Hi,

On Mon, Mar 11, 2013 at 10:18:31AM +0000, Gordon Bryan wrote:
> Can I ask what your thoughts are on core IP addressing? Do you have specified 
> global ranges for this purpose with matching  iACLs or do you use another 
> method altogether.

We use a dedicated IPv4 /24 for all core links which is heavily ACLed at 
all external borders.

What we're currently not so good at is "protect the PE-CE link" - the
customer infrastructure is so heterogeneous that we can't do "every PE-CE
link gets a /30 from a well-known /22 (or whatever) and that is also
strongly filtered" (as ytti suggested).

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             [email protected]
fax: +49-89-35655025                        [email protected]

Attachment: pgpfIYLCirhbY.pgp
Description: PGP signature

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to