& cplSiteName &

Stateful NAT64 Performance

Light Reading
Series Column
Light Reading
2/5/2012
50%
50%

EXECUTIVE SUMMARY: Cisco’s CRS-1 loaded with four CGSE cards successfully translated IPv6 traffic to IPv4 at 4 million translations per second. The same system scaled up to 78.4Gbit/s at a total of 67,107,840 translations with almost no loss.


While the industry embraces IPv6 now more than ever, it also recognizes that IPv4 services are not going away soon. The Internet is an obvious example where IPv4 addresses are going to be used for years to come. Cloud applications will use those addresses as well.

While data centers will have different IP migration strategies, they will likely look to serve both IPv4- and IPv6-based customers. Long-term strategies will include native IPv6 throughout the data center, but in the short term a complete IPv6 strategy might not be practical.

For this reason service providers and cloud operators are likely to find themselves needing to deploy Network Address Translation (NAT) from IPv6 users to IPv4 services (NAT64). Let's say an enterprise is building a brand-new large-scale office and wants to use unique IP addressing. The carrier could provide this adventurous customer with IPv6 addresses to use for internal hosts and servers. In order to communicate with the Internet, which at this point is still IPv4 heavy, the carrier could install a NAT64 device somewhere between the customer and their services to translate the IPv6 addressing to IPv4 before sending the datagrams to the Internet. Another example is the rollout of mobile services en masse using IPv6, to customers who still plan to access IPv4 services, including cloud services.

Cisco claimed to be ready for these scenarios -- delivering IPv4 services to IPv6 customers -- at scale. Since we have already reported results on Cisco's stateless NAT 64 capabilities we wanted to use this opportunity to verify Cisco's stateful NAT64 performance claims -- that by placing four Carrier-Grade Services Engine (CSGE) modules into a single CRS-1, we could scale up to 60 million NAT64 translations, at 4 million translations per second, all while transmitting up to 80Gbit/s of data.

Would any carrier need this performance? Probably not anytime soon, but we have learned that those who purchase large-scale core routers want to know that they can use their significant financial investment for a while.

Given the scale, we looked to verify each metric separately. Even with this divide-and-conquer approach, NAT can become complex to test. Cisco explained, and showed, that when their NAT64 implementation chooses an IPv4 address to map to an incoming IPv6 request, it is done at random. Now imagine manually configuring the tester for 60 million mappings, when all 60 million incoming requests are given random IPv4 addresses -- clearly this was not the way to go.

One alternative that we considered was to use stateful traffic using Ixia's IxLoad application, but emulating up to 60 million sessions would have required a significant amount of very high-performance test equipment -- again, not really a workable option. The solution we used involved Ixia's IxNetwork generating stateless traffic, with the appropriate TCP fields set to emulate a stateful session (TCP SYN/TCP ACKs). Since Cisco’s implementation randomly assigned TCP port numbers and IPv4 addresses to incoming IPv6 requests, we schemed to simply exhaust the entire pool of resources on the CRS-1. This way we were able to predict which addresses and ports would be used -- it would be all of them. If your head is spinning, we hope the following diagram will help.

To summarize, we sent client traffic from 1,024 IPv6 addresses -- each of whom opened 65,535 TCP sessions. In fact, this brought us to a total of 67,107,840 translations on the CRS-1. We sent traffic in return toward all 960 IPv4 addresses, each with all 65,535 TCP port numbers, as was configured in the CRS-1 pool. All traffic used IMIX frame sizes -- 122:7, 512:4, 1500:1 (106 in place of 122 on the IPv4 side) at a rate of 38.4Gbit/s toward the clients and 40Gbit/s toward the servers, all across four 10-Gigabit Ethernet links. Once the configuration was pre-staged and verified to be working, we could breathe a sigh of relief.

As we started the official test run we recorded only a small amount of loss -- 0.002 percent on eight of the 16 flows configured from the IPv6 emulated clients toward the IPv4 emulated servers. The other four of such flows ran with no loss, and no flows in the return direction observed any loss either. Considering that we had planned to only test 60 million translations rather than 67,107,840, the loss was considered very minimal. We also verified, using the CRS-1 Command Line Interface (CLI) that all expected translations appeared in the enormous translation table. We also measured latency. The maximum latency values were not very surprising given the translation work to be done by the CRS-1, but in general, given that the latency also included the seven other devices in the test bed, the average latency was quite low.

Next was performance. How quickly could these translations be built in hardware? Now that our test methodology was proven, we felt safe clearing the NAT table on the CRS-1. After doing so, we lowered all frame sizes to 150 bytes so we could increase the frame rate to 4 million frames per second -- 1 million frames per second on each of the four 10-Gigabit Ethernet ports. In order to add realism to the test we configured IxNetwork to randomly assign TCP ports to the IPv6 flows, so that they were not sequential. This however required that we also lower the total number of ports to 13,824, bringing the number of translations to 56,622,848 in total. We ran the test for two minutes without loss.

After some pretty long nights of some complex configuration, we had finally established a test that was able to verify the rate, translation capacity, and throughput of Cisco’s NAT64 solution. Impressive.


Next Page: IPv6 Rapid Deployment (RD) Performance
Previous Page: Intro: Cloud Intelligent Networks


Back to the Cisco Test Main Page

(1)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
TJ Evans
50%
50%
TJ Evans,
User Rank: Light Beer
6/17/2013 | 7:28:06 PM
re: Stateful NAT64 Performance
Are any numbers available for NAT64 performance on slightly more moderate platforms, ASR1k, ASR9k, etc.?
Light Reading’s Upskill U is a FREE, interactive, online educational resource that delivers must-have education on themes that relate to the overall business transformation taking place in the communications industry.
NEXT COURSE
Friday, September 30, 1:00PM EDT
Gigabit & the Great Migration
Robert Howald, Vice President, Network Architecture, Comcast
UPCOMING COURSE SCHEDULE
Wednesday, October 5, 1:00PM EDT
Gigabit & Smart Cities
Joe Kochan, COO & Co-Founder, US Ignite
Friday, October 7, 1:00PM EDT
Gigabit & DOCSIS 3.1
Ty Pearman, Director, Access Architecture, Comcast
Wednesday, October 19, 1:00PM EDT
Securing a Virtual World
Rita Marty, Executive Director, Mobility and Cloud Security, Chief Security Office, AT&T
in association with:
From The Founder
Light Reading today starts a new voyage as part of a larger Enterprise.
Flash Poll
Live Streaming Video
Charting the CSP's Future
Six different communications service providers join to debate their visions of the future CSP, following a landmark presentation from AT&T on its massive virtualization efforts and a look back on where the telecom industry has been and where it's going from two industry veterans.
LRTV Custom TV
Flexible Deployment Approaches for the Gigabit Services Evolution

9|29|16   |     |   (0) comments


For many operators, the gigabit evolution begins with the shift from DOCSIS 3.0 to DOCSIS 3.1. But that move represents a change not only in the protocol itself, but in the approach to architecting their entire DOCSIS delivery chain -- from the headend to the outside plant and home gateway components.

Jonathan Ruff, senior director of global technical ...

LRTV Interviews
Level 3 VP: Enterprises Need More for Less

9|29|16   |   05:27   |   (0) comments


Andrew Dugan, Level 3 group vice president of global technology and IT, says enterprises need more bandwidth and they need it faster and with greater security, but they want to spend less, if possible. They are looking to carriers to reduce their network complexity and help protect them from cyberattacks as well.
LRTV Interviews
CenturyLink: SDN/NFV Pose New Interconnection Possibilities

9|28|16   |   04:37   |   (0) comments


Network operators should develop new APIs and business processes for reselling virtual assets to each other, says CenturyLink's Bill Walker. That will enable them to build digital business portfolios that help them avoid becoming commodity transport providers.
LRTV Interviews
Level 3: Overcoming Terror of Being Supplier, Integrator & Developer

9|28|16   |     |   (0) comments


At Light Reading's NFV & Carrier SDN event in Denver, Travis Ewert of Level 3 Communications said there is terror in becoming supplier, integrator and developer, but it can be overcome and be cost effective.
LRTV Custom TV
Introducing IoT World News

9|27|16   |   01:43   |   (0) comments


Self-driving cars, medical sensors, smart cities... and refrigerators. In order to address the huge scope of IoT, KNect365 has created a unique online community that will help businesses to understand and monetize the opportunities that live within the IoT market. We look forward to welcoming you to IoT World News -- your gateway to a better connected future.
LRTV Interviews
AT&T: Reusable Functions Next NFV Key

9|27|16   |   06:03   |   (0) comments


The next generation of NFV has to break functions down into reusable software chunks, making everything much more cloud-like.
LRTV Interviews
Masergy on Security: Attackers Gaining Upper Hand

9|27|16   |   5:10   |   (2) comments


At Light Reading's NFV & Carrier SDN event in Denver, Ray Watson, vice president of Global Technology at Masergy, says that because of the growth in virtualization, the threat landscape is shifting in favor of the attackers. As a result, service providers need to think beyond just defending the perimeter and take a more holistic approach to security.
LRTV Interviews
Verizon Takes Next Step on Biz Virtualization Journey

9|26|16   |   4:38   |   (2) comments


At September's NFV & Carrier SDN event in Denver, Light Reading sat down with Victoria Lonker, director of Product and New Business Innovation at Verizon, to chat about where the carrier is with delivering virtualized services to business customers.
LRTV Interviews
Global Services: The $40B Face-Off

9|26|16   |   05:53   |   (1) comment


More service providers than ever before are battling it out to win a slice of what is now a $40 billion global communications services pie, explains Ovum Principal Analyst David Molony.
LRTV Documentaries
MEC Congress: The Key Takeaways

9|22|16   |   03:25   |   (3) comments


Three key takeaways from the Mobile Edge Computing (MEC) Congress in Munich, Germany.
Wagner’s Ring
Time to Shut Up About 'Dumb Pipes'

9|22|16   |     |   (20) comments


Service providers can't compete with OTT players. It just isn't in their DNA. Instead, service providers need to embrace what they're good at -- providing reliable, secure connectivity.
Wagner’s Ring
Keeping Your Tech Career Going After 50

9|21|16   |     |   (13) comments


How do you keep your career moving forward when you're past the half-century mark?
Upcoming Live Events
November 3, 2016, The Montcalm Marble Arch, London
November 30, 2016, The Westin Times Square, New York City
December 1, 2016, The Westin Times Square, New York, NY
December 6-8, 2016, The Westin Excelsior, Rome
May 16-17, 2017, Austin Convention Center, Austin, TX
All Upcoming Live Events
Infographics
Hot Topics
Eurobites: Telefónica Taps Juniper for Network Security
Paul Rainford, Assistant Editor, Europe, 9/26/2016
WiCipedia: The Women Helping Women Edition
Eryn Leavens, Special Features & Copy Editor, 9/23/2016
Powell Kills the Cable Show
Mari Silbey, Senior Editor, Cable/Video, 9/29/2016
Telstra Sees Quadrupled Data Capacity by 2020
Carol Wilson, Editor-at-large, 9/28/2016
Open Source Getting on My Nerves
Carol Wilson, Editor-at-large, 9/26/2016
Like Us on Facebook
Twitter Feed
BETWEEN THE CEOs - Executive Interviews
Light Reading CEO Steve Saunders and UXP Systems CEO Gemini Waghmare discuss the strategic importance of digital identity for operators in the midst of transformation.
Join us for an in-depth interview between Steve Saunders of Light Reading and Alexis Black Bjorlin of Intel as they discuss the release of the company's Silicon Photonics platform, its performance, long-term prospects, customer expectations and much more.
Animals with Phones
There's Nothing Like Missing a Full Minute of Pokémon Go Click Here
Live Digital Audio

A vital part of increasing the number of women in comms is transforming the ways companies can support and empower women. While progressive company policies that support both men and women in achieving work-life balance are a step in the right direction, creating a company culture that supports those policies can at times be more challenging.

During this show, we'll talk to Lynn Comp, Senior Director of Industry and Sales Enabling (ISE) in the Network Platforms Group at Intel, about why those challenges exist and how companies can overcome them. She'll provide insight into how Intel has worked to create a culture that supports work-life balance, and provide steps and guidance for other companies wishing to do the same. We will also leave plenty of time to get your questions answered live on the air.