
MPLS over IP Operational Considerations: L2TPv3 189
IPsec PE-PE
The applicability of IPsec between PEs is when the core may not be pure MPLS, but rather
IP based. The principle behind the use of IPsec between PEs is to protect against
misbehaving transit nodes.
However, with PE-PE IPsec, snooping on the link is possible. Recall that your weakest link
is between the PE and CE.
The best practice is to implement CE-CE IPsec when required, or consider an alternative
technology implementation such as MPLS over L2TPv3, which we will discuss in the next
section.
Table 5-3 compares security aspects between IPsec CE-CE and IPsec PE-PE.
MPLS over IP Operational ...