Actionable Transition Blueprint

Interactive Institutional Deployment Roadmap Generator

Turn diagnostic audits into structured execution across 4 distinct phases. Assign responsible roles, track milestones, and download customized compliance checklists for your ICT steering committee.

Institutional Transition Progress
13% Complete(1 of 8 Milestones Done)

Phase 1: Discovery & Audit (Months 1-2)

1 / 2 Done
Role: Network Engineering & IT OpsCompleted

Conduct Complete Asset & IP Address Inventory

Catalogue all edge routers, core switches, firewalls, enterprise software, and cloud instances to verify hardware/software IPv6 compatibility.

Outcome: Hardware capability audit report with clear hardware refresh requirements.Click to advance state →
Role: Network Engineering & ProcurementIn Progress

Evaluate Upstream ISP Transit & Peering SLAs

Engage with primary and backup transit providers (MTN, Airtel, RENU, Liquid) to verify native BGP IPv6 peering support and SLA terms.

Outcome: Signed dual-stack transit agreement or scheduled upstream migration date.Click to advance state →

Phase 2: Architecture & Addressing Plan (Months 3-4)

0 / 2 Done
Role: Network Architecture TeamIn Progress

Acquire Official AFRINIC / ISP IPv6 Prefix Allocation

Apply for an independent /32 (or /48) Provider Independent block from AFRINIC or receive a dedicated /48 allocation from your ISP.

Outcome: Registered institutional IPv6 prefix assigned in AFRINIC WHOIS database.Click to advance state →
Role: Lead Network ArchitectNot Started

Formulate Subnetting Architecture (/64 per VLAN)

Develop a hierarchical hexadecimal subnetting blueprint, allocating standard /64 subnets to every branch, campus building, and data center VLAN.

Outcome: Immutable IPAM database and addressing documentation.Click to advance state →

Phase 3: Pilot & Staging Deployment (Months 5-6)

0 / 2 Done
Role: Cyber Security & Edge TeamNot Started

Update Perimeter Firewalls & Security Groups for IPv6

Mirror all critical IPv4 firewall policies (`iptables`, `pfSense`, Cisco ASA/Firepower) to IPv6 and explicitly permit RFC 4890 ICMPv6 packets.

Outcome: Zero-trust dual-stack firewall configuration without ICMPv6 black holes.Click to advance state →
Role: DevOps & Systems AdministratorsNot Started

Enable Dual-Stack on Staging Web Servers & DNS

Assign AAAA records and IPv6 virtual IPs (`[::]:443`) to non-critical internal portals or staging subdomains (`staging.institution.ug`).

Outcome: Successful end-to-end dual-stack HTTP/HTTPS reachability verification.Click to advance state →

Phase 4: Full Production & Governance (Months 7-12)

0 / 2 Done
Role: DNS & Domain AdministratorNot Started

Publish Production AAAA Records for Primary Domain

Update authoritative zone files to broadcast AAAA records for `www.institution.ug` and main enterprise application gateways.

Outcome: Public score of 100/100 on Uganda DNS Observatory & global accessibility.Click to advance state →
Role: Executive Leadership & ProcurementNot Started

Enforce Mandatory IPv6-Ready Procurement Policies

Incorporate strict dual-stack RFC compliance clauses into all future IT hardware, cloud hosting, and software vendor contracts.

Outcome: Permanent institutional resilience against IPv4 obsolescence.Click to advance state →