, there is no need for elastic IPv6 addresses. AWS has also introduced an Egress-Only Internet Gateway (EIGW) that statefully controls Internet reachability for your VPC. The EIGW prevents unsolicited IPv6 inbound connections for private VPC connectivity.
Now that you can configure native IPv6 service for VPCs, you can have your EC2 instances connected to your own VPCs and you will get a /56 IPv6 prefix from AWS’s global IPv6 address block. The IPv6 address allocated to your VPC will vary based on the region you are operating in. Today this IPv6 VPC capability is only offered within the US-East-2 (Ohio, US) region. Hopefully this IPv6 VPC capability will be coming soon to other commercial AWS regions and U.S. GovCloud.
Amazon Web Services (AWS) has become one of the most dominant Infrastructure as a Service (IaaS) public cloud service providers. AWS has a strong set of ecosystem partners and a thriving AWS Marketplace. You can even buy Infoblox NIOS DNS and IPAM systems through the AWS Marketplace and run it in your AWS environment. Even though Infoblox has supported IPv6 for many years, if the cloud provider you are using was not IPv6 capable, then the IPv6 functionality in NIOS would be diminished. If your AWS virtual networks are not yet IPv6-enabled, then your Infoblox instance will only function over IPv4 transport. In this situation, however, the Infoblox NIOS system could return AAAA DNS record responses over IPv4 transport. But now that AWS has IPv6 support for VPCs, your Infoblox NIOS instances could be connected to those dual-protocol VPCs, then your Infoblox system will easily support your dual-protocol architecture.
Amazon Web Services should be commended for putting forth substantial effort to IPv6-enable their services. Their customers should now leverage these capabilities to enable their public web applications and make sure that they are reachable by all the IPv6-capable clients. Hopefully sometime soon, all AWS services will be dual-protocol capable. At that point, there will be complete functional parity and all AWS services will use both IP versions. The current AWS offering is dual-protocol, but eventually, AWS will make their platform functional in an IPv6-only configuration. We can anticipate that AWS’s movement toward IPv6 will help inspire other cloud providers. There are signs that the larger public CSPs are starting to embrace IPv6. For example, now Microsoft Azure has support for IPv6 on VMs. We can expect more cloud providers to adopt IPv6 in the coming year which will result in even higher Alexa top sites gaining IPv6 benefits.