RE: VPLS model for L2VPN Framework document

Ali Sajassi <[email protected]> Thu, 29 May 2003 14:43:15 -0700
Newsgroups gmane.ietf.ppvpn
Message-ID <[email protected]>
At 06:21 PM 5/29/2003 +0100, [email protected] wrote:
>Eric,
>
>The security concern I was thinking of is the possibility of a customer
>injecting untagged frames into the SP network via a trunk port. In an
>Ethernet switch all untagged frames arriving on a trunk port can either be
>dropped or forwarded on the native VLAN (where the forward or drop action is
>dependant on the implementation and configuration). If untagged customer
>frames are not dropped by default, then access lists would have to be used
>to ensure untagged customer frames were not forwarded on the untagged VPLS
>instance. This is probably an implementation issue rather than something
>that would need to be defined in the draft.

The control VPLS is only for SP use and there shouldn't be any leak of 
customers' frames into this VPLS. If there is, then there is an intentional 
config error.

-Ali


>Richard
>
>  > -----Original Message-----
>  > From: [email protected] [mailto:[email protected]]
>  > Sent: 29 May 2003 17:34
>  > To: [email protected]
>  > Cc: [email protected]
>  > Subject: RE: VPLS model for L2VPN Framework document
>  >
>  >
>  > Eric
>  >
>  > Is the sole purpose of the untagged VPLS instance to carry
>  > service provider
>  > BPDUs? If so there aren't any security concerns as all other
>  > untagged frames
>  > can simply be dropped. However, I think the general term
>  > "untagged packets"
>  > is misleading:
>  >
>  > - a further distinct  VPLS instance is used to  carry the
>  > "untagged packets"
>  >   of the emulated LAN.
>  >
>  > Perhaps replacing "untagged packets" with "Service provider
>  > BPDUs" would
>  > provide clarification on exactly what traffic can be carried
>  > using this VPLS
>  > instance?
>  >
>  > Richard
>  >
>  >  > -----Original Message-----
>  >  > From: Eric Rosen [mailto:[email protected]]
>  >  > Sent: 29 May 2003 15:29
>  >  > To: Spencer,R,Richard,XGH5 R
>  >  > Cc: [email protected]
>  >  > Subject: Re: VPLS model for L2VPN Framework document
>  >  >
>  >  >
>  >  >
>  >  > Richard> Is the  intention here  to create 1  VPLS control
>  >  > instance  (i) per
>  >  > Richard> customer
>  >  >
>  >  > No.
>  >  >
>  >  > Richard>  or (ii) per service provider network?
>  >  >
>  >  > Not necessarily limited to one per service provider network.
>  >  >
>  >  > However, this would be a deployment consideration, I think.
>  >  >
>  >  > Richard> what  traffic  will be  carried  over  the  control
>  >  > VPLS?  Untagged
>  >  > Richard> customer  frames or  untagged service  provider
>  >  > frames,  either way
>  >  > Richard> this sounds like it may lead to security concerns.
>  >  >
>  >  > I  think "untagged  service provider  frames" is  the
>  >  > answer.   What  is the
>  >  > security concern?
>  >  >
>  >
>  >
>  >