Why allow… (deployment) Deployment considerations In some scenarios, final address assignment depends on the client ID (authentication) Pre-PANA address, post-PANA address Allocation of pre-PANA address IPv6: link-locals IPv4: rely on IPv4 link-locals, or Use (additional) local DHCP server Address management If IPsec-based access control is used: Pre-PANA address is used even after PANA auth as the IPsec tunnel end-point If IPsec is NOT used, pre-PANA IPv4 address must be disabled after post-PANA address is obtained (IPv6 LL is OK) |