RFC 7610: BCP 199: DHCPv6-Shield: Protecting against Rogue DHCPv6 Servers
Best Current Practice
- F. Gont
- W. Liu
- G. Van de Velde
- August 2015
- IETF publication
- Operations and Management Area
Abstract
This document specifies a mechanism for protecting hosts connected to a switched network against rogue DHCPv6 servers. It is based on DHCPv6 packet filtering at the layer 2 device at which the packets are received. A similar mechanism has been widely deployed in IPv4 networks ('DHCP snooping'); hence, it is desirable that similar functionality be provided for IPv6 networks. This document specifies a Best Current Practice for the implementation of DHCPv6-Shield.