Enabling IPv6 Communication Between Overlapping VCN CIDR Networks
In the previous article, we discussed the IPv6 address
format and how it differs from IPv4. In this article, we will explore how IPv6
communication can be set up.
In the IPv4 model, VCN CIDR ranges must not overlap in order
to establish connectivity between networks. However, in real-world environments
- especially in multi-cloud architectures - CIDR overlap is a common challenge.
This limitation can be effectively addressed by using IPv6 for communication.
As we know, an IPv6 address includes a VCN-specific
identifier, which ensures global uniqueness. Because of this uniqueness,
interconnectivity between networks is possible even when their IPv4 CIDR ranges
overlap.
Let’s look at the steps in detail. First, we create two VCNs
with the same IPv4 CIDR range. Next, we enable IPv6 CIDR ranges for both VCNs
to allow seamless communication over IPv6.
The VCN has only IPv4 CIDR Range.
Lets enable IPv6 CIDR range to the VCN.
After enable, we could see IPv6 CIDR range now.
Right now, only VCN got enabled with IPv6 and we need to
enable IPv6 CIDR range at Subnet level.
In the Subnet -> IP Administration page, add IPv6 prefix.
Perform the above steps for Second VCN and subnets within
the second vcn.
At this stage VCNs and Subnets are configured with IPv6.
Lets test the communication among them by creating VM compute instance in each
VCN and try to communicate through IPv6.
After instance creation, we can check their IPv4 and IPv6
address.
At the network side, we need to enable rules to allow
communication among them. Add Security list and Route rule to allow
communication between the instances. Specify IPv6 CIDR range of other VCN as
Source CIDR (Ingress) and Destination CIDR (Egress) and use “IPv6-ICMP”
protocol.
First_VCN
In general, the communication between different VCN happens
via Local peering gateway, but here IPv4 CIDR ranges are overlapping, hence we
can’t use Local peering gateway, lets use Internet gateway.
Second_VCN
Perform the security rule and Route rule configuration in
Second VCN.
Test the connectivity by pinging the compute instances from
each other.
No comments:
Post a Comment