IPv6 equivalent to DHCP Option 82 for geolocating customer MACs to certain ports of Multi-port Layer 2 demarcation devices

Florian Weimer fw at deneb.enyo.de
Sun May 8 12:17:37 CEST 2011

>> You still need unicast flood protection.

> What is that? 

Some switches periodically broadcast unicast traffic.  This is a
problem for DNS traffic, for instance.  It enables non-blind spoofing
of DNS responses.  Source address validation on your network doesn't
help because the spoofed response could be injected somewhere without

(Don't count on TLD operators notifying you when they become
customers.  Some of them happily buy mass-market products. 8-/)

