This feature allows the user to enforce security at an inter-AS boundary and to configure a router, acting in a PE role and, or in an ASBR role, to accept packets of VPRN prefixes only from direct EBGP neighbors to which it advertised a VPRN label.