& cplSiteName &

Stateful NAT64 Performance

Light Reading
Series Column
Light Reading
2/5/2012
50%
50%

EXECUTIVE SUMMARY: Cisco’s CRS-1 loaded with four CGSE cards successfully translated IPv6 traffic to IPv4 at 4 million translations per second. The same system scaled up to 78.4Gbit/s at a total of 67,107,840 translations with almost no loss.


While the industry embraces IPv6 now more than ever, it also recognizes that IPv4 services are not going away soon. The Internet is an obvious example where IPv4 addresses are going to be used for years to come. Cloud applications will use those addresses as well.

While data centers will have different IP migration strategies, they will likely look to serve both IPv4- and IPv6-based customers. Long-term strategies will include native IPv6 throughout the data center, but in the short term a complete IPv6 strategy might not be practical.

For this reason service providers and cloud operators are likely to find themselves needing to deploy Network Address Translation (NAT) from IPv6 users to IPv4 services (NAT64). Let's say an enterprise is building a brand-new large-scale office and wants to use unique IP addressing. The carrier could provide this adventurous customer with IPv6 addresses to use for internal hosts and servers. In order to communicate with the Internet, which at this point is still IPv4 heavy, the carrier could install a NAT64 device somewhere between the customer and their services to translate the IPv6 addressing to IPv4 before sending the datagrams to the Internet. Another example is the rollout of mobile services en masse using IPv6, to customers who still plan to access IPv4 services, including cloud services.

Cisco claimed to be ready for these scenarios -- delivering IPv4 services to IPv6 customers -- at scale. Since we have already reported results on Cisco's stateless NAT 64 capabilities we wanted to use this opportunity to verify Cisco's stateful NAT64 performance claims -- that by placing four Carrier-Grade Services Engine (CSGE) modules into a single CRS-1, we could scale up to 60 million NAT64 translations, at 4 million translations per second, all while transmitting up to 80Gbit/s of data.

Would any carrier need this performance? Probably not anytime soon, but we have learned that those who purchase large-scale core routers want to know that they can use their significant financial investment for a while.

Given the scale, we looked to verify each metric separately. Even with this divide-and-conquer approach, NAT can become complex to test. Cisco explained, and showed, that when their NAT64 implementation chooses an IPv4 address to map to an incoming IPv6 request, it is done at random. Now imagine manually configuring the tester for 60 million mappings, when all 60 million incoming requests are given random IPv4 addresses -- clearly this was not the way to go.

One alternative that we considered was to use stateful traffic using Ixia's IxLoad application, but emulating up to 60 million sessions would have required a significant amount of very high-performance test equipment -- again, not really a workable option. The solution we used involved Ixia's IxNetwork generating stateless traffic, with the appropriate TCP fields set to emulate a stateful session (TCP SYN/TCP ACKs). Since Cisco’s implementation randomly assigned TCP port numbers and IPv4 addresses to incoming IPv6 requests, we schemed to simply exhaust the entire pool of resources on the CRS-1. This way we were able to predict which addresses and ports would be used -- it would be all of them. If your head is spinning, we hope the following diagram will help.

To summarize, we sent client traffic from 1,024 IPv6 addresses -- each of whom opened 65,535 TCP sessions. In fact, this brought us to a total of 67,107,840 translations on the CRS-1. We sent traffic in return toward all 960 IPv4 addresses, each with all 65,535 TCP port numbers, as was configured in the CRS-1 pool. All traffic used IMIX frame sizes -- 122:7, 512:4, 1500:1 (106 in place of 122 on the IPv4 side) at a rate of 38.4Gbit/s toward the clients and 40Gbit/s toward the servers, all across four 10-Gigabit Ethernet links. Once the configuration was pre-staged and verified to be working, we could breathe a sigh of relief.

As we started the official test run we recorded only a small amount of loss -- 0.002 percent on eight of the 16 flows configured from the IPv6 emulated clients toward the IPv4 emulated servers. The other four of such flows ran with no loss, and no flows in the return direction observed any loss either. Considering that we had planned to only test 60 million translations rather than 67,107,840, the loss was considered very minimal. We also verified, using the CRS-1 Command Line Interface (CLI) that all expected translations appeared in the enormous translation table. We also measured latency. The maximum latency values were not very surprising given the translation work to be done by the CRS-1, but in general, given that the latency also included the seven other devices in the test bed, the average latency was quite low.

Next was performance. How quickly could these translations be built in hardware? Now that our test methodology was proven, we felt safe clearing the NAT table on the CRS-1. After doing so, we lowered all frame sizes to 150 bytes so we could increase the frame rate to 4 million frames per second -- 1 million frames per second on each of the four 10-Gigabit Ethernet ports. In order to add realism to the test we configured IxNetwork to randomly assign TCP ports to the IPv6 flows, so that they were not sequential. This however required that we also lower the total number of ports to 13,824, bringing the number of translations to 56,622,848 in total. We ran the test for two minutes without loss.

After some pretty long nights of some complex configuration, we had finally established a test that was able to verify the rate, translation capacity, and throughput of Cisco’s NAT64 solution. Impressive.


Next Page: IPv6 Rapid Deployment (RD) Performance
Previous Page: Intro: Cloud Intelligent Networks


Back to the Cisco Test Main Page

(1)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
TJ Evans
50%
50%
TJ Evans,
User Rank: Light Beer
6/17/2013 | 7:28:06 PM
re: Stateful NAT64 Performance
Are any numbers available for NAT64 performance on slightly more moderate platforms, ASR1k, ASR9k, etc.?
From The Founder
Download our complete guide to de-risking NFV deployment in 2016, including:
  • An eight-step strategy to deploying NFV safely, based on input from the companies that have already started virtualizing their production networks.
  • Interviews with leading executives at Colt, AT&T, Deutsche Telekom, Cisco, Nokia, ZTE, Ericsson and Heavy Reading.
  • Flash Poll
    Live Streaming Video
    Prepping for the Future: Upskill U Explained
    During this short kick-off video, Doug Webster, Vice President of Service Provider Marketing, Cisco, and Light Reading’s CEO & Founder Steve Saunders give an overview of Upskill U.
    LRTV Custom TV
    Dealing With a Disrupted Video Market

    5|2|16   |     |   (0) comments


    Ericsson's Simon Frost discusses how traditional pay-TV providers can cope with the big changes wrought by the rise of OTT video and IP technology.
    LRTV Custom TV
    The VNF Responsibility of Red Hat

    5|2|16   |     |   (0) comments


    At MWC, Caroline Chappell of Heavy Reading visits the Red Hat booth and sits down with Chris Wright to talk about the responsibility the VNF needs to take on in order to ensure the operators get the carrier-grade performance they expect for their network.
    LRTV Interviews
    AT&T Expert on the Key Pillars of UC

    4|29|16   |   03:58   |   (0) comments


    Vishy Gopalakrishnan, AVP of product marketing at AT&T, talks about the three developments that are making unified communications and collaboration secure and reliable for enterprise users.
    LRTV Documentaries
    LRTV Report: Mobile Core Innovation

    4|28|16   |   25:32   |   (0) comments


    Hear from multiple industry experts from Deutsche Telekom, SK Telecom, Heavy Reading, Huawei, Cisco, Ericsson, Nokia, NEC and many more about developments in the mobile core as operators virtualize their IMS and evolved packet core systems and prepare for a 5G world.
    LRTV Huawei Video Resource Center
    NFV World Congress Highlight

    4|26|16   |     |   (0) comments


    The highlight of the NFV World Congress contains exciting telecom news. Join us for an inside look at Huawei's ICT 2020 plan and its latest collaboration with industry leaders.
    LRTV Interviews
    Unified Comms Finds Its Voice

    4|25|16   |   03:44   |   (0) comments


    Peter Quinlan, VP of UCC Product Management at Tata Communications, talks about the evolution of the unified communications and collaboration services sector and how voice is now a big part of current developments.
    LRTV Documentaries
    So... What Do We Do Now?

    4|25|16   |   03:24   |   (0) comments


    After a long hiatus, Max Dingman, the CEO of a GeeGhiz, returns for a motivational board room pep talk.
    LRTV Documentaries
    NAB 2016 Highlights

    4|21|16   |     |   (0) comments


    Light Reading's Cable/Video Practice Leader Alan Breznick climbs down from the slots to tell us about the latest news in broadcast technology at NAB 2016 in Las Vegas.
    Between the CEOs
    CEO Chat: Deepfield's Craig Labovitz

    4|21|16   |     |   (0) comments


    In this latest installment of the CEO Chat series, Craig Labovitz, co-founder and CEO of Deepfield, sits down with Light Reading's Steve Saunders in Light Reading's New York City office to discuss how Deepfield fits in with the big data trend and more.
    Shades of Ray
    Leading Lights 2016: Shortlists Announced

    4|20|16   |   0:53   |   (0) comments


    The judging is over and the Leading Lights 2016 shortlists have been published -- you can see who made the cut by clicking on this link.
    LRTV Custom TV
    Introducing MulteFire – Qualcomm at MWC 2016

    4|18|16   |   3.29   |   (0) comments


    MulteFire is the latest option for using LTE in unlicensed spectrum. As oppose to its close 'siblings', LAA and LTE-U, MulteFire operates solely in unlicensed spectrum, which enables it to offer the best of two worlds – LTE-like performance with WiFi-like deployment simplicity. In this interview, Sanjeev Athalye, Sr. Director, Product Management at Qualcomm ...
    Between the CEOs
    CEO Chat: Grant Van Rooyen of Cologix

    4|18|16   |     |   (0) comments


    Grant van Rooyen, president and CEO of Cologix, sits down with Steve Saunders, founder and CEO of Light Reading, in the vendor's New Jersey facility to offer an inside look at the company's success story and discuss the importance of security in the telecom industry.
    Upcoming Live Events
    May 23, 2016, Austin, TX
    May 23, 2016, Austin Convention Center
    May 24-25, 2016, Austin Convention Center, Austin, TX
    September 13-14, 2016, The Curtis Hotel, Denver, CO
    December 6-8, 2016,
    June 16-18, 2017, Austin Convention Center, Austin, TX
    All Upcoming Live Events
    Infographics
    A new survey conducted by Heavy Reading and TM Forum shows that CSPs around the world see the move to digital operations as a necessary part of their overall virtualization strategies.
    Hot Topics
    Ultra-Broadband Summit, Hong Kong
    Iain Morris, News Editor, 4/27/2016
    Amazon AWS Reports $2.6B Quarterly Revenue, Up a Colossal 64%
    Mitch Wagner, West Coast Bureau Chief, Light Reading, 4/28/2016
    WiCipedia: Woman Cards & Bitch Switches
    Sarah Thomas, Director, Women in Comms, 4/29/2016
    FCC Poised to Re-Regulate Wholesale Access
    Carol Wilson, Editor-at-large, 4/28/2016
    LoRa Alliance Defends Tech Against Sigfox Slur
    Iain Morris, News Editor, 4/28/2016
    Like Us on Facebook
    Twitter Feed
    BETWEEN THE CEOs - Executive Interviews
    In this latest installment of the CEO Chat series, Craig Labovitz, co-founder and CEO of Deepfield, sits down with Light Reading's Steve Saunders in Light Reading's New York City office to discuss how Deepfield fits in with the big data trend and more.
    Grant van Rooyen, president and CEO of Cologix, sits down with Steve Saunders, founder and CEO of Light Reading, in the vendor's New Jersey facility to offer an inside look at the company's success story and discuss the importance of security in the telecom industry.
    Animals with Phones
    Live Digital Audio

    Of all the tech companies in the Valley, Intel has made the most aggressive commitment to building a diverse and inclusive workplace culture. It's doing so by taking concrete, measurable steps, making a large financial investment and through a commitment to complete transparency about its progress. In this radio show, WiC Director Sarah Thomas will be joined by Shlomit Weiss, Intel's Vice President, Data Center Group, and General Manager of Networking Engineering, who will share with us why Intel is tackling this huge challenge, how and to what effect. She will also discuss her unique experiences leading development of Client SOC development in the past and today leading development of all of the chipmaker's silicon hardware for networking IPs and discrete devices and managing a team of 600 engineers across Israel, Europe and the US.