08-11-2003 11:31 PM
Hi, I was wandering if there is a way between two routers that 'speak' MPLS to introduce a firewall (i.e. pix firewall). I know by default is not possible but perhaps through tunneling etc?
Ragards.
Solved! Go to Solution.
08-12-2003 05:55 AM
Hi,
No, it is not possible at least for today. The packets between P and PE router are not IP packet but MPLS packets (it protocol type is different). One exception to that is penultimate hop poping. If P-H-P is placed and there is no other label stack (ex : no vpn ) the packet is pure IP packet.
Also one of the main idea of MPLS is that P router doesn't know anything except label binding information.
If you want to use firewall somewhere , use it on the CE side not between P-PE,P-P or PE-PE.
Best Regards
08-12-2003 05:55 AM
Hi,
No, it is not possible at least for today. The packets between P and PE router are not IP packet but MPLS packets (it protocol type is different). One exception to that is penultimate hop poping. If P-H-P is placed and there is no other label stack (ex : no vpn ) the packet is pure IP packet.
Also one of the main idea of MPLS is that P router doesn't know anything except label binding information.
If you want to use firewall somewhere , use it on the CE side not between P-PE,P-P or PE-PE.
Best Regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide