%% You should probably cite rfc7610 instead of this I-D. @techreport{ietf-opsec-dhcpv6-shield-08, number = {draft-ietf-opsec-dhcpv6-shield-08}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-opsec-dhcpv6-shield/08/}, author = {Fernando Gont and Will (Shucheng) LIU and Gunter Van de Velde}, title = {{DHCPv6-Shield: Protecting against Rogue DHCPv6 Servers}}, pagetotal = 12, year = 2015, month = jul, day = 6, abstract = {This document specifies a mechanism for protecting hosts connected to a switched network against rogue DHCPv6 servers. It is based on DHCPv6 packet filtering at the layer 2 device at which the packets are received. A similar mechanism has been widely deployed in IPv4 networks ('DHCP snooping'); hence, it is desirable that similar functionality be provided for IPv6 networks. This document specifies a Best Current Practice for the implementation of DHCPv6-Shield.}, }