Adam Vitkovsky <[email protected]> writes:

> How plausible is that customer will replace your device with theirs without
> you noticing it + they crack all the passwords so they can run ISIS, LDP and
> BGP sessions with you. 

They don't need to do that. Just put a switch between the CE and the
upstream. Then inject MPLS packets from a different port on the switch.

Maybe one day we will get either strict MPLS label checks or L2
encryption and authentication. At that point the only attacks are to the
CE itself. I am not holding my breath.


/Benny

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to