@techreport{behringer-mpls-vpn-auth-04, number = {draft-behringer-mpls-vpn-auth-04}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-behringer-mpls-vpn-auth/04/}, author = {Michael H. Behringer and Jim Guichard and Pedro R. Marques}, title = {{Layer-3 VPN Import/Export Verification}}, pagetotal = 9, year = 2004, month = jun, day = 4, abstract = {Configuration errors on Provider Edge (PE) routers in Layer-3 VPN networks based on {[}RFC2547{]} can lead to security breaches of the connected VPNs. For example, the PE router could be mistakenly configured such that a connected Customer Edge (CE) router belongs to an incorrect VPN. Here we propose a scheme that verifies local and remote routing information received by the PE router before it installs new VPN routes into the Virtual Routing \& Forwarding Instance (VRF). The proposed changes affect only the PE routers.}, }