Hi, On Mon, Mar 11, 2013 at 10:18:31AM +0000, Gordon Bryan wrote: > Can I ask what your thoughts are on core IP addressing? Do you have specified > global ranges for this purpose with matching iACLs or do you use another > method altogether.
We use a dedicated IPv4 /24 for all core links which is heavily ACLed at
all external borders.
What we're currently not so good at is "protect the PE-CE link" - the
customer infrastructure is so heterogeneous that we can't do "every PE-CE
link gets a /30 from a well-known /22 (or whatever) and that is also
strongly filtered" (as ytti suggested).
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany [email protected]
fax: +49-89-35655025 [email protected]
pgpfIYLCirhbY.pgp
Description: PGP signature
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
