Feature Explorer AI AI

×

Subscribe now to get the Latest Updates

Watch a 2-minute overview video

Protection against label spoofing or errant label injection across ASBRs

More Information:

Protection against label spoofing or errant label injection across ASBRs

You can use regular BGP implicit and explicit export policies to restrict VPN ASBR peer route advertisement to a given routing instance. This is especially useful in the context of Inter-AS VPN Option-B ASBRs because it prevents a peer ASBR in a neighboring AS from spoofing or unintentionally injecting a VPN label intended for a different peer AS or intra-AS into the protected AS. In other words, service providers can configure a common ASBR so it does not accept MPLS packets from a peer ASBR unless the label has been explicitly advertised to the common ASBR. Two new commands are introduced to provide this protection: mpls-forwarding at the [edit routing-instances name instance-type mpls-forwarding] hierarchy level and forwarding-context at the [edit protocols bgp group group-name neighbor address], hierarchy level.
Product / Application Software Introduced Release
MX5 Junos OS 15.1F2
MX10 Junos OS 15.1F2
MX40 Junos OS 15.1F2
MX80 Junos OS 15.1F2
MX104 Junos OS 15.1F2
MX204 Junos OS 17.4R1
MX240 Junos OS 16.1R4
MX240 Junos OS 15.1F2
MX301 Junos OS 25.4R1
MX304 Junos OS 22.2R3
MX480 Junos OS 16.1R4
MX480 Junos OS 15.1F2
MX960 Junos OS 16.1R4
MX960 Junos OS 15.1F2
MX2008 Junos OS 15.1F7
MX2010 Junos OS 16.1R4
MX2010 Junos OS 15.1F2
MX2020 Junos OS 16.1R4
MX2020 Junos OS 15.1F2
MX10003 Junos OS 17.3R1
MX10004 Junos OS 22.3R1
MX10008 Junos OS 18.2R1
MX10016 Junos OS 19.2R1