DHCPv6 default gateway option?

Simon Hobson dhcp1 at thehobsons.co.uk
Wed Dec 8 16:32:54 UTC 2010

Randall C Grimshaw wrote:
>Wow... I have to ask about the security concerns about this...
>With dhcp, before dhcp snooping, we would have a lot of problems 
>with rogue dhcp servers giving clients misinformation.
>Is there any protection against rogue routers in an ipv6 paradigm?

I don't see how there can be - if the client is expected to accept RA 
broadcasts then any old router will screw up the network. SO now you 
will have to check not only for rogue DHCP servers (since they will 
screw up clients too), but rogue routers with RA broadcasts.

I really cannot see how omitting gateways from DHCP for IPv6 is 
helpful in most managed environments.

Simon Hobson

