[c-nsp] Private IP in SP Core
Gert Doering
gert at greenie.muc.de
Mon Mar 11 06:43:34 EDT 2013
Hi,
On Mon, Mar 11, 2013 at 10:18:31AM +0000, Gordon Bryan wrote:
> Can I ask what your thoughts are on core IP addressing? Do you have specified global ranges for this purpose with matching iACLs or do you use another method altogether.
We use a dedicated IPv4 /24 for all core links which is heavily ACLed at
all external borders.
What we're currently not so good at is "protect the PE-CE link" - the
customer infrastructure is so heterogeneous that we can't do "every PE-CE
link gets a /30 from a well-known /22 (or whatever) and that is also
strongly filtered" (as ytti suggested).
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany gert at greenie.muc.de
fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 305 bytes
Desc: not available
URL: <https://puck.nether.net/pipermail/cisco-nsp/attachments/20130311/fe438253/attachment.sig>
More information about the cisco-nsp
mailing list