Overall Promotion and Intensive Construction of IPv6 Transformation of Shanghai Municipal Government Website —— A Case Study of IPv6 Scale Deployment and Application in Shanghai Big Data Center
I. Implementation Background and Objectives
According to the requirements of the Action Plan for Promoting the Scale Deployment of the Sixth Edition of Internet Protocol (IPv6) issued by the Central Office and the State Council, the Notice of the General Office of the State Council on Printing and Distributing the Main Points of Government Affairs Disclosure in 2018 (Guo Ban Fa [2018] No.23), and the Notice of the General Office of the State Council on Printing and Distributing the Pilot Work Plan for Intensive Government Websites (Guo Ban Han [2018] No.71), Shanghai Big Data Center carried out the IPv6 upgrade and transformation of the whole station. At the same time, combined with the intensive platform construction of government websites, it organized and coordinated the websites of 16 district governments and 43 municipal government departments to realize IPv6 access and transformation simultaneously.
Second, the work situation
(a) to complete the "China Shanghai" portal IPv6 upgrade.
In 2018, based on the previous investigation, the Municipal Big Data Center made a work plan for upgrading and transforming the IPv6 portal of China Shanghai, and actively and steadily promoted related work in strict accordance with the work requirements.
The first is to clarify the subject of responsibility.The "China Shanghai" portal is hosted by the General Office of Shanghai Municipal People’s Government and undertaken by the Municipal Big Data Center. According to the job functions, the City Big Data Center is the main body responsible for the IPv6 deployment and transformation of "China Shanghai" portal website, responsible for implementing the work requirements and coordinating with other relevant departments to promote the IPv6 transformation of "China Shanghai".
The second is to clarify the status quo of the website.In July 2018, all the portals of "China Shanghai" were moved to the government cloud platform of the whole city, and the government cloud platform provided the network and equipment layer infrastructure in a unified way.
The third is to determine the work plan.After research and comparison, it is decided to use the firewall equipment exported from the network side, and use NAT64 protocol to realize the initiative connection of IPv4 network to access IPv6 network.
Figure 1: Business Access Process
NAT64 is a stateful network address and protocol conversion technology, which can realize the address and protocol conversion between IPv6 and IPv4 under TCP, UDP and ICMP protocols. This scheme can directly support IPv6 connection access without affecting the normal operation of the original business. The advantage is that the internal transformation of the data center is small, and it can be launched quickly, thus solving the problem of "skylight" on the page caused by external links.
Figure 2: Network deployment scenarios of 2:NAT64 and DNS64.
The Internet address of "China Shanghai" portal website is bound with the internal load-balancing address, so this time it will be realized by configuring NAT conversion from IPv6 address to IPv4 load-balancing address; This IPv6 address translation configuration is to add an IPv6 address entry on the original basis, without affecting the normal operation of the original IPv4 address.
At the end of 2018, we verified the connectivity, stability and IPv6 network effectiveness of the "China Shanghai" portal website one by one, and achieved the expected results.
(two) actively promote the city’s government website IPv6 upgrade.
The IPv6 transformation of Shanghai municipal government website needs the cooperation of many government departments and manufacturers, and it is difficult to coordinate and solve many tasks such as optical fiber circuit and political cloud network configuration, server networking and domain name resolution.
Since 2019, Shanghai has written the work requirements related to the IPv6 transformation of government websites into the "Annual Work Points of Government Affairs Openness" for two consecutive years. At the same time, according to the Notice of the General Office of Shanghai Municipal People’s Government on Printing and Distributing the Work Plan for the Construction of Intensive Platform of Shanghai Municipal Government Website (Hu Fu Ban [2019] No.9), we will deploy and promote the IPv6 transformation work together with the intensive work of government websites.
The website architecture of Shanghai municipal government is the interconnection of two platforms in urban areas, the websites of municipal departments are connected to the intensive platform of municipal government websites, and the network and equipment layer infrastructure is provided by the municipal government cloud platform. The 16 district-level platforms are the portal websites of all districts, which are transformed by the government cloud platforms of all districts.
The first is to complete the transformation of IPv6, an intensive platform for government websites.The transformation scope includes the portal website of the municipal government and the websites of 43 government departments. The municipal government cloud platform provides IPv6 addresses for the export of each website, and the municipal big data center applies for domain names for analysis.
Figure 3: IPv6 detection results
The second is to complete the IPv6 address transformation of cloud shield security protection service.The website authorities coordinate and promote Yundun technology providers to provide solutions, and apply for domain name resolution to Shanghai Big Data Center. At present, the websites of four departments using Yundun have all completed the IPv6 address transformation.
The third is to urge all commissions and bureaus to complete the IPv6 transformation of website dynamic link.Because most of the dynamic link backstage is developed and operated by the commissions, the IPv6 transformation of the website except the intensive part needs to be coordinated by the commissions. At present, most of the links have been transformed, and the IPv6 accessibility rate of the websites of various commissions and bureaus is basically above 90%.
The fourth is to complete the IPv6 address transformation of the portal website of the district government.The competent authorities of the portal websites of each district government formulated and implemented the upgrading scheme of the portal websites of this district government, and all 16 districts chose the cloud conversion service scheme to complete the IPv6 transformation.
Third, the effectiveness of the work
After intensive transformation, the use of IP in government websites has also changed from "multiple sites at one site" to "multiple sites at one site", and unified domain name resolution has been used to reduce the occupation of resources and greatly improve the efficiency of IPv6 upgrading.
At the end of 2020, the General Office of the State Council conducted a spot check on the IPv6 transformation of the national government websites. The websites of "China Shanghai" and 16 district governments all passed the retest, and the pass rate of the second and third level links exceeded 90%.
Fourth, work highlights
(1) Overall planning and unified deployment.The IPv6 transformation of government websites is a systematic project. From intensive integration to IPv6 transformation and deployment, it involves many contents, manufacturers and technical teams, and needs support from all sides. Shanghai Big Data Center actively cooperates with the general office of the municipal government to strengthen overall coordination and do a good job of communication and connection with technical support, construction trustees and network operators. After the transformation of IPv6, users of both IPv4 and IPv6 protocols can access it normally, so that government websites have many functions and services, and their normal use and access will not be affected.
(2) Intensive construction and simultaneous advancement.Shanghai Big Data Center reused the experience of "China Shanghai" IPv6 upgrade in the construction of intensive platform, and accelerated the deployment of IPv6 after relying on the intensive platform to solve most of the "external chain" problems. In 2019, relying on the intensive platform, it completed the IPv6 transformation of the city’s government websites in a unified way, and really achieved resource intensive.
(three) supervision and inspection to ensure the effectiveness.According to the Inspection Index of Government Websites and Government Affairs New Media and the Annual Assessment Index of Government Websites and Government Affairs New Media Supervision formulated by the General Office of the State Council, the Shanghai Big Data Center will bring the IPv6 upgrading of the government websites into the supervision from 2019. From July, 2020, report the IPv6 upgrade and transformation of the homepage of each website every month; At the same time, this work will be included in the annual evaluation of government websites to maintain the effectiveness of IPv6 upgrading.