One document matched: draft-ietf-mip6-hiopt-18.xml


<?xml version="1.0" encoding="UTF-8"?>

<!DOCTYPE rfc SYSTEM "rfc2629.dtd" [
<!ENTITY rfc1035 PUBLIC ''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.1035'>
<!ENTITY rfc2119 PUBLIC ''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.2119.xml'>
<!ENTITY rfc3315 PUBLIC ''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.3315.xml'>
<!ENTITY rfc3736 PUBLIC ''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.3736.xml'>
<!ENTITY rfc3753 PUBLIC	''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.3753.xml'>
<!ENTITY rfc4282 PUBLIC ''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.4282.xml'>
<!ENTITY rfc4640 PUBLIC	''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.4640.xml'>
<!ENTITY rfc5447 PUBLIC '' 
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.5447.xml'>
<!ENTITY rfc5380	PUBLIC ''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.5380.xml'>
<!ENTITY rfc5555 PUBLIC	''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.5555.xml'>
<!ENTITY rfc6052 PUBLIC	''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.6052.xml'>
<!ENTITY rfc6275 PUBLIC	''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.6275.xml'>
<!ENTITY rfc6422 PUBLIC	''
 'http://xml.resource.org/public/rfc/bibxml/reference.RFC.6422.xml'>
]>

<?xml-stylesheet type='text/xsl' href='rfc2629.xslt' ?>

<?rfc toc="yes" ?>
<?rfc iprnotified="no" ?>
<?rfc strict="yes" ?>
<?rfc symrefs="yes" ?>
<?rfc sortrefs="yes"?>

<rfc category="std" ipr="pre5378Trust200902" docName="draft-ietf-mip6-hiopt-18.txt">

<front>

<title abbrev="DHCPv6 for Home Info Discovery in MIPv6">
	DHCP Options for Home Information Discovery in MIPv6
</title>

	<author initials="H" surname="Jang" fullname="Heejin Jang">
		<organization abbrev="Samsung">Samsung Electronics</organization>
		<address>
			<postal>
				<street>416 Maetan-3dong, Yeongtong-gu</street>
				<city>Suwon 443-742</city>
				<country>Korea</country>
			</postal>
			<email>heejin.jang@samsung.com</email>
		</address>
	</author>

	<author initials='A' surname="Yegin" fullname='Alper E. Yegin'>
		<organization abbrev="Samsung">Samsung Electronics</organization>
		<address>
			<postal>
				<street></street>
				<city>Istanbul</city>
				<country>Turkey</country>
			</postal>
			<email>a.yegin@partner.samsung.com</email>
		</address>
	</author>

	<author initials='K' surname="Chowdhury" fullname='Kuntal Chowdhury'>
		<organization abbrev="Starent Networks">Starent Networks</organization>
		<address>
			<postal>
				<street>30 International Place</street>
				<city>Tewksbury, MA  01876</city>
				<country>US</country>
			</postal>
			<email>kchowdhury@starentnetworks.com</email>
		</address>
	</author>

	<author initials='J' surname="Choi" fullname='JinHyeock Choi'>
		<organization abbrev="Samsung">Samsung Advanced Institute of Technology</organization>
		<address>
			<postal>
				<street>P.O. Box 111</street>
				<city>Suwon 440-600</city>
				<country>Korea</country>                </postal>
			<email>jinchoe@samsung.com</email>
		</address>
	</author>

    <author fullname="Ted Lemon" initials="T." surname="Lemon">
      <organization>Nominum</organization>

      <address>
        <postal>
          <street>2000 Seaport Blvd</street>

          <!-- Reorder these if your country does things differently-->

          <city>Redwood City</city>

          <region>CA</region>

          <code>94063</code>

          <country>USA</country>
        </postal>

        <phone>+1 650 381 6000</phone>

        <email>mellon@nominum.com</email>
      </address>
    </author>

	<date/>
	<area>Internet</area>
	<workgroup>MIP6 Working Group</workgroup>

    <abstract>
	<t> This draft defines a DHCP-based scheme to enable dynamic discovery of Mobile IPv6 home network information. New DHCP options are defined which allow a mobile node to request the home agent IP address, FQDN, or home network prefix and obtain it via the DHCP response.</t>
	</abstract>
     
</front>

<middle>

<section title="Introduction">


<t>Before a mobile node can engage in Mobile IPv6 signaling with a home agent, it should either know the IP address of the home agent via pre-configuration, or dynamically discover it.  The Mobile IPv6  specification <xref target='RFC6275'/> describes how home agents can be dynamically discovered by mobile nodes that know the home network prefix.  This scheme does not work when prefix information is not already available to the mobile node.  This document specifies extensions to DHCPv6 <xref target='RFC3736'/> <xref target='RFC3315'/> to deliver the home agent information to the mobile node in the form of the IP address of the home agent or the <xref target="RFC1035">Fully-qualified Domain Name (FQDN)</xref> of the home agent. The information delivered to the mobile node may also include the home prefix for the mobile node. The solution involves defining a new DHCP option to carry home network prefix, home agent IP address and FQDN information. The mobile node MAY also use the home prefix to discover the list of home agents serving the home prefix using the Dynamic Home Agent Address Discovery mechanism specified in <xref target='RFC6275'/>.</t> 

<t>As part of configuring the initial TCP/IP parameters, a mobile node can find itself a suitable home agent. Such a home agent might reside in the access network that the mobile node connects to, or in a home network that the mobile node is associated with. A mobile node can indicate its home network identity when roaming to a visited network in order to obtain the MIP6 bootstrap parameters from the home network. As an example, the visited network may determine the home network of the mobile node based on the realm portion of the NAI (Network Access Identifier) <xref target='RFC4282'/> used in <xref target="RFC5447">access authentication</xref>. </t>

<t>The mobile node may or may not be connected to the "home" network when it attempts to learn Mobile IPv6 home network information. This allows operators to centrally deploy home agents while being able to bootstrap mobile nodes that are already roaming. This scenario also occurs when HMIPv6 <xref target='RFC5380'/> is used, where the mobile node is required to discover the MAP (a special home agent) that is located multiple hops away from the mobile node's attachment point.</t>
</section>

<section title="Terminology">

<t>The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in <xref target='RFC2119'/>.</t>

<t>General mobility terminology can be found in <xref target="RFC3753" />. The following additional terms, as defined in <xref target="RFC4640" />, are used in this document:</t>

<t><list style="hanging" hangIndent="4">
<t hangText="Access Service Provider (ASP):">A network operator that provides direct IP packet forwarding to and from the mobile node.</t>

<t hangText="Mobility Service Provider (MSP):">A service provider that provides Mobile IPv6 service.  In order to obtain such service, the mobile node must be authenticated and authorized to use the Mobile IPv6 service.</t>

<t hangText="Mobility Service Authorizer (MSA):">A service provider that authorizes Mobile IPv6 service.</t>
</list></t>
</section>

<section title="DHCP options for Home Network/Agent Dynamic Discovery">

<t>This section introduces new DHCP options which are used for dynamic discovery of the home agent's IPv6 address, IPv6 home network prefix, or FQDN information in Mobile IPv6.  Transport to a home agent over IPv4 is also supported by specifying an IPv4-Embedded IPv6 address.  The detailed procedures are described in Section 2.3.2 of <xref target='RFC5555'>Mobile IPv6 support for dual stack Hosts and Routers</xref>.</t>

<t>The names of options listed in this section all start with MIP6, in order to differentiate them from other DHCP options that might have similar names.   However, throughout the rest of this document, the options are referred to by name without the MIP6 prefix, for brevity.</t>

<section title="MIP6 Home Network ID FQDN Option">

<t>This option is used by mobile nodes to communicate to the DHCP server an FQDN that identifies the target home network for which the client is requesting configuration information.   When the mobile nodes requests configuration for more than one target home network, this option is also used by the server to identify the target home network for each Identified Home Network Information option returned.</t>

<t>When a mobile node sends this option to request information about a specific home network, the option is simply included in the DHCP message from the mobile node.   When a server responds with an Identified Home Network Information option, this option MUST be encapsulated in the Identified Home Network Information option that it identifies.</t>

<figure><artwork>
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|       OPTION_MIP6_HNIDF       |           Option-len          |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                                                               |
|               Home Network Identification FQDN                |
.                                                               .
.                                                               .
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
</artwork></figure>
<t><list style="hanging" hangIndent="4">
  <t hangText="Option-code">OPTION_MIP6_HNIDF (TBD)</t>
  <t hangText="Option-len">Length of option, per RFC3315</t>
  <t hangText="Home Network Identification FQDN">
    A fully-qualified domain name that identifies a mobile IP
    home network for which the client is seeking configuration
    information.   This is encoded in accordance with RFC3315,
    section 8, "Representation and Use of Domain Names."
  </t>
</list></t>

</section>
<section title="Home Network Information Options">
<t>There are three different options that specify home network information.   Which of these options is used depends on what kind of home network information the client needs.   Each of these options is used to encapsulate options containing prefix and home agent information about the home network for which configuration information was requested.</t>

<section title="MIP6 Visited Home Network Information Option">

<t>This option is used by relay agents and DHCP servers to provide information about the local home network.</t>

<figure><artwork>
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|       OPTION_MIP6_VDINF       |           Option-len          |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                                                               |
|                            Options                            |
.                                                               .
.                                                               .
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
</artwork></figure>
<t><list style="hanging" hangIndent="4">
  <t hangText="Option-code">OPTION_MIP6_VDINF (TBD)</t>
  <t hangText="Option-len">Length of option, per RFC3315</t>
  <t hangText="Suboptions">
    One or more suboptions, specifying information about the local ASP
    (visited domain).
  </t>
</list></t>

</section>
<section title="MIP6 Identified Home Network Information Option">

<t>This option is used by relay agents and DHCP servers to provide
information about the the home network identified by a Home Network
Identifier FQDN option.</t>

<figure><artwork>
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|       OPTION_MIP6_IDINF       |           Option-len          |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                                                               |
|                            Options                            |
.                                                               .
.                                                               .
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
</artwork></figure>
<t><list style="hanging" hangIndent="4">
  <t hangText="Option-code">OPTION_MIP6_IDINF (TBD)</t>
  <t hangText="Option-len">Length of option, per RFC3315</t>
  <t hangText="Suboptions">
    One or more suboptions, specifying information about the home
    network identified by a Home Network Identifier FQDN option
    sent by a mobile node.
  </t>
</list></t>
</section>

<section title="MIP6 Unrestricted Home Network Information Option">

<t>This option is used by relay agents and DHCP servers to provide
information about the a home network specified by the DHCP server
administrator.</t>

<figure><artwork>
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|       OPTION_MIP6_UDINF       |           Option-len          |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                                                               |
|                            Options                            |
.                                                               .
.                                                               .
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
</artwork></figure>
<t><list style="hanging" hangIndent="4">
  <t hangText="Option-code">OPTION_MIP6_UDINF (TBD)</t>
  <t hangText="Option-len">Length of option, per RFC3315</t>
  <t hangText="Suboptions">
    One or more suboptions, specifying information about some
    home network as specified by the DHCP server administrator.
  </t>
</list></t>
</section>
</section>

<section title="MIP6 Home Network Prefix Option">

<t>This option is used by DHCP servers and relay agents to define the prefix for a home network.   This option should only appear in one of the Home Network Information options.</t>

<figure><artwork>
 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|        OPTION_MIP6_HNP        |           Option-len          |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|  Prefix-len   |                                               |
+-+-+-+-+-+-+-+-+                                               +
|                                                               |
|                           Prefix                              |
|                                                               |
|                                                 +-+-+-+-+-+-+-+
|                                                 |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
</artwork></figure>
<t><list style="hanging" hangIndent="4">
  <t hangText="Option-code">OPTION_MIP6_HNP (TBD)</t>
  <t hangText="Option-len">Length of option, per RFC3315</t>
  <t hangText="Prefix-len">Length of prefix</t>
  <t hangText="Prefix">Home Network Prefix</t>
</list></t>
</section>

<section title="MIP6 Home Agent Address Option">

<t>This option is used by DHCP servers and relay agents to specify the home agent IP address.   In cases where the home agent must be contacted over an IPv4-only infrastructure, the IPv4 address is specified as an IPv4-Embedded IPv6 address using the <xref target="RFC6052">Well-Known prefix</xref>.   This option should only appear in one of the Home Network Information options.</t>

<figure><artwork>

 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|        OPTION_MIP6_HAA        |           Option-len          |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                                                               |
|                                                               |
|                           Address                             |
|                                                               |
|                                                               |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
</artwork></figure>
<t><list style="hanging" hangIndent="4">
  <t hangText="Option-code">OPTION_MIP6_HAA (TBD)</t>
  <t hangText="Option-len">Length of option, per RFC3315</t>
  <t hangText="Address">IP Address of home agent</t>
</list></t>
</section>

<section title="MIP6 Home Agent FQDN Option">

<t>This option is used by DHCP servers and relay agents to specify the home agent FQDN.   This FQDN is used to look up one or more A or AAAA records containing IPv4 or IPv6 addresses for the home agent, as needed.  This option should only appear in one of the Home Network Information options.</t>

<figure><artwork>

 0                   1                   2                   3
 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|        OPTION_MIP6_HAF        |           Option-len          |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
|                                                               |
|                                                               |
|                             FQDN                              |
|                                                               |
|                                                               |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
</artwork></figure>
<t><list style="hanging" hangIndent="4">
  <t hangText="Option-code">OPTION_MIP6_HAF (TBD)</t>
  <t hangText="Option-len">Length of option, per RFC3315</t>
  <t hangText="Address">
    FQDN resolving to one or more IPv4 and/or IPv6 addresses for
    the home agent.  This is encoded in accordance with
    RFC3315, section 8, "Representation and Use of Domain Names."
  </t>
</list></t>

</section>

</section>

<section title="Option Usage">

<t>The requesting and sending of the proposed DHCP options follow the rules for DHCPv6 options in <xref target='RFC3315'/>. </t>

<section title="Mobile Node Behavior">

<t>Mobile nodes MAY obtain MIP6 configuration information either during a stateful configuration exchange [RFC3315] or a stateless configuration exchange [RFC3736].</t>

<t>Mobile nodes that obtain MIP6 configuration information using a stateful configuration exchange SHOULD include the same options in every message they send to the DHCP server.</t>

<t>Mobile nodes that obtain MIP6 configuration using a stateless exchange MAY omit MIP6 configuration from some exchanges, but SHOULD reconfigure whenever a change in the attached network is detected.   If the DHCP server responds to a MIP6-related stateless configuration request with an Information Request Timer option, the mobile node SHOULD attempt to reconfigure when the IRT expires.</t>

<t>A mobile node using stateless configuration may try to perform home network information discovery when it lacks home network information for MIPv6 or needs to change the home agent for some reason.   For example, this may be necessary to recover from the failure of an existing home agent or to use the local home agent located in the network where the mobile node is currently attached. Note that despite the home information discovery procedure the mobile node may continue to use the old home agent, in order to avoid losing current sessions.</t>

<section title="Requesting MIP6 configuration">

<t>Mobile nodes signal that they are interested in being configured with MIP6 home agent information by requesting one or more of the three Home Network Information options—the Visited Home Network Information option, the Identified Home Network Information option, or the Unrestricted Home Network Information option.   To request these options, the client lists them in the Option Request Option.   A client that requests any of these three options in the ORO MUST also request the Home Network Identification FQDN option, the Home Network Prefix option, the Home Agent Address Option, and the Home Agent FQDN option.</t>

<t>If the mobile node requests the Visited Home Network Information option, this indicates that it is interested in learning the home network information that pertains to the currently visited network. This type can be used to discover local home agents in the local ASP.</t>

<t>If the mobile node requests the Identified Home Network Information option, this indicates that it is interested in learning the home network information that pertains to a specified realm. This type can be used to discover home agents that are hosted by a user's home domain or by any target domain.  A mobile node requesting the Identified Home Network Information option MUST include a Client Home Network ID FQDN option identifying the MSP being identified.  The target MSP can be a mobile node's home MSP or any MSP which has a trusted roaming relationship with the mobile node's MSA.</t>

<t>If the mobile node has no preference as to the home network with which it should be configured, it SHOULD request the Unrestricted Home Network Information option, and SHOULD NOT request either the Visited Home Network Information option or the Identified Home Network Information option.</t>

<t>A client that wishes to be configured with both the Visited Home Network Information option and the Identified Home Network Information option may request both options in the Option Request Option.   A client may request information about more than one identified domain by requesting the Identified Home Network Information option in the ORO and including more than one Home Network ID FQDN option.   A client that sends more than one Home Network ID FQDN option MUST request the Home Network ID option in the ORO.</t>

</section>

<section title="Processing MIP6 configuration information">

<t>DHCP Clients on mobile nodes should be prepared to receive any MIP6 Home Network Information options they request.   If more than one Home Network ID FQDN option was sent, the client should be prepared to handle zero or more Identified Home Network Information options in response; the DHCP server may not have configuration information for all targeted domains, or, indeed, for any.   If a misconfigured server returns an Identified Home Network option that does not contain a Home Network ID FQDN option corresponding to one that the client requested, the client MUST silently discard that Identified Home Network option.</t>

<t>If any of the three Home Network Information options is returned, configuration information will be included within it.   The client must be prepared to handle home agent addresses either in the form of the Home Agent Address option or the Home Agent FQDN option.</t>

<t>If the client finds a v4-embedded IPv6 address in a Home Agent Address option, it may only use this address to communicate over IPv4.   If a Home Network Information option does not contain complete configuration information, the client MUST silently discard that Home Network Information option.</t>

<t>If the client receives any Home Network ID FQDN options, Home Network Prefix options, Home Agent Address options, or Home Agent FQDN options that are not encapsulated in one of the three types of Home Network Information options, it MUST silently discard these options.</t>

<t>The DHCP client must pass whatever configuration information it receives to the appropriate mobile IP implementation on the mobile node.   How this is done, and what the mobile IP implementation on the mobile node does with this information, is outside the scope of this document.</t>

<t>As described later in this section, servers may provide more than one Home Network Information option, or multiple Home Agent Prefix, Home Agent Address or Home Agent FQDN options.   When provided with multiple Visited Home Network Information options or Unrestricted Home Network Information options of the same type, or with multiple sub-options within such an option, the mobile node SHOULD choose the first one that it can employ.</t>
     
<t>If the DHCP client on a mobile node receives any MIP6 Home Network Prefix options, MIP6 Home Agent Address option, or MIP6 Home Agent FQDN option that are not contained within Home Network Information options, the DHCP client MUST silently discard these options.</t>
</section>
</section>

<section title="Relay Agent Behavior">
<t>DHCP relay agents may in some cases have access to configuration information for the mobile node.   In such cases, relay agents MAY send Visited Home Network Information options, Identified Home Network Information options, and/or Unrestricted Home Network Information options to the DHCP server.   To do so, the Relay agent MUST encapsulate these options in a <xref target="RFC6422">Relay Supplied Options option</xref>.   If the DHCP Relay Agent includes any Identified Home Network Information options, these options MUST correspond to home networks identified in Home Network ID FQDN options in the client request.   In addition, each Identified Home Network option must contain a Home Network ID FQDN option identical to the one sent by the client, to identify the network to the client.</t>

<t>No special handling is required when processing relay-reply messages.</t>
</section>

<section title="DHCP Server Behavior">
<t>DHCP servers generally can simply be configured with Visited Network Information options, Identified Network Information options, and Unrestricted Network Information options.   In the case of Visited Network Information options and Unrestricted Network Information options, which clients get what options depends on operator configuration.</t>

<t>A DHCP server MAY maintain a table of Home Network ID FQDNs.   For each such FQDN, a server that maintains such a table SHOULD include an Identified Network Information option.   Such a server would look up the FQDN from any Home Network ID FQDN options provided by the client in its table, and for each match, include the Identified Network Information option configured in the table entry for that FQDN.</t>

<t>If a DHCP server does not implement the Home Network ID FQDN table, or some similar functionality, it is an error for the operator to configure it with any Identified Network Information options.   These options could be erroneously forwarded to the client, which would have no use for them, and is required to discard them.</t>

<t>DHCP servers that implement the Home Network ID FQDN table must, when sending an Identified Network Information option to the client, include a Home Network ID option within the Identified Network Information option that identifies the home network for which configuration information is being sent.</t>

<t>Aside from the Home Network ID FQDN table, the actual behavior of the DHCP server with respect to MIP6 configuration is simply in accordance with the DHCPv6 protocol specification [RFC3315] and depends on operator configuration.   No special processing is required for Visited Home Network Information options or Unrestricted Home Network Information options.</t>
</section>

<section title="Home agent discovery using a Network Access Server">
<t><xref target='RFC5447'/> describes the complete procedure for home agent assignment among the mobile node, NAS (Network Access Server), DHCP and AAA entities for the bootstrapping procedure in the integrated scenario.</t>

<t>A NAS is assumed to be co-located with a DHCP relay agent or a DHCP server in this solution.  In a network where the NAS is not co-located with a DHCP relay nor a server, the server may not be provided with the home network information from the NAS, and thereby it may either fail to provide information, or provide home information which has been preconfigured by the administrator or which is acquired through a mechanism that is not described in this document.</t>
</section>
</section>

<section title="Security Considerations">

<t>Secure delivery of home agent and home network information from a DHCP server to the mobile node (DHCP client) relies on the same security as DHCP. The particular option defined in this draft does not have additional impact on DHCP security.</t>

<t>Aside from the DHCP client to server interaction, an operator must also ensure secure delivery of mobile IP information to the DHCP server. This is outside the scope of DHCP and the newly defined option.</t>

<t>The mechanisms in this specification could be used by attackers to learn the addresses of home agents in the home network, or to feed incorrect information to mobile nodes.</t>

<t>The ability to learn addresses of nodes may be useful to attackers because brute-force scanning of the address space is not practical with IPv6.  Thus, they could benefit from any means which make mapping the networks easier.  For example, if a security threat targeted at routers or even home agents is discovered, having a simple mechanism to easily find out possible targets may prove to be an additional security risk.</t>

<t>Apart from discovering the address(es) of home agents, attackers will not be able to learn much from this information, and mobile nodes cannot be tricked into using wrong home agents, as the actual communication with the home agents employs mutual authentication.</t>

<t>The mechanisms from this specification may also leak interesting information about network topology and prefixes to attackers, and where there is no security to protect DHCP, even modify this information. Again, the mobile nodes and home agents employ end-to-end security when they communicate with each other. The authentic source of all information is that communication, not the information from DHCP.</t>

<t>However, attacks against the information carried in DHCP may lead to denial-of-service if mobile nodes are unable to connect to any home agent, or choose a home agent that is not the most preferred one.</t>
</section>

<section title="IANA Consideration">

<t>IANA is requested to assign the following new DHCPv6 Option Codes, DHCPv6 Sub-option Codes, and Id-type Codes in the registry maintained in http://www.iana.org/assignments/dhcpv6-parameters:</t>

<t>IANA is requested to assign the following new DHCPv6 Option Codes:</t>
<t>
<list style="symbols">
  <t>OPTION_MIP6_HNIDF for the Home Network ID FQDN option</t>
  <t>OPTION_MIP6_VDINF for the Visited Home Network Information option</t>
  <t>OPTION_MIP6_IDINF for the Identified Home Network Information option</t>
  <t>OPTION_MIP6_UDINF for the Unrestricted Home Network Information option</t>
  <t>OPTION_MIP6_HNP for the Home Network Prefix option</t>
  <t>OPTION_MIP6_HAA for the Home Agent Address option</t>
  <t>OPTION_MIP6_HAF for the Home Agent FQDN option</t>
</list>
</t>
</section>

<section title="Acknowledgments">
<t>The authors would like to thank Kilian Weniger, Domagoj Premec, Basavaraj Patil, Vijay Devarapalli, Gerardo Giaretta, Bernie Volz, David W. Hankins, Behcet Sarikaya, Vidya Narayanan, Francis Dupont, Sam Weiler, Jari Arkko, Alfred Hoenes, Suresh Krishnan, and Miguel A. Diaz for their valuable feedback.</t>
</section>

</middle>

<back>
	<references	title='Normative References'>
	&rfc1035;
	&rfc2119;
	&rfc4282;
	&rfc3315;
	&rfc3736;
	&rfc5555;
	&rfc6052;	
	&rfc6275;	
	&rfc6422;	
	</references>
	
	<references	title='Informative References'>
	&rfc3753;
	&rfc4640;
	&rfc5380;
	&rfc5447;
    </references>

</back>

</rfc>

PAFTECH AB 2003-20262026-04-24 01:36:44