Hello, We are in the process of deploying an MPLS network (carrier-provided) to connect several customers to a data center. The customer locations are all separate entities and need to be completely isolated from each other. The carrier is now telling us that they will only announce a full set of routes (either through BGP or statically) to all locations, and will not do any filtering or policy routing, or anything else in the core. So question is, how do I make sure the various customer locations stay segregated? I know the easy answer is to write ACLs on the CPE routers (which I am providing), but since they are not under my physical control, that makes me somewhat uneasy. Are there any better solutions?
Thanks, Michael Malitsky _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
