摘要:
A method of dynamically enabling MPLS stations and ports using an ARP database is disclosed. The method of dynamically enabling MPLS stations and ports using an ARP database includes augmenting an ARP database with labels distributed via Label Distribution Protocol. The augmented ARP database includes for each ARP entry a list of labels that were advertised to an immediate neighbour. Subsequent use of the ARP database allows for automatic enabling/disabling of MPLS stations and allows labels to be used only on the appropriate ports as advertised to immediate neighbours. The method of dynamically enabling MPLS stations and ports using an ARP database is particularly useful for restricting ports and labels for security purposes, and to automatically provide configuration updates in a timely manner.
摘要:
A method of linking inner and outer MPLS labels to provide enhanced security is disclosed. The method of linking inner and outer MPLS labels to provide enhanced security includes provisioning both an outer label database with reference keys. The outer label database entry provides a key that must be used in conjunction with the inner label database lookup to realize appropriate actions. As the provided key is not publically accessible an additional increment of security is provided. The method of linking inner and outer MPLS labels to provide enhance security is particularly useful blocking malicious packets from being sent into a remote VLAN or VFI.