Presentation is loading. Please wait.

Presentation is loading. Please wait.

1 draft-behringer-mpls-vpn-auth-05.txt62nd IETF, Minneapolis, 7-11 Mar 2005 MPLS VPN Import/Export Verification draft-behringer-mpls-vpn-auth-05.txt Michael.

Similar presentations


Presentation on theme: "1 draft-behringer-mpls-vpn-auth-05.txt62nd IETF, Minneapolis, 7-11 Mar 2005 MPLS VPN Import/Export Verification draft-behringer-mpls-vpn-auth-05.txt Michael."— Presentation transcript:

1 1 draft-behringer-mpls-vpn-auth-05.txt62nd IETF, Minneapolis, 7-11 Mar 2005 MPLS VPN Import/Export Verification draft-behringer-mpls-vpn-auth-05.txt Michael Behringer Jim Guichard Pedro Roque Marques

2 2 draft-behringer-mpls-vpn-auth-05.txt62nd IETF, Minneapolis, 7-11 Mar 2005 This Draft Addresses: RFC 2547 BGP/MPLS VPN RT misconfiguration protection: –If the SP misconfigures the RT on a PE, security of the VPN is compromised

3 3 draft-behringer-mpls-vpn-auth-05.txt62nd IETF, Minneapolis, 7-11 Mar 2005 Current Status: Routing Authentication with MD5 CE PE CE VRF k1 k2 PE VRF k2k1 Routing MD5 auth No end-to-end MD5 authentication

4 4 draft-behringer-mpls-vpn-auth-05.txt62nd IETF, Minneapolis, 7-11 Mar 2005 Our idea: Link the MD5’s CE PE CE VRF k1 k2 PE VRF k2k1 Routing MD5 auth

5 5 draft-behringer-mpls-vpn-auth-05.txt62nd IETF, Minneapolis, 7-11 Mar 2005 Comparison to Bonica draft Our draftBonica draft Requires CE/site to participateNoYes Allows verification by siteNoYes Works with Route ReflectorsYes Requires routing PE-CEYesNo Requires new signalling PE-CENoYes xor

6 6 draft-behringer-mpls-vpn-auth-05.txt62nd IETF, Minneapolis, 7-11 Mar 2005 Questions Is this work useful? What is wrong / missing / … ? Does this work fit into the PPVPN WG? Goal: Accept as WG document


Download ppt "1 draft-behringer-mpls-vpn-auth-05.txt62nd IETF, Minneapolis, 7-11 Mar 2005 MPLS VPN Import/Export Verification draft-behringer-mpls-vpn-auth-05.txt Michael."

Similar presentations


Ads by Google