This document discusses security concerns regarding MPLS VPN configurations and proposes methods to check MPLS VPN configurations for errors and compliance. Key points that should be checked include VPN access points, VRF configurations, route distinguishers (RD), route targets (RT), routes, and administrative/service VPN configurations. A tool is proposed to collect configuration data from provider edge (PE) routers periodically and check for obvious errors, inconsistencies, and non-compliance between actual and allocated configurations across all VPNs in the network. Results would be provided to both network operators and VPN owners.