This curriculum spans the technical and operational rigor of a multi-workshop IPv6 transition program for global CDNs, addressing addressing, routing, security, and observability with the depth required to redesign production-scale delivery infrastructure.
Module 1: IPv6 Addressing Architecture in CDN Design
- Allocate provider-independent vs. provider-aggregatable IPv6 address blocks based on multi-CDN failover requirements and routing control needs.
- Implement /64 subnetting for edge POPs to comply with SLAAC requirements while reserving /56 blocks for regional aggregation.
- Design dual-stack addressing schemes that preserve consistent routing policies across IPv4 and IPv6 without asymmetric path risks.
- Configure reverse DNS (PTR) records for IPv6 addresses using ip6.arpa zones with automated zone file generation from IPAM systems.
- Integrate IPv6 address planning into existing IP address management (IPAM) tools to maintain audit trails and prevent allocation conflicts.
- Enforce strict prefix length validation in BGP announcements to prevent route leaks and ensure compliance with RIR allocation policies.
Module 2: Dual-Stack Integration at the Network Edge
- Deploy stateful NAT64 gateways at legacy IPv4-only origin servers to enable IPv6-only clients without modifying backend infrastructure.
- Configure DNS64 synthesis on recursive resolvers to provide synthetic AAAA records for IPv4-only origin domains.
- Balance traffic between IPv4 and IPv6 paths using weighted DNS responses based on real-time reachability and latency metrics.
- Implement Happy Eyeballs v2 on client-facing endpoints to minimize connection delays during dual-stack fallback scenarios.
- Monitor IPv6 connection success rates per ASN and adjust DNS response ordering to deprioritize non-functional IPv6 paths.
- Enforce TLS server name indication (SNI) consistency across IPv4 and IPv6 virtual hosts to prevent certificate validation failures.
Module 3: BGP and Routing Infrastructure for IPv6
- Establish separate BGP sessions for IPv6 (AFI 2, SAFI 1) with distinct route filters and prefix limits per peer.
- Apply outbound prefix filtering to prevent accidental advertisement of reserved or ULA IPv6 ranges to transit providers.
- Implement BGP communities for IPv6 routes to signal traffic engineering policies such as low-latency or DDoS scrubbing paths.
- Configure MP-BGP with next-hop self for IPv6 in iBGP clusters to ensure correct next-hop resolution in large-scale deployments.
- Use BGP convergence testing tools to validate IPv6 route propagation times during failover events across global POPs.
- Integrate RPKI validation into BGP route ingestion to reject unauthenticated IPv6 route announcements from peers.
Module 4: Load Balancer and Anycast IPv6 Configuration
- Program ADCs to perform health checks over IPv6 on origin servers and exclude non-responsive endpoints from the IPv6 pool.
- Bind anycast IPv6 /128 addresses to loopback interfaces on load balancers and redistribute via OSPFv3 or IS-IS.
- Configure asymmetric routing mitigation on multi-homed load balancers using VRRPv3 with IPv6 link-local addresses.
- Set TCP keepalive intervals for idle IPv6 connections to prevent premature timeout in stateful devices along the path.
- Enable IPv6 flow-label hashing in ECMP configurations to maintain per-flow consistency across multiple backend servers.
- Validate hardware offload compatibility for IPv6 fragmented packets on ADC platforms to avoid performance degradation.
Module 5: DNS Infrastructure for IPv6-Centric Delivery
- Deploy authoritative DNS servers with native IPv6 listeners and ensure AAAA records are served from anycast IPv6 anycast addresses.
- Size DNS response payloads to avoid IPv6 fragmentation by limiting the number of RRs in UDP responses to under 1232 bytes.
- Implement DNS0XID tracking to correlate IPv6 source ports and transaction IDs for cache poisoning resistance.
- Use DNS traffic steering to direct IPv6 clients to geographically optimal POPs based on EDNS Client Subnet over IPv6.
- Monitor NXDOMAIN and timeout rates specifically for AAAA queries to detect resolver-level IPv6 blocking.
- Enforce DNSSEC signing for IPv6 zones using ECDSA P-256 with automated key rollover procedures.
Module 6: Security and DDoS Mitigation in IPv6 CDNs
Module 7: Monitoring, Telemetry, and Performance Optimization
- Instrument synthetic transactions over IPv6 to measure end-to-end latency, packet loss, and TLS handshake duration per region.
- Aggregate IPv6 traffic counters by source /56 prefix to identify top contributing ASNs and detect misconfigured networks.
- Deploy IPv6-capable NetFlow or sFlow collectors to capture flow data from core and edge routers.
- Correlate IPv6 DNS query success rates with actual connection attempts to isolate resolver-level connectivity issues.
- Use traceroute over IPv6 with ICMPv6 Echo and TCP probes to diagnose path MTU and middlebox interference.
- Optimize TCP initial window and enable RFC 8799 Large Initial Window for IPv6 connections to improve start-up performance.
Module 8: Operational Governance and Compliance
- Define SLA thresholds for IPv6 availability and include them in contractual obligations with transit and peering partners.
- Conduct quarterly audits of IPv6 BGP announcements to verify alignment with approved routing policies and AS_PATHs.
- Document IPv6 change management procedures for firewall rule updates, DNS modifications, and load balancer reconfigurations.
- Enforce mandatory IPv6 testing in pre-deployment validation for all new origin integrations and domain onboarding.
- Report IPv6 adoption metrics per customer domain to support compliance with regulatory or industry benchmarks.
- Establish incident response playbooks specifically for IPv6-related outages, including DNS64/NAT64 failure modes.