Name: draft-behringer-mpls-vpn-auth-04
Title: Layer-3 VPN Import/Export Verification
State: Active
Authors: Michael Behringer, Jim Guichard, Pedro Marques
Group: Individual Submissions (none)
Date: 2004-06-04
Configuration errors on Provider Edge (PE) routers in Layer-3 VPN networks
based on [RFC 2547] can lead to security breaches of the connected VPNs. For
example, the PE router could be mistakenly configured such that a connected
Customer Edge (CE) router belongs to an incorrect VPN. Here we propose a
scheme that verifies local and remote routing information received by the
PE router before it installs new VPN routes into the Virtual Routing &
Forwarding Instance (VRF). The proposed changes affect only the PE routers.
|
|
|