<?xml version='1.0' encoding='UTF-8'?>

<reference anchor='I-D.behringer-mpls-vpn-auth'>
<front>
<title>Layer-3 VPN Import/Export Verification</title>

<author initials='M' surname='Behringer' fullname='Michael Behringer'>
    <organization />
</author>

<author initials='J' surname='Guichard' fullname='Jim Guichard'>
    <organization />
</author>

<author initials='P' surname='Marques' fullname='Pedro Marques'>
    <organization />
</author>

<date month='June' day='4' year='2004' />

<abstract><t>Configuration errors on Provider Edge (PE) routers in Layer-3 VPN networks based on [RFC2547] can lead to security breaches of the connected VPNs. For example, the PE router could be mistakenly configured such that a connected Customer Edge (CE) router belongs to an incorrect VPN. Here we propose a scheme that verifies local and remote routing information received by the PE router before it installs new VPN routes into the Virtual Routing &amp; Forwarding Instance (VRF). The proposed changes affect only the PE routers.</t></abstract>

</front>

<seriesInfo name='Internet-Draft' value='draft-behringer-mpls-vpn-auth-04' />
<format type='TXT'
        target='http://www.ietf.org/internet-drafts/draft-behringer-mpls-vpn-auth-04.txt' />
</reference>

