
96 Chapter 4: Secure MPLS VPN Designs
This way, either of the Internet provisioning models can be made secure; the difference lies
in the number of security mechanisms that protect the core. Architectural security is in
every case stronger because it cannot be misconfigured.
As you can see from Table 4-1, Internet in a VRF provides the highest security level of all
Internet options. However, there are a number of other design considerations to be taken
into account, such as memory consumption. Routes in VRF require significantly more
memory than in the global table. Therefore, decisions on design options cannot be taken
solely based on security ...