RE: VPLS model for L2VPN Framework document
Ali Sajassi <[email protected]> Thu, 29 May 2003 14:38:16 -0700
| Newsgroups | gmane.ietf.ppvpn |
|---|---|
| Message-ID | <[email protected]> |
At 05:33 PM 5/29/2003 +0100, [email protected] wrote: >Eric > >Is the sole purpose of the untagged VPLS instance to carry service provider >BPDUs? Basically yes. >If so there aren't any security concerns as all other untagged frames >can simply be dropped. However, I think the general term "untagged packets" >is misleading: > >- a further distinct VPLS instance is used to carry the "untagged packets" > of the emulated LAN. > >Perhaps replacing "untagged packets" with "Service provider BPDUs" would >provide clarification on exactly what traffic can be carried using this VPLS >instance? Or we can say "SP untagged packets - e.g., BPDUs". -Ali >Richard > > > -----Original Message----- > > From: Eric Rosen [mailto:[email protected]] > > Sent: 29 May 2003 15:29 > > To: Spencer,R,Richard,XGH5 R > > Cc: [email protected] > > Subject: Re: VPLS model for L2VPN Framework document > > > > > > > > Richard> Is the intention here to create 1 VPLS control > > instance (i) per > > Richard> customer > > > > No. > > > > Richard> or (ii) per service provider network? > > > > Not necessarily limited to one per service provider network. > > > > However, this would be a deployment consideration, I think. > > > > Richard> what traffic will be carried over the control > > VPLS? Untagged > > Richard> customer frames or untagged service provider > > frames, either way > > Richard> this sounds like it may lead to security concerns. > > > > I think "untagged service provider frames" is the > > answer. What is the > > security concern? > >