On 9 March 2018 at 16:35,  <[email protected]> wrote:

> Regarding point b)
> That one might be cumbersome as IP for CE-PE links in the Internet VRF are
> usually allocated from either your own public address space (so you'd have
> to fragment it and not advertising block used for PE-CE links -creating more
> state in GRT) or come from PI space which you don't have control over yet
> it's part of your infrastructure.

In one shop I did /31 or /30 links customer or our pool, but we never
advertised the connected networks. If far-end for some reason needed
routed linknetwork, after we tried to demotivate, we crated /32 static
route for it. So we still didn't have that address as attack surface
on the PE from outside the PE.


-- 
  ++ytti
_______________________________________________
juniper-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/juniper-nsp

Reply via email to