IPv6 & RPKI Implementation Tasks

Posted 4 days ago

Worldwide

Summary

1. Pre-Implementation / Design • Review the received HLD/LLD, network topology and device inventory. • Review the complete IPv6 traffic path for DMZ segment from ISP → DDoS → Edge Router → Firewall → F5 WAF → Core/ACI → Server. • Review the complete IPv6 traffic path for UAT segment from ISP → DDoS → Edge Router → Firewall → F5 WAF →DC firewall→ Core/ACI → Server. • Prepare the IPv6 addressing/subnet allocation plan based on the IPv6 prefix allocated by RIPE. • Prepare the detailed implementation and rollback plan. 2. ISP IPv6 Connectivity • Obtain the IPv6 point-to-point subnet and IPv6 BGP peering details from each ISP. • Configure IPv6 addressing on the ISP-facing interfaces • Establish eBGP IPv6 peering with the respective ISPs. • Configure IPv6 BGP route advertisement and inbound/outbound routing policies. • Validate IPv6 BGP establishment and route exchange. • Validate primary/backup ISP routing and failover. 3. Internet Edge IPv6 Enablement • Enable IPv6 routing on the edge routers (2 Main site; 2 DR site) • Configure required IPv6 interfaces and routing. • Configure IPv6 routing toward the internal network. • Apply appropriate IPv6 routing policies equivalent to the existing IPv4 design. • Verify IPv6 reachability from the edge toward the internal network. 4. Firewall IPv6 Enablement • Enable/configure IPv6 on the Internet firewalls (Internet firewall & DC firewall (4 Main site; 4 DR site)). • Configure required IPv6 interfaces and routing. • Create IPv6 security policies corresponding to the required application traffic. • Validate IPv6 traffic forwarding through the firewall. 5. F5 WAF / Load Balancer IPv6 Enablement • Enable IPv6 connectivity on the F5 WAF/load balancer. (2 Main site; 2 DR site) • Configure IPv6 Virtual Server/VIP addresses as required. • Configure IPv6-related pool/member connectivity where applicable. • Configure/verify WAF policies for IPv6 traffic. • Validate IPv6 traffic flow from the F5 toward the backend application. 6. Core / ACI / Server Network IPv6 Enablement • Enable IPv6 routing on the required Core/ACI components. • Configure IPv6 L3 connectivity toward the required server/UAT segments. • Configure required ACI L3Out, Bridge Domain and Contract policies for IPv6. • Configure IPv6 addressing/default gateway on the required server networks. • Enable IPv6 on the applicable servers/endpoints. • Validate end-to-end IPv6 connectivity up to the application servers. 7. DNS • Provide the required AAAA record information for the IPv6-enabled applications. • Global/DNS administrators to create AAAA records on DNS servers. • Validate public DNS resolution over IPv6. 8. Arbor IPv6 Enablement • TBD 9. RIPE / RPKI • Verify the allocated IPv6 prefix in the RIPE account. • Create the required ROA (Route Origin Authorization) for the IPv6 prefix. • Configure the correct originating ASN (based on the information received). • Define the authorized IPv6 prefix and maximum length as required. • Validate that the ROA is successfully published and visible in the RIPE RPKI system. • Verify the resulting RPKI status of the advertised IPv6 route. 10. End-to-End Testing • Verify IPv6 BGP sessions with all applicable ISPs. • Verify IPv6 route advertisement to the Internet. • Verify IPv6 reachability from the Internet to the public application. • Verify IPv6 traffic through DDoS → Edge → Firewall → F5 → ACI → Server. • Verify application accessibility using IPv6. • Verify DNS AAAA resolution. • Perform ISP failover testing. • Verify return-path routing. • Verify RPKI/ROA validity of the advertised prefix. • Perform UAT and obtain customer acceptance. 11. Documentation & Handover • Update HLD/LLD with the implemented IPv6 design. • Provide IPv6 addressing and routing details. • Provide implemented configuration details. • Provide test/validation report. • Provide as-built network diagram. • Conduct knowledge transfer/handover.

  • Less than 30 hrs/week
    Hourly
  • 1-3 months
    Duration
  • Expert
    Experience Level
  • Remote Job
  • Complex project
    Project Type
Skills and Expertise
Mandatory skills
Network Security
Network Administration
Activity on this job
  • Proposals:5 to 10
  • Interviewing:
    0
  • Invites sent:
    0
  • Unanswered invites:
    0
About the client
Member since Aug 16, 2026
  • Saudi Arabia
    3:45 PM

Explore similar jobs on Upwork

Network Engineering
Network Administration
Ubiquiti
Cisco Meraki
Aruba
RADIUS
Wireless Network Implementation
Technical Support
Spanish
Portuguese
Network Security
Network Administration
System Administration
Encryption
Wireless Security

How it works

  • Post a job icon
    Create your free profile
    Highlight your skills and experience, show your portfolio, and set your ideal pay rate.
  • Talent comes to you icon
    Work the way you want
    Apply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
  • Payment simplified icon
    Get paid securely
    From contract to payment, we help you work safely and get paid securely.
Want to get started? Create a profile

About Upwork

  • Rating is 4.9 out of 5.
    4.9/5
    (Average rating of clients by professionals)
  • G2 2021
    #1 freelance platform
  • 49,000+
    Signed contract every week
  • $2.3B
    Freelancers earned on Upwork in 2020

Find the best freelance jobs

Growing your career is as easy as creating a free profile and finding work like this that fits your skills.

Trusted by

  • Microsoft Logo
  • Airbnb Logo
  • Bissell Logo
  • GoDaddy Logo