skip to content

In an MPLS core, how does LDP build label-switched paths, and why do those paths follow the IGP's best route?

level: middleimportance: should knowfreq 20%

answer

  1. hello, then a TCP session
  2. one binding per prefix
  3. use the next hop's label
  4. no path computation of its own

basics

~20 s

LDP routers find neighbours with UDP hellos, open a TCP session on port 646 and advertise a label for each prefix they route; each router forwards with the label from its IGP next hop, so every LSP copies the IGP's path.

solid answer

~40 s

LDP (RFC 5036) discovers neighbours with Hello messages sent over UDP port 646 to the all-routers-on-this-subnet multicast group, then opens a session over TCP port 646, the router with the higher transport address connecting. Each router sends **Label Mapping** messages binding a label to a FEC, typically every PE's /32 loopback. In the usual **downstream unsolicited** mode it advertises to every peer; with **liberal retention** it keeps every mapping but forwards using only the one from its **IGP next hop**. LDP has no path selection of its own, so the LSP is the IGP's shortest path stitched together hop by hop. When the IGP reconverges, the router switches to the label it already holds from the new next hop. Steering traffic off that path needs RSVP-TE.

go deeper

for a junior

Recall that LDP hands out labels for routes the IGP already chose, using hellos to find neighbours and a TCP session to exchange label bindings.

for a middle

Explain discovery on UDP 646, the TCP 646 session, Label Mapping messages, and why each router forwards with the label from its IGP next hop.

for a senior

Diagnose LDP-specific failures: summarised PE loopbacks that break LSPs, a link carrying IGP traffic before LDP labels exist, and how liberal retention speeds recovery.

for a principal

Weigh LDP's simplicity, following the IGP for free, against its inability to engineer paths or pre-build protection, and decide where RSVP-TE is worth its state.

## What LDP is for A label switching router can only swap a label if its downstream neighbour has told it which label to use for a FEC. **LDP**, the Label Distribution Protocol (RFC 5036, which obsoletes RFC 3036), is the protocol that carries those bindings. It does not choose paths. It hands out labels for the routes the IGP (OSPF or IS-IS) has already chosen, and the result is a mesh of **label-switched paths (LSPs)** that mirror the routing table. In a provider network the FECs that matter are the PE routers' loopbacks. RFC 4364 has PEs that carry VPN routes insert /32 prefixes for themselves into the IGP, so that every router in the core can bind a label to each PE. ## Discovery and session setup 1. **Basic discovery.** Each LSR periodically sends LDP **Hello** messages as UDP packets to port 646 at the all-routers-on-this-subnet multicast group on every LDP-enabled interface. A router that is not directly attached is reached by **extended discovery**, with Hellos sent to a specific address. 2. **Transport connection.** The two routers compare transport addresses as unsigned integers; the higher one plays the active role and connects to TCP port 646 on the other. 3. **Initialization.** The session negotiates its parameters, including the label advertisement mode: if one side proposes downstream on demand and the other downstream unsolicited, the RFC's rules settle it. 4. **Addresses and labels.** Each router sends **Address** messages listing its interface addresses, which lets a neighbour match an IGP next-hop address to an LDP peer, then **Label Mapping** messages binding a label to each FEC. **Label Withdraw** removes a binding. ## The modes that shape the label table LDP keeps received bindings in a label information base and installs only some of them for forwarding. Three pairs of modes decide how: | Choice | Option A | Option B | |---|---|---| | Advertisement | **Downstream unsolicited**: send mappings to every peer unasked | **Downstream on demand**: send a mapping only when asked | | Retention | **Liberal**: keep every mapping from every peer | **Conservative**: keep only mappings from the next hop | | Control | **Independent**: advertise a FEC as soon as you route it | **Ordered**: advertise only after the next hop has, or when you are the egress | RFC 5036 notes that liberal retention's main advantage is fast reaction to routing changes, because labels already exist, and its cost is holding unneeded mappings. Most router cores pair downstream unsolicited advertisement with liberal retention; downstream on demand with conservative retention was typical of ATM-based LSRs. ## Why the LSP follows the IGP An LDP router never compares paths. For each FEC it asks the routing table for the next hop, finds the LDP peer that owns that address, and uses that peer's label as its outgoing label. Chain that rule across every router and the LSP is exactly the IGP's best path, hop by hop. Several consequences follow: - **Reconvergence is the IGP's.** When a link fails, the IGP picks a new next hop and, with liberal retention, the router already holds that neighbour's label, so the LSP repairs as fast as the IGP converges. - **Equal-cost paths carry over.** If the IGP installs two next hops, the router can hold two outgoing labels and split flows between them. - **Summarisation breaks LSPs.** If an area border summarises the PE loopbacks, routers beyond it see no /32 to bind a label to, and an end-to-end LSP to the PE no longer forms. - **Timing gaps blackhole traffic.** If the IGP brings a link into service before LDP has exchanged labels across it, the routing table points at a neighbour with no label yet, and labelled traffic for VPN routes is dropped. Implementations offer a feature that keeps the IGP from preferring a link until LDP is up on it. - **No engineering.** LDP cannot place an LSP on a longer but emptier path, reserve bandwidth or pre-build a backup path. Those jobs belong to RSVP-TE (RFC 3209), which signals explicitly routed LSPs. ## Where LDP sits in a provider design - **PE routers** run LDP toward their core neighbours and originate bindings for their own loopbacks. - **P routers** run LDP and the IGP only; they hold labels for PE loopbacks and no customer routes. - **CE routers** do not run LDP at all; they speak ordinary IP routing to their PE. That split is why a provider core with a few hundred PEs needs only a few hundred transport FECs, however many customer prefixes ride on top.

  • What does an LDP router do with labels it receives from a neighbour that is not its next hop?
    With liberal retention, RFC 5036 keeps them in the label base without using them for forwarding. If the IGP later makes that neighbour the next hop, the router switches to the stored label immediately instead of requesting one. With conservative retention it discards them and must obtain a new label after a routing change.
  • Why must PE loopbacks stay as /32 routes in the core IGP when LDP builds the transport LSPs?
    LDP binds labels to prefixes the routing table holds. If an area boundary summarises the loopbacks, routers beyond it hold only the aggregate and never bind a label for an individual PE's /32, so the LSP toward that PE breaks at the summarisation point and labelled VPN traffic cannot reach it.

saying these in an interview costs you the question

  • LDP computes its own shortest paths independently of the IGP.
  • LDP sessions run over UDP port 646 for their whole lifetime.
  • An LDP router uses whichever neighbour's label arrived first.
  • The upstream router picks the label it will send toward a neighbour.
  • LDP can reserve bandwidth along an LSP like RSVP-TE.
  • CE routers must run LDP with the PE to join an MPLS VPN.