<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic MPLS Security Design in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/mpls-security-design/m-p/2647651#M196702</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I am trying to get a better idea of how to improve security between my MPLS sites.&lt;/P&gt;&lt;P&gt;I currently have 10 MPLS sites sharing a 100 Mb backbone, each location is connected physically&lt;/P&gt;&lt;P&gt;using a L3 Switch provided by the Telco. I simply plug that L3 switch into my L3 Switch and distribute my networks using OSPF.&lt;/P&gt;&lt;P&gt;Should I add an ASA between L3 switches to improve security ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:34:07 GMT</pubDate>
    <dc:creator>Alex Li</dc:creator>
    <dc:date>2019-03-12T05:34:07Z</dc:date>
    <item>
      <title>MPLS Security Design</title>
      <link>https://community.cisco.com/t5/network-security/mpls-security-design/m-p/2647651#M196702</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I am trying to get a better idea of how to improve security between my MPLS sites.&lt;/P&gt;&lt;P&gt;I currently have 10 MPLS sites sharing a 100 Mb backbone, each location is connected physically&lt;/P&gt;&lt;P&gt;using a L3 Switch provided by the Telco. I simply plug that L3 switch into my L3 Switch and distribute my networks using OSPF.&lt;/P&gt;&lt;P&gt;Should I add an ASA between L3 switches to improve security ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:34:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mpls-security-design/m-p/2647651#M196702</guid>
      <dc:creator>Alex Li</dc:creator>
      <dc:date>2019-03-12T05:34:07Z</dc:date>
    </item>
    <item>
      <title>ColinIt depends on your</title>
      <link>https://community.cisco.com/t5/network-security/mpls-security-design/m-p/2647652#M196703</link>
      <description>&lt;P&gt;Colin&lt;/P&gt;&lt;P&gt;It depends on your security requirements.&lt;/P&gt;&lt;P&gt;MPLS is a private network so many companies do not firewall their connections to it because it is only their internal users who have access to the network.&lt;/P&gt;&lt;P&gt;Obviously that doesn't necessarily mean you don't need firewalling for critical internal servers but that is a separate issue from the MPLS side of things.&lt;/P&gt;&lt;P&gt;If you don't trust your SP then you should probably be thinking about a new SP rather than firewalling.&lt;/P&gt;&lt;P&gt;Some companies do encrypt traffic over their MPLS connections but again this is to address specific security concerns which many other companies don't have.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2015 21:36:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mpls-security-design/m-p/2647652#M196703</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-02-26T21:36:34Z</dc:date>
    </item>
    <item>
      <title>Hi, Colin Tennyson.</title>
      <link>https://community.cisco.com/t5/network-security/mpls-security-design/m-p/2647653#M196704</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Hi, Colin Tennyson.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;&amp;nbsp;Definitely agree with Jon. However,adding a security appliance would secure your connection in your network.&amp;nbsp;This is advisable as connecting through&amp;nbsp;different sites, im sure that security would pose an issue.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Happy to Serve!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;&lt;SPAN style="font-size:14px;"&gt;Barry&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2015 17:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mpls-security-design/m-p/2647653#M196704</guid>
      <dc:creator>bsiapco</dc:creator>
      <dc:date>2015-02-27T17:06:00Z</dc:date>
    </item>
    <item>
      <title>BarryDefinitely agree with</title>
      <link>https://community.cisco.com/t5/network-security/mpls-security-design/m-p/2647654#M196705</link>
      <description>&lt;P&gt;Barry&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Definitely agree with Jon&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;This is advisable as connecting through&amp;nbsp;different sites, im sure that security would pose an issue&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;The second statement pretty much contradicts the first.&lt;/P&gt;&lt;P&gt;Can you expand on what you mean by your second statement ?&lt;/P&gt;&lt;P&gt;What are the issues you are referring to ?&lt;/P&gt;&lt;P&gt;If every company firewalled it's private WAN connections then yes it would definitely mean a lot more firewalls were sold but it's not something most companies do in my experience so what is your reasoning for recommending it ?&lt;/P&gt;&lt;P&gt;Just curious really as it's not something I have come across before.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Sat, 28 Feb 2015 13:41:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mpls-security-design/m-p/2647654#M196705</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-02-28T13:41:08Z</dc:date>
    </item>
  </channel>
</rss>

