%% You should probably cite rfc7610 instead of this I-D. @techreport{ietf-opsec-dhcpv6-shield-07, number = {draft-ietf-opsec-dhcpv6-shield-07}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-opsec-dhcpv6-shield/07/}, author = {Fernando Gont and Will (Shucheng) LIU and Gunter Van de Velde}, title = {{DHCPv6-Shield: Protecting Against Rogue DHCPv6 Servers}}, pagetotal = 11, year = 2015, month = may, day = 15, abstract = {This document specifies a mechanism for protecting hosts connected to a switched network against rogue DHCPv6 servers. It is based on DHCPv6 packet-filtering at the layer-2 device at which the packets are received. A similar mechanism has been widely deployed in IPv4 networks ('DHCP snooping'), and hence it is desirable that similar functionality be provided for IPv6 networks. This document specifies a Best Current Practice for the implementation of DHCPv6 Shield.}, }