MPLS: Technology and Applications

Security is clearly an important component for any credible VPN solution. In the area of security, the goal of the BGP/MPLS VPN approach is to achieve security comparable to that provided today by Frame Relay or ATM-based VPNs. Specifically, the goal is to make sure that, in the absence of either deliberate interconnection or misconfiguration, packets from one VPN wouldn t be able to get into another VPN.
To see how we accomplish this goal, first observe that forwarding within a VPN service provider is based on label switching, not on traditional IP forwarding. Therefore, forwarding within the provider is not determined by the IP addresses carried in the packets. Moreover, observe that LSPs associated with VPN-IP routes originate and terminate only at the PE routers they don t terminate in the middle of a service provider network, and they don t start in the middle of a service provider network. At a PE router, these LSPs are associated with particular forwarding tables, and the forwarding tables are associated (at provisioning time) with interfaces on the PE router. Finally, observe that these interfaces are associated at provisioning time with particular VPNs.
Therefore, when a PE router sends a packet to a CE router that belongs to a particular VPN, this packet has to arrive at the PE router either from another (directly connected) CE router or from some other PE router. In order for this to happen in the former case, both of the CE routers have to be within the same...