+ Mobile Network Prefix +
| |
+ +
| |
+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+
Type
6
Length
Eight-bit unsigned integer indicating the length in octets of
the option, excluding the type and length fields. Set to 18.
Reserved
This field is unused for now. The value MUST be initialized to
0 by the sender and MUST be ignored by the receiver.
Prefix Length
Eight-bit unsigned integer indicating the prefix length of the
IPv6 prefix contained in the option.
Mobile Network Prefix
A sixteen-byte field containing the Mobile Network Prefix
5. Mobile Router Operation
Mobile Router operation is derived largely from the combined
behaviors of a host, of a router [5], and of a Mobile Node [1].
A Mobile Node can act in two ways: (1) as a Mobile Host, in which
case the Home Agent doesn’t maintain any prefix information related
to the Mobile Host’s Home Address but does maintain a binding cache
entry related to the Mobile Host’s Home Address, and (2) as a Mobile
Router, in which case, in addition to maintaining the binding cache
entry corresponding to the Mobile Router Home Address, the Home Agent
maintains forwarding information related to prefixes assigned to the
Mobile Network. The distinction between the two modes is represented
by the value of the Mobile Router Flag (R).
A Mobile Router MUST implement all requirements for IPv6 Mobile Nodes
as described in section 8.5 of [1].
5.1. Data Structures
Like a Mobile Host, a Mobile Router also maintains a Binding Update
List, described in section 11.1 of the Mobile IPv6 specification [1].
The Binding Update list is a conceptual data structure that records
information sent in the Binding Updates. There is one entry per each
destination to which the Mobile Router is currently sending Binding
Updates.
This document introduces a new Prefix Information field in the
Binding Update list structure. This field is used to store any
prefix information that the Mobile Router includes in the Binding
Update. If the Mobile Router sets the Mobile Router Flag (R) in the
Binding Update but does not include any prefix information in it this
field is set to null. The Mobile Router does not include prefix
information in the Binding Update in the implicit mode or when it,
runs a dynamic routing protocol with its Home Agent.
As does a Mobile Host, a Mobile Router stores the information
regarding status of flags of the Binding Update in the corresponding
Binding Update List entry. This document introduces a new Mobile
Router Flag (R) for this entry. The status of this flag is stored in
the Binding Update list whenever a Binding Update is sent.
A Mobile Router also maintains a Home Agent list populated according
to the same procedure as a Mobile Host.
5.2. Sending Binding Updates
A Mobile Router sends Binding Updates to its Home Agent, as described
in [1]. If the Mobile Router is not running a routing protocol as
described in section 8, it uses one of the following modes to tell
the Home Agent to determine which prefixes belong to the Mobile
Router. In both modes, the Mobile Router sets the Mobile Router Flag
(R).
Implicit:
In this mode, the Mobile Router does not include a Mobile
Network Prefix Option in the Binding Update. The Home Agent
can use any mechanism (not defined in this document) to
determine the Mobile Network Prefix(es) owned by the Mobile
Router and to set up forwarding for the Mobile Network. One
example would be manual configuration at the Home Agent mapping
the Mobile Router’s Home Address to the information required
for setting up forwarding for the Mobile Network.
Explicit:
In this mode, the Mobile Router includes one or more Mobile
Network Prefix Options in the Binding Update. These options
contain information about the Mobile Network Prefix(es)
configured on the Mobile Network.
A Mobile Router MUST implement at least one mode and MAY implement
both. In the latter case, local configuration on the Mobile Router
decides which mode to use. This is out of scope for this document.
If the Mobile Router Flag is set, the Home Registration Flag (H) MUST
be set.
If the Mobile Router has a valid binding cache entry at the Home
Agent, subsequent Binding Updates for the same Home Address should
have the same value as the value in the binding cache for the Mobile
Router Flag (R). In explicit mode, the Mobile Router MUST include
prefix information in all Binding Updates, including those sent to
refresh existing binding cache entries, if it wants forwarding
enabled for the corresponding Mobile Network Prefixes.
5.3. Receiving Binding Acknowledgements
The Mobile Router receives Binding Acknowledgements from the Home
Agent corresponding to the Binding Updates it sent. If the Binding
Acknowledgement status is set to 0 (Binding Update accepted) and the
Mobile Router Flag (R) is set to 1, the Mobile Router assumes that
the Home Agent has successfully processed the Binding Update and has
set up forwarding for the Mobile Network. The Mobile Router can then
start using the bi-directional tunnel to reverse-tunnel traffic from
the Mobile Network. If the Mobile Router Flag (R) is not set, then
the Mobile Router concludes that its current Home Agent does not
support Mobile Routers and it performs Dynamic Home Agent Address
Discovery again to discover Home Agents that do. The Mobile Router
MUST also de-register with the Home Agent that did not support it
before attempting registration with another.
5.4. Error Processing
If the Binding Acknowledgement status is set to a value between 128
and 139, the Mobile Router takes necessary actions as described in
the Mobile IPv6 specification [1]. For the Binding Acknowledgement
status values defined in this document, the following sections
explain the Mobile Router’s behavior.
5.4.1. Implicit Mode
In Implicit mode, the Mobile Router interprets only error statuses
140 (Mobile Router Operation not permitted) and 143 (Forwarding Setup
failed). The Mobile Router MUST treat Binding Acknowledgements with
statuses ’141’ and ’142’ as fatal errors, since they should not be
sent by the Home Agent in implicit mode.
If the Binding Acknowledgement from the Home Agent has the status
140, the Mobile Router SHOULD send a Binding Update to another Home
Agent on the same home link. If no Home Agent replies positively,
the Mobile Router MUST refrain from sending Binding Updates with the
Mobile Router Flag set to any Home Agent on the home link, and it
must log the information.
If the Binding Acknowledgement has the status 143, the Mobile Router
SHOULD send a Binding Update to another Home Agent on the same home
link. If no Home Agent replies positively, the Mobile Router SHOULD
refrain from sending this Binding Update to any Home Agent on the
home link, and MAY send Binding Updates in Explicit mode to a Home
Agent on the same home link.
5.4.2. Explicit Mode
If the Mobile Router sent a Binding Update to the Home Agent in
explicit mode, then the Mobile Router interprets only error statuses
140 (Mobile Router Operation not permitted), 141 (Invalid Prefix),
and 142 (Not Authorized for Prefix). The Mobile Router MUST treat
Binding Acknowledgements with status ’143’ as a fatal error, since it
should not be sent by the Home Agent in explicit mode.
If the Binding Acknowledgement from the Home Agent has the status
140, the Mobile Router SHOULD send a Binding Update to another Home
Agent on the same home link. If no Home Agent replies positively,
then the Mobile Router MUST refrain from sending Binding Updates with
the Mobile Router Flag set to any Home Agent on the home link, and it
must log the information.
If the Binding Acknowledgement has the status 141 or 142, the Mobile
Router SHOULD send a Binding Update to another Home Agent on the same
home link. If no Home Agent replies positively, then the Mobile
Router SHOULD refrain from sending Binding Updates to any Home Agent
on the home link. The Mobile Router MUST also stop advertising the
prefix in the Mobile Network and try to obtain new IPv6 prefix
information for the Mobile Network. It would do this by the same
means that it initially got assigned the current Mobile Network
Prefix. Alternatively, the Mobile Router MAY send Binding Updates in
Implicit mode to a Home Agent on the same home link.
If by the end of this Error Processing procedure, as described in
sections 5.4.1 and 5.4.2, the Mobile Router has tried every available
mode and still has not received a positive Binding Acknowledgement,
the Mobile Router MUST stop sending Binding Updates with the Mobile
Router Flag set for this Home Address and it must log the
information.
In all cases above, the Mobile Router MUST conclude that the Home
Agent did not create a binding cache entry for the Mobile Router’s
Home Address.
5.5. Establishment of Bi-directional Tunnel
When a successful Binding Acknowledgement is received, the Mobile
Router sets up its endpoint of the bi-directional tunnel.
The bi-directional tunnel between the Mobile Router and the Home
Agent allows packets to flow in both directions, while the Mobile
Router is connected to a visited link. The bi-directional tunnel is
created by merging two unidirectional tunnels, as described in RFC
2473 [3]. The tunnel from the Mobile Router to the Home Agent has
the Care-of address of the Mobile Router as the tunnel entry point
and the Home Agent’s address as the tunnel exit point. The tunnel
from the Home Agent to the Mobile Router has the Home Agent’s address
and the Mobile Router’s Care-of Address as the tunnel entry point and
exit point, respectively. All IPv6 traffic to and from the Mobile
Network is sent through this bi-directional tunnel.
A Mobile Router uses the Tunnel Hop Limit normally assigned to
routers (not to hosts). Please refer to [3] for more details.
5.6. Neighbor Discovery for Mobile Router
When the Mobile Router is at home, it MAY be configured to send
Router Advertisements and to reply to Router Solicitations on the
interface attached to the home link. The value of the Router
Lifetime field SHOULD be set to 0 to prevent other nodes from
configuring the Mobile Router as the default router.
A Mobile Router SHOULD NOT send unsolicited Router Advertisements and
SHOULD NOT reply to Router Solicitations on any egress interface when
that interface is attached to a visited link. However, the Mobile
Router SHOULD reply with Neighbor Advertisements to Neighbor
Solicitations received on the egress interface, for addresses valid
on the visited link.
A router typically ignores Router Advertisements sent by other
routers on a link. However, a Mobile Router MUST NOT ignore Router
Advertisements received on the egress interface. The received Router
Advertisements MAY be used for address configuration, default router
selection, or movement detection.
5.7. Multicast Groups for Mobile Router
When at home, the Mobile Router joins the multicast group All Routers
Address with scopes 1 interface-local (on the home-advertising
interface), and 2 link-local, on any of its egress interfaces. When
in a visited network, the Mobile Router MUST NOT join the above
multicast groups on the corresponding interface.
5.8. Returning Home
When the Mobile Router detects that it has returned to its home link,
it MUST de-register with its Home Agent. The Mobile Router MUST
implement and follow the returning-home procedures defined for a
mobile node in [1]. In addition, the Mobile Router MAY start
behaving as a router on its egress interface, especially as follows:
- The Mobile Router MAY send Router Advertisements on its egress
interfaces, but the router lifetime SHOULD be set to 0 so that
hosts on the home link do not pick the Mobile Router as the
default router.
- The Mobile Router MAY join the All Routers Address multicast group
on the home link.
- The Mobile Router MAY send routing protocol messages on its egress
interface if it is configured to run a dynamic routing protocol.
When the Mobile Router sends a de-registration Binding Update in
Explicit mode, it SHOULD NOT include any Mobile Network Prefix
options in the Binding Update. When the Home Agent removes a binding
cache entry, it deletes all associated Mobile Network Prefix routes.
6. Home Agent Operation
For a Mobile Router to operate correctly, the Home Agent MUST satisfy
all the requirements listed in section 8.4 of [1]. The Home Agent
MUST implement both modes described in section 5.2 of this document.
6.1. Data Structures
6.1.1. Binding Cache
The Home Agent maintains Binding Cache Entries for each Mobile Router
currently registered with the Home Agent. The Binding Cache is a
conceptual data structure described in detail in [1].
The Home Agent might need to store the Mobile Network Prefixes
associated with a Mobile Router in the corresponding Binding Cache
Entry. This is required if the Binding Update that created the
Binding Cache Entry contained explicit prefix information. This
information can be used later to clean up routes installed in
explicit mode, when the Binding Cache Entry is removed, and to
maintain the routing table, for instance, should the routes be
removed manually.
The Home Agent also stores the status of the Mobile Router Flag (R)
in the Binding Cache entry.
6.1.2. Prefix Table
The Home Agent SHOULD be able to prevent a Mobile Router from
claiming Mobile Network Prefixes belonging to another Mobile Router.
The Home Agent can prevent such attacks if it maintains a Prefix
Table and verifies the prefix information provided by the Mobile
Router against Prefix Table entries. The Prefix Table SHOULD be used
by the Home Agent when it processes a Binding Update in explicit
mode. It is not required when a dynamic routing protocol is run
between the Mobile Router and the Home Agent.
Each entry in the Prefix Table contains the following fields:
- The Home Address of the Mobile Router. This field is used as the
key for searching the pre-configured Prefix Table.
- The Mobile Network Prefix of the Mobile Router associated with the
Home Address.
6.2. Mobile Network Prefix Registration
The Home Agent processes the Binding Update as described in section
10.3.1 of the Mobile IPv6 specification [1]. This section describes
the processing of the Binding Update if the Mobile Router (R) Flag is
set. The Home Agent performs the following check.
- The Home Registration (H) Flag MUST be set. If it is not, the
Home Agent MUST reject the Binding Update and send a Binding
Acknowledgement with status set to 140. Note: The basic support
does not allow sending a Binding Update for a Mobile Network
Prefix to correspondent nodes (for route optimization).
- Mobile IPv6 specification [1] requires that the Home Address in
the Binding Update be configured from a prefix advertised on the
home link. Otherwise the Binding Update is rejected with status
value 132 [1]. This specification relaxes this requirement so
that the Home Agent rejects the Binding Update only if the Home
Address does not belong to the prefix that the Home Agent is
configured to serve.
If the Home Agent has a valid binding cache entry for the Mobile
Router, and if the Binding Update has the Mobile Router Flag (R) set
to a value different from that in the existing binding cache entry,
then the Home Agent MUST reject the Binding Update and send a Binding
Acknowledgement with status set to 139 (Registration type change
disallowed). However, if the Binding Update is a de-registration
Binding Update, the Home Agent ignores the value of the Mobile Router
Flag (R).
If the Lifetime specified in the Binding Update is 0 or the specified
Care-of address matches the Home Address in the Binding Update, then
this is a request to delete the cached binding for the home address
and specified Mobile Network Prefixes. The Binding Update is
processed as described in section 6.7.
If the Home Agent does not reject the Binding Update as invalid, and
if a dynamic routing protocol is not run between the Home Agent and
the Mobile Router as described in section 8, then the Home Agent
retrieves the Mobile Network Prefix information as described below.
- If a Mobile Network Prefix Option is present in the Binding
Update, the prefix information for the Mobile Network Prefix is
retrieved from the Mobile Network Prefix field and the Prefix
Length field of the option. If the Binding Update contains more
than one option, the Home Agent MUST set up forwarding for all the
Mobile Network Prefixes. If the Home Agent fails to set up
forwarding to all the prefixes listed in the Binding Update, then
it MUST NOT forward traffic to any of the prefixes. Furthermore,
it MUST reject the Binding Update and send a Binding
Acknowledgement with status set to 141 (Invalid Prefix).
If the Home Agent verifies the prefix information with the Prefix
Table and the check fails, the Home Agent MUST discard the Binding
Update and send a Binding Acknowledgement with status set to 142
(Not Authorized for Prefix).
- If there is no option in the Binding Update carrying prefix
information, the Home Agent uses manual pre-configured information
to determine the prefixes assigned to the Mobile Router and to set
up forwarding for the Mobile Network. If there is no information
that the Home Agent can use, it MUST reject the Binding Update and
send a Binding Acknowledgement with status set to 143 (Forwarding
Setup failed).
If the Home Agent has a valid binding cache entry for the Mobile
Router, it should compare the list of prefixes in the Binding Update
against the prefixes stored in the binding cache entry. If the
binding cache entry contains prefixes that do not appear in the
Binding Update, the Home Agent MUST disable forwarding for these
Mobile Network Prefixes.
If all checks are passed, the Home Agent creates a binding cache
entry for Mobile Router’s Home Address or updates the entry if it
already exists. Otherwise, the Home Agent MUST NOT register the
binding of the Mobile Router’s Home Address.
The Home Agent defends the Mobile Router’s Home Address through Proxy
Neighbor Discovery by multicasting a Neighbor Advertisement message
onto the home link on behalf of the Mobile Router. All fields in the
Proxy Neighbor Advertisement message should be set the same way they
would be by the Mobile Router if it sent this Neighbor Advertisement
while at home, as described in [6]. There is an exception: If the
Mobile Router (R) Flag has been set in the Binding Update, the Router
(R) bit in the Advertisement MUST be set.
The Home Agent also creates a bi-directional tunnel to the Mobile
Router for the requested Mobile Network Prefix or updates an existing
bi-directional tunnel as described in section 6.4.
6.3. Advertising Mobile Network Reachability
To receive packets meant for the Mobile Network, the Home Agent
advertises reachability to the Mobile Network. If the Home Link is
configured with an aggregated prefix and the Mobile Network Prefix is
aggregated under that prefix, then the routing changes related to the
Mobile Network may be restricted to the Home Link. If the Home Agent
is the only default router on the Home Link, routes to the Mobile
Network Prefix are aggregated naturally under the Home Agent, which
does not have to do anything special.
If the Home Agent receives routing updates through a dynamic routing
protocol from the Mobile Router, it can be configured to propagate
those routes on the relevant interfaces.
6.4. Establishment of Bi-directional Tunnel
The implementation of the bi-directional tunnels and the mechanism
for attaching them to the IP stack are outside the scope of this
specification. However, all implementations MUST be capable of the
following operations:
- The Home Agent can tunnel packets meant for the Mobile Network
prefix to the Mobile Router’s current location, the Care-of
Address.
- The Home Agent can accept packets tunneled by the Mobile Router
with the source address of the outer IPv6 header set to the Mobile
Router’s Care-of Address.
6.5. Forwarding Packets
When the Home Agent receives a data packet destined for the Mobile
Network, it MUST forward the packet to the Mobile Router through the
bi-directional tunnel. The Home Agent uses either the routing table,
the Binding Cache, or a combination to route packets to the Mobile
Network. This is implementation specific. Two examples are shown
below.
1. The Home Agent maintains a route to the Mobile Network Prefix with
the next hop set to the Mobile Router’s Home Address. When the
Home Agent tries to forward the packet to the next hop, it finds a
binding cache entry for the home address. Then the Home Agent
extracts the Mobile Router’s Care-of address and tunnels the
packet to the Care-of address.
2. The Home Agent maintains a route to the Mobile Network Prefix with
the outgoing interface set to the bi-directional tunnel interface
between the Home Agent and the Mobile Router. For this purpose,
the Home Agent MUST treat this tunnel as a tunnel interface. When
the packets are forwarded through the tunnel interface, they are
encapsulated automatically, with the source address and
destination address in the outer IPv6 header set to the Home
Agent’s address and the Mobile Router’s Care-of address,
respectively.
6.6. Sending Binding Acknowledgements
A Home Agent serving a Mobile Router sends Binding Acknowledgements
with the same rules it uses for sending Binding Acknowledgements to
Mobile Hosts [1], with the following enhancements.
The Home Agent sets the status code in the Binding Acknowledgement to
0 (Binding Update accepted) to indicate to the Mobile Router that it
successfully processed the Binding Update. It also sets the Mobile
Router Flag (R) to indicate to the Mobile Router that it has set up
forwarding for the Mobile Network.
If the Home Agent is not configured to support Mobile Routers, it
sets the status code in the Binding Acknowledgement to 140 (Mobile
Router Operation not permitted).
If one or more prefixes received in the Binding Update are invalid
and the Home Agent cannot set up forwarding for the prefixes, the
Home Agent sets the status code in the Binding Acknowledgement to 141
(Invalid Prefix) to indicate this to the Mobile Router.
If the Mobile Router is not authorized to use this Home Address to
forward packets for one or more prefixes present in the Binding
Update, the Home Agent sets the status code in the Binding