
188 Chapter 5: Security Recommendations
against Spanning Tree, and DoS storms (for which a hacking tool exists). An example of a
solution includes, for 1 and 2, port security.
Few service providers do this normally, so this attack is not difficult; and to disable
Spanning Tree on the router port, hard code Root Bridge is a factor here.
For labeled packets on a VLAN, the data plane attributes are that any label combination can
be sent, by any station in the VLAN, and for Carriers Carrier, the top label (LSP) is checked
by the PE.
NOTE For both CsC and Inter-AS deployments, implement only on private peerings due to
vulnerabilities highlighted abov ...