
192 Chapter 5: Security Recommendations
Securing Core and Routing Check List
The following provides a brief checklist of the recommendations detailed within this
overall chapter:
• Use static routing between PE and CE if possible.
• If dynamic routing is required between PE and CE, secure the peering using MD5:
— Use eBGP as the dynamic routing protocol if possible.
— Configure “maximum prefix” limits per VRF and per neighbor.
— Establish “dampening” parameters.
— If MD5 is not possible, use distance to mark all but the peering router as
unreliable.
— Only use EIGRP/OSPF/RIP as PE-CE routing protocol if static/eBGP
routing are not available and only if ...