[c-nsp] Hiding MPLS L3VPN hops from the CE

Justin Shore justin at justinshore.com
Tue Aug 24 15:38:03 EDT 2010


On 8/22/2010 6:31 AM, Peter Hicks wrote:
> Just out of interest - is this for marketing reasons, or technical?

At my ISP it was for security reasons.  Our infrastructure was privately 
addressed to limit exposure to the outside world.  In theory, a true 
MPLS P core is analogous to a pure L2 switching core.  There's no reason 
for anyone to ever know that those hops even exist.  In addition, it 
also helps prevent a confused user from thinking something silly when 
they see a RFC1918 address in their traceroute.  Oh the stories I could 
tell like the time a guy thought IANA had hijacked our network because 
"their IPs" appeared in the middle of our network.  Classic...


More information about the cisco-nsp mailing list