There are two security considerations inherited from the MPLS
architecture which may be pointed out here:
- Some routers may implement security procedures which depend on
the network layer header being in a fixed place relative to the
data link layer header. These procedures will not work when
the MPLS encapsulation is used, because that encapsulation is
of a variable size.
- An MPLS label has its meaning by virtue of an agreement between
the LSR that puts the label in the label stack (the "label
writer"), and the LSR that interprets that label (the "label
reader"). However, the label stack does not provide any means
of determining who the label writer was for any particular
label. If labeled packets are accepted from untrusted sources,
the result may be that packets are routed in an illegitimate
manner.
8. Intellectual Property
The IETF has been notified of intellectual property rights claimed in
regard to some or all of the specification contained in this