> -----Original Message-----

> From: Ted Lemon [mailto:[email protected]]

> Sent: Thursday, October 18, 2012 6:11 PM

> To: Tirumaleswar Reddy (tireddy)

> Cc: [email protected]

> Subject: Re: [mif] New Version Notification for draft-reddy-mif-dhcpv6-

> precedence-ops-02.txt

>

> On Oct 18, 2012, at 8:32 AM, Tirumaleswar Reddy (tireddy) 
> <[email protected]<mailto:[email protected]>>

> wrote:

> > These options can also be used to conditionally disable IPv6 temporary

> addresses in a managed network for selective hosts without authentication

> supplicant.

>

> How would that work?



Hi Ted,



For e.g. In Enterprise premises hosts with EAP kind of supplicants can be 
tracked even when the IP address changes but for guests, BYOD (Bring your Own 
Device) without such supplicants IP address based authentication is still 
required for such users. When Address-based authentication is used, re-

authentication occurs for each new address obtained by the host, which can 
create a lot of authentication transactions. Switches acting as DHCP relay 
agent can influence the DHCP server not to assign temporary addresses. It's 
explained in detail in section 3.2.1 "Avoiding Excessive IP-Based 
Authentication" of this draft.



> Have you raised this in 6man ?



The above point was discussed in 6man specific to privacy addresses 
http://www.ietf.org/mail-archive/web/ipv6/current/msg15710.html



--Tiru.
_______________________________________________
mif mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/mif

Reply via email to