MAC-Forced Forwarding: A Method for Subscriber Separation on an Ethernet Access Network
RFC 4562

Technical Summary
This document describes a mechanism to ensure layer-2 separation of
LAN stations accessing an IPv4 gateway over a shared Ethernet
segment. Rather than use standard "bridge" forwarding, this document
uses a variant of ARP spoofing and address filtering to prevent nodes
from improperly sending traffic directly to a MAC address other than
that of the designated Access Router.
Working Group Summary
This document is not a Working Group document and has not been
discussed in any WG.
Protocol Quality
This document has been reviewed for the IESG by Thomas Narten.


The IESG had serious concerns about an earlier version of
this document with respect to its affect on IPv6 and VRRP.
The authors chose to make significant efforts to correct the
document based on these concerns. The latest version (-04,
published Jan 27) is now satisfactory.

This RFC is not a candidate for any level of Internet Standard.  The
IETF disclaims any knowledge of the fitness of this RFC for any
purpose and in particular notes that the decision to publish is not
based on IETF review for such things as security, congestion control,
or inappropriate interaction with deployed protocols.  The RFC Editor
has chosen to publish this document at its discretion.  Readers of
this document should exercise caution in evaluating its value for
implementation and deployment.  See RFC 3932 for more information.