Skip to Content
MPLS VPN Security
book

MPLS VPN Security

by Michael H. Behringer, Monique J. Morrow
June 2005
Intermediate to advanced
312 pages
11h 13m
English
Cisco Press
Content preview from MPLS VPN Security
MPLS over IP Operational Considerations: L2TPv3 189
IPsec PE-PE
The applicability of IPsec between PEs is when the core may not be pure MPLS, but rather
IP based. The principle behind the use of IPsec between PEs is to protect against
misbehaving transit nodes.
However, with PE-PE IPsec, snooping on the link is possible. Recall that your weakest link
is between the PE and CE.
The best practice is to implement CE-CE IPsec when required, or consider an alternative
technology implementation such as MPLS over L2TPv3, which we will discuss in the next
section.
Table 5-3 compares security aspects between IPsec CE-CE and IPsec PE-PE.
MPLS over IP Operational ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Router Security Strategies: Securing IP Network Traffic Planes

Router Security Strategies: Securing IP Network Traffic Planes

Gregg Schudel - CCIE No. 9591, David J. Smith - CCIE No. 1986
MPLS and VPN Architectures, Volume II

MPLS and VPN Architectures, Volume II

Jim Guichard, Ivan Pepelnjak, Jeff Apcar
Selecting MPLS VPN Services

Selecting MPLS VPN Services

Chris Lewis, Steve Pickavance, Monique Morrow, John Monaghan, Craig Huegen

Publisher Resources

ISBN: 1587051834Purchase book