On 9 March 2018 at 16:35, <[email protected]> wrote:
> Regarding point b) > That one might be cumbersome as IP for CE-PE links in the Internet VRF are > usually allocated from either your own public address space (so you'd have > to fragment it and not advertising block used for PE-CE links -creating more > state in GRT) or come from PI space which you don't have control over yet > it's part of your infrastructure. In one shop I did /31 or /30 links customer or our pool, but we never advertised the connected networks. If far-end for some reason needed routed linknetwork, after we tried to demotivate, we crated /32 static route for it. So we still didn't have that address as attack surface on the PE from outside the PE. -- ++ytti _______________________________________________ juniper-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/juniper-nsp

