skip to content

MPLS and L3VPN

Routers forward on labels instead of IP lookups, and providers build isolated customer L3VPNs from VRFs, route distinguishers and MP-BGP. Interviewers ask when it still beats internet transport.

on this pageshow

questions

5

In MPLS, how does a label switching router forward a packet by pushing, swapping and popping labels instead of doing an IP lookup?

level: middleimportance: must knowfreq 32%

answer

  1. classify once at the edge
  2. four-byte entry, twenty-bit value
  3. exact match on the top label
  4. second-to-last router pops

basics

~20 s

The ingress router classifies a packet once and pushes a label; each transit router swaps the top label using an exact-match table, and the last or second-to-last router pops it, so the core never re-reads the IP header.

solid answer

~40 s

MPLS (RFC 3031) makes the routing decision once, at the edge. The ingress router maps a packet to a **forwarding equivalence class** (typically "leaves the core at egress router X") and **pushes** a 4-byte label stack entry: a 20-bit label, a 3-bit Traffic Class field (EXP until RFC 5462), the bottom-of-stack bit and an 8-bit TTL (RFC 3032). Each transit LSR looks up only the **top** label in its incoming label map and **swaps** it for the value its downstream neighbour advertised, so a label means something on one link only. At the end the label is **popped**: with penultimate hop popping, the egress advertised the Implicit NULL label (3), so the second-to-last router pops and the egress does a single lookup. The chain of swaps is a one-way **label-switched path**.

go deeper

for a junior

Recall the three operations and where each happens: the ingress pushes a label, transit routers swap it, and the end of the path pops it.

for a middle

Explain the four fields of the label stack entry, why labels are downstream-assigned with link-local meaning, and how penultimate hop popping saves the egress a second lookup.

for a senior

Show the operational edges: Implicit versus Explicit NULL and what happens to Traffic Class on the last hop, TTL behaviour in the uniform and pipe models, and one-way LSPs.

for a principal

Argue why MPLS survives after its speed argument faded: label stacking lets a core carry traffic it cannot route itself, which is the foundation of VPNs and explicit paths.

## Why routers forward on labels **MPLS** (Multiprotocol Label Switching, RFC 3031) splits forwarding into two jobs. At the edge, the **ingress** router decides once which **forwarding equivalence class (FEC)** a packet belongs to. In a provider core that is usually "packets that leave the core at the same egress router", identified by that router's /32 loopback address. Every router after that forwards on a short, fixed-length **label** that it matches exactly, without re-reading the IP header. Labels are **downstream-assigned**: the router a packet is going *to* chooses the value for a FEC and tells its upstream neighbour. A label therefore has meaning only on one hop between two routers; the same number can mean a different FEC elsewhere. The original pitch was speed, because an exact match is simpler than longest-prefix match. Modern hardware does longest-prefix match at line rate, so the argument that still holds is different: a core router can carry a packet whose inner header it cannot or should not route. That covers a customer's overlapping private prefixes, IPv6 across an IPv4-only core, or a packet pinned to an explicit path. Labels **stack**, and stacking is what VPNs and traffic engineering are built from. ## The label stack entry RFC 3032 defines the encoding: 4 bytes per entry, after the link-layer header (an Ethernet frame announces it with ethertype `0x8847`) and before the network-layer header. | Field | Bits | Meaning | |---|---|---| | Label | 20 | the value looked up; 0-15 are reserved | | Traffic Class (TC) | 3 | QoS marking; named EXP until RFC 5462 renamed it | | S (bottom of stack) | 1 | 1 on the last entry, 0 on every other entry | | TTL | 8 | hop count, decremented by every label switching router | Twenty bits give 1,048,576 values. The stack has no "next protocol" field, so the router that pops the last label must infer what lies underneath from the label value itself. ## Push, swap and pop along a path The sequence of routers a FEC's packets follow is a **label-switched path (LSP)**. It is one-directional: replies ride a separate LSP toward the other edge. A trace through a provider core, where the FEC is PE2's loopback `198.51.100.2/32`: 1. **PE1, the ingress, pushes.** The destination is reached via PE2, so PE1 pushes label `24001`, the value P1 advertised for `198.51.100.2/32`. 2. **P1 swaps.** It finds `24001` in its incoming label map: "send to P2 with label `24017`". It rewrites the label, decrements the TTL and forwards. No IP lookup happens. 3. **P2 pops.** PE2 advertised the Implicit NULL label for its own loopback, so P2's entry says "pop and send to PE2". 4. **PE2, the egress,** receives an unlabelled IP packet and does one IP lookup. Each step is the result of one lookup on the **top** label. A router never inspects deeper entries unless a pop exposes them, and the S bit tells it whether one does. ## Penultimate hop popping and the reserved labels Without **penultimate hop popping (PHP)** the egress would look up the label, learn that it is the egress, pop, and then do a second lookup on whatever remains. RFC 3031 section 3.16 lets the second-to-last router pop instead, so every router on the path does a single lookup. RFC 3032 reserves the low label values: - **0, IPv4 Explicit NULL**: legal only at the bottom of the stack; the receiver pops it and forwards on the IPv4 header. - **1, Router Alert**: legal anywhere except the bottom; hands the packet to local software. - **2, IPv6 Explicit NULL**: as 0, for an IPv6 header. - **3, Implicit NULL**: distributed by label distribution but never sent on the wire; an upstream router that would swap to it pops instead. - **4-15**: reserved. An egress that advertises Explicit NULL rather than Implicit NULL still receives a labelled packet. Operators choose that when the last hop must still see the Traffic Class bits, at the cost of one extra pop at the egress. ## TTL and the edges of the model RFC 3032 section 2.4 says the ingress copies the IP TTL into the label TTL, each LSR decrements the top entry, and a packet whose outgoing TTL reaches 0 is not forwarded. When the last label is popped, the IP TTL SHOULD be set to the label's outgoing TTL, so a loop inside the core still ends. RFC 3443 describes two ways to present this to the outside: the **uniform** model, where every LSR counts as a hop, and the **pipe** model, where the core behaves like one hop and its routers vanish from a traceroute. Three points interviewers probe: - A label is local to one link; it is not an end-to-end address. - LSPs are unidirectional, so a reply needs its own LSP. - A transit router forwards on the top label alone, which is why it needs no routes for whatever the label carries.

  • Why would an egress router advertise Explicit NULL instead of Implicit NULL for its own loopback?
    With Implicit NULL (label 3) the penultimate router pops, so the packet crosses the last link unlabelled and its MPLS Traffic Class marking is gone. Advertising Explicit NULL (0 for IPv4, 2 for IPv6) keeps one label on the last hop, so the egress can still classify on the Traffic Class bits; it then pops that label and forwards on the IP header.
  • How does an MPLS router handle the TTL, and why can a traceroute miss the core routers?
    RFC 3032 copies the IP TTL into the label at ingress, decrements the top label TTL at each LSR, drops the packet when it reaches 0, and writes the result back into the IP header at the final pop. RFC 3443's pipe model instead treats the core as one hop, so traceroute sees the edges but none of the core routers.

A parcel depot writes a bin number on each parcel once; every later depot reads only that bin number and replaces it with the next depot's bin number, never re-reading the street address.

saying these in an interview costs you the question

  • Every MPLS router still does a full IP lookup and then reads the label.
  • A label identifies the destination end to end, like an address.
  • The egress router always pops the last label itself.
  • Label 3 travels on the wire to mean pop here.
  • One LSP carries traffic in both directions between two edge routers.
  • MPLS is used today mainly because label lookups are faster than IP lookups.
open as a page

A provider's MPLS L3VPN carries two customers that both use 10.0.0.0/8; how do VRFs, route distinguishers and route targets keep their routes and traffic apart?

level: seniorimportance: must knowfreq 26%

basics

~20 s

Each PE holds a VRF per customer; a route distinguisher turns each customer's 10.0.0.0/8 into a distinct VPN-IPv4 route for MP-BGP, route targets decide which remote VRFs import it, and an inner VPN label selects the VRF at the egress PE.

open as a page

In an MPLS core, how does LDP build label-switched paths, and why do those paths follow the IGP's best route?

level: middleimportance: should knowfreq 20%

basics

~20 s

LDP routers find neighbours with UDP hellos, open a TCP session on port 646 and advertise a label for each prefix they route; each router forwards with the label from its IGP next hop, so every LSP copies the IGP's path.

open as a page

When does a provider's MPLS L3VPN still beat encrypted tunnels over internet links for an enterprise connecting forty branches?

level: principalimportance: should knowfreq 18%

basics

~20 s

MPLS L3VPN wins where predictability is the requirement: one provider engineers the whole path, honours traffic classes under a contract and gives any-to-any reachability; internet tunnels win on price, speed of delivery, provider diversity and direct cloud access.

open as a page

In an MPLS core, how does RSVP-TE fast reroute keep traffic flowing within tens of milliseconds when a protected link fails?

level: seniorimportance: nice to knowfreq 11%

basics

~20 s

RSVP-TE fast reroute pre-signals a backup path around each protected link or node; when the failure is detected, the adjacent router redirects traffic onto that backup immediately, with no path computation or signalling, while the head-end later re-optimises.

open as a page