@techreport{bi-intarea-savi-wlan-04, number = {draft-bi-intarea-savi-wlan-04}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-bi-intarea-savi-wlan/04/}, author = {Mingwei Xu and Jianping Wu and Tao Lin and Lin He and You Wang}, title = {{A SAVI Solution for WLAN}}, pagetotal = 19, year = 2024, month = nov, day = 25, abstract = {This document describes a source address validation solution for WLANs where 802.11i or other security mechanisms are enabled to secure MAC addresses. This mechanism snoops NDP and DHCP packets to bind IP addresses to MAC addresses, and relies on the security of MAC addresses guaranteed by 802.11i or other mechanisms to filter IP spoofing packets. It can work in the special situations described in the charter of SAVI (Source Address Validation Improvements) workgroup, such as multiple MAC addresses on one interface. This document describes three different deployment scenarios, with solutions for migration of binding entries when hosts move from one access point to another.}, }