There is disclosed an apparatus and method for limiting tunnel traffic in
a network. Traffic engineering tunnels are used to direct traffic along a
predefined path, which may differ from the path that internet protocol
(IP) routing would determine. Interior gateway protocol (IGP) cut through
will allow the forwarding of all destinations downstream of a tunnel
through the tunnel, without the operator needing to specify a forwarding
equivalence class (FEC). But congestion in the tunnel and network
instability may result from this approach. A solution to these problems
is disclosed which limits the traffic in the tunnel to only that with
destination addresses of the tunnel's egress router or nodes directly
supported thereby. Other solutions are disclosed which allow tunnel
traffic to nodes having destination addresses other than those being
directly supported by the tunnel's egress router. All of these solutions
are achieved in both pre-determined forwarding entry and dynamic
packet-by packet embodiments.