
72 Chapter 3: MPLS Security Analysis
In CsC Layer 2, as in the Inter-AS architecture, security is paramount for any critical
interface. Therefore, we repeat this warning:
NOTE Never connect PEs and CEs over a shared Layer 2 infrastructure such as an Internet
Exchange Point (IXP). Use a private connection, or at least a private VLAN.
The Carrier’s Carrier architecture provides a secure way to operate multilevel VPNs,
assuming correct implementation and operation. It is the backbone carrier that assigns and
polices policy for the customer carrier, as the customer carrier does for its customers. On
both levels the “customer” has no way to break ...