Re: [PATCH v2 2/3] mpls: Per-device enabling of packet input

2015-04-22 Thread Eric W. Biederman
Robert Shearman writes: > An MPLS network is a single trust domain where the edges must be in > control of what labels make their way into the core. The simplest way > of ensuring this is for the edge device to always impose the labels, > and not allow forward labeled traffic from untrusted neigh

[PATCH v2 2/3] mpls: Per-device enabling of packet input

2015-04-22 Thread Robert Shearman
An MPLS network is a single trust domain where the edges must be in control of what labels make their way into the core. The simplest way of ensuring this is for the edge device to always impose the labels, and not allow forward labeled traffic from untrusted neighbours. This is achieved by allowin