Glossary

MPLS

Multiprotocol Label Switching

What is MPLS

MPLS (Multiprotocol Label Switching) is a backbone-network technology that brings connection-oriented label switching to what is otherwise a connectionless IP network. It combines Layer 3 routing with Layer 2 switching, so a network gets the flexibility IP routing is known for alongside the simplicity and speed of Layer 2 forwarding. Because traffic is forwarded based on short, fixed-length labels rather than a full routing-table lookup at every hop, MPLS also supports a wide range of higher-layer protocols and services, and helps protect the traffic it carries in the process.

How MPLS Works

At the core of MPLS is the label: a short identifier attached to a packet that tells each router along the path exactly which pre-established route to follow, without needing to re-evaluate the destination IP address hop by hop. A path built this way is a Label Switched Path (LSP) — the MPLS equivalent of a circuit, established either statically by an administrator or dynamically through a signaling protocol.

Labels can be assigned manually, which is how a static LSP is built: an administrator directly configures the inbound label a router should expect, and the outbound label (or action) it should apply before forwarding. Two special outbound actions matter here: implicit-null, which strips the label entirely before the packet reaches its final hop (a technique called penultimate hop popping), and explicit-null, which forwards the packet with a label value of 0 instead of removing it outright. Static LSPs work, but they don't scale — every router along every path needs manual, coordinated configuration.

For larger networks, MPLS pairs with LDP (Label Distribution Protocol), which lets routers dynamically discover neighbors and exchange label bindings automatically, removing the need to hand-configure every LSP hop by hop. LDP typically runs alongside an IGP like OSPF, which handles reachability, while LDP handles the label bindings that turn that reachability into an actual LSP.

On top of these label-switched paths, MPLS supports several VPN service models:

  • L3VPN: Provider edge (PE) routers maintain separate VRF instances per customer, exchanging customer routes over MP-BGP (Multiprotocol BGP) between PEs, while EBGP sessions connect each PE to its directly attached customer edge (CE) router. This lets multiple customers share the same physical backbone while keeping their routing completely separate — the same isolation concept VRF provides on a single device, extended across an entire provider network.

  • L2VPN VPLS (Virtual Private LAN Service): Multiple sites are stitched together into what looks, from the customer's perspective, like a single shared Layer 2 network. Each PE connects to customer-facing AC (Attachment Circuit) interfaces and to other PEs via pseudowires (PWs) — virtual point-to-point Layer 2 connections carried over the MPLS backbone — letting hosts across three or more sites communicate as if they were on the same LAN.

  • L2VPN VPWS (Virtual Private Wire Service): The point-to-point counterpart to VPLS — a single pseudowire directly connects two customer sites, emulating a dedicated Layer 2 circuit between exactly two endpoints rather than a shared multi-site LAN.

When an L3VPN needs to span more than one autonomous system — common when a service crosses provider or regional boundaries — two interconnection models are used. Option A keeps things simple: ASBRs (Autonomous System Boundary Routers) at the boundary treat each other essentially like CE routers, exchanging routes over ordinary EBGP sessions per VRF, with no MPLS label information crossing the AS boundary itself. Option B goes further: ASBRs exchange labeled VPN routes directly over MP-EBGP, preserving the VPN label end-to-end across the AS boundary and giving PEs on each side a full MP-IBGP relationship with their local ASBR — a more scalable design for providers handling many VPNs across multiple autonomous systems.

Why MPLS is Beneficial

  • Forwards on a simple label instead of a full route lookup: Label-based forwarding is faster and more predictable than routing every packet based on a full IP lookup at every hop, which is part of why MPLS became the backbone technology of choice for large provider networks.

  • Combines the best of Layer 2 and Layer 3: MPLS gets IP routing's flexibility for path selection alongside Layer 2 switching's simplicity for actual forwarding, rather than forcing a network to choose one approach exclusively.

  • True multi-tenant isolation at scale: L3VPN's per-customer VRF and route-target model lets a single backbone carry many customers' traffic with genuine routing separation, the same way VRF isolates tenants on one device — just extended across an entire provider network.

  • Layer 2 and Layer 3 services on the same infrastructure: VPLS, VPWS, and L3VPN all run over the same label-switched backbone, so a provider isn't forced to build and maintain separate physical infrastructure for Layer 2 versus Layer 3 services.

  • Scales across AS boundaries: Option A and Option B interconnection models mean L3VPN services aren't limited to a single autonomous system — a service can span multiple providers or regions using whichever interconnection model fits the operator's scale and trust boundary.

At Asteraix

What We Can Do at Asteraix

AsterNOS implements the full MPLS stack — static LSPs, LDP, L3VPN, and both major L2VPN service types — configurable entirely through the CLI, with documented end-to-end examples for every major deployment model.

  • Static LSP configuration with explicit label control: ip route <prefix> <next-hop> label <label> and mpls lsp <in-label> <next-hop> <out-label> let operators build a complete static LSP hop by hop, including implicit-null and explicit-null handling at the penultimate and final hops — demonstrated end-to-end in AsterNOS's documented PE-P-P-PE static LSP example.

  • Dynamic label distribution with LDP: mpls ldp → router-id → address-family ipv4 → discovery transport-address configures LDP neighbor discovery and label exchange, removing the need for manual per-hop label configuration in larger networks.

  • Full L3VPN with MP-BGP: VRF creation, OSPF and LDP in the underlay, and address-family ipv4 vpn on PE-to-PE MP-BGP sessions — combined with rd vpn export, rt vpn both, export vpn, and import vpn on the PE-to-CE EBGP session — implement complete multi-tenant L3VPN, all confirmed in a documented PE1-P-PE2 reference topology.

  • Both L2VPN service models: pseudowire <name> with neighbor lsr-id and pw-id builds the underlying pseudowire, and l2vpn <name> type vpls or l2vpn <name> type vpws then binds that pseudowire to an AC interface — AsterNOS's documentation includes a full three-PE VPLS example (multiple pseudowires meshing three sites) and a two-PE VPWS example (a single point-to-point pseudowire), covering both the multi-site and point-to-point L2VPN use cases.

  • Multi-AS L3VPN with both interconnection options: Option A is configured with ordinary per-VRF EBGP sessions between ASBRs, while Option B uses mpls bgp l3vpn-multi-domain-switching on ASBR-facing interfaces alongside MP-EBGP address-family VPN sessions with next-hop-self — both documented as complete, verified PE-ASBR-ASBR-PE topologies for operators building services across AS boundaries.

  • Verified against real connectivity tests: Every documented example ends with actual CE-to-CE (or PC-to-PC) reachability verification — not just protocol-session state — giving operators a concrete reference for confirming their own deployment works end-to-end, not just that the control plane came up.