Networking

Begineer Friendly

How Routers Forward Traffic Using MPLS Labels

How Routers Forward Traffic Using MPLS Labels

How Routers Forward Traffic Using MPLS Labels

How Routers Forward Traffic Using MPLS Labels

router
router

When data travels across a service provider network, routers need an efficient way to determine where packets should go next. Traditional IP routing uses destination addresses to make forwarding decisions. Multiprotocol Label Switching (MPLS) adds another approach by attaching short labels to packets and using those labels to guide traffic through the network.

Understanding how routers forward traffic using MPLS labels helps explain how service providers deliver Layer 3 virtual private networks (VPNs), support traffic engineering, and separate customer traffic across a shared infrastructure.

In simple terms, MPLS routers forward labeled packets by checking the top label against their forwarding tables and performing an action such as swapping or removing it. The process relies on forwarding information established by the control plane, while the data plane handles packet forwarding.

MPLS label forwarding in brief

An ingress router classifies a packet and pushes a label onto it. Each transit router looks up the top label in its Label Forwarding Information Base (LFIB), swaps it for an outgoing label, and sends the packet out the matching interface. The final label is removed at the penultimate hop or at the egress router, and the packet continues using normal IP or service-specific forwarding.

What MPLS labels are and how they differ from IP forwarding

An MPLS label is a 20-bit value in a 32-bit header inserted between the Layer 2 and Layer 3 headers. That header also carries a 3-bit traffic class field, a bottom-of-stack bit, and an 8-bit time-to-live (TTL). Labels can be stacked, and the result is the MPLS label stack. The top label drives forwarding, while deeper labels can identify services such as a Layer 3 VPN.

The main difference from IP is that a label is an exact-match index, not a prefix to search. Labels also have local significance. Label 100 on one router means nothing on the next, because each router picks the labels it advertises to its neighbors.

How routers forward traffic using MPLS labels

Two router roles matter here. A Label Edge Router (LER) sits at the boundary between the IP and MPLS domains. A Label Switched Router (LSR) forwards labeled packets inside the network.

Ingress router

The ingress LER receives an unlabeled packet and classifies it into a forwarding equivalence class (FEC), a group of packets that get the same forwarding treatment. Often that means all traffic for one destination prefix. The router then imposes one label or several and sends the packet toward the next hop.

Transit routers

Transit LSRs do not need the IP header. They read the top label, find the matching LFIB entry, and apply the programmed action and outgoing interface.

Egress router

With penultimate-hop popping (PHP), the router just before the egress removes the top label, so the egress handles the packet with a single lookup. If a service label remains, the egress uses it to select the right forwarding context, such as a VRF. Some designs use explicit null instead of PHP, so behavior depends on configuration.

Understanding MPLS Push, Swap, and Pop

Three core operations explain how MPLS labels change as packets travel through the network.

Operation

What the router does

Purpose

Push

Adds a label to the stack

Introduces traffic into an MPLS path or adds a service label

Swap

Replaces the top label

Directs the packet toward the next hop

Pop

Removes the top label

Supports label-stack processing and delivery toward the destination

Understanding MPLS Label Stacks in VPN Networks

MPLS can carry more than one label at a time. In a common Layer 3 VPN design, the packet uses an outer transport label and an inner VPN service label.

The transport label guides the packet across the provider core. The VPN label identifies the customer or forwarding context that should receive the packet at the egress provider edge router.

For example, a provider might use transport label 100 and VPN label 240 for a packet destined for a customer's headquarters network. Transit routers swap the outer label as required while leaving the inner VPN label unchanged. When the transport label is removed, the egress router uses the remaining VPN label to select the correct customer routing context.

These label values are illustrative, not universal. Actual label assignments and forwarding behavior depend on the implementation.

IP routing versus MPLS forwarding

Feature

IP routing

MPLS label forwarding

Lookup key

Destination IP address

Top label

Lookup type

Longest-prefix match

Exact match

Where classification happens

At every hop

Mainly at the ingress

Forwarding table

FIB

LFIB

Path control

Follows the IGP best path

Follows the LSP, which can be engineered

Service separation

Needs extra mechanisms

Label stacks support VPNs

A packet crossing an MPLS network

Take a packet from 10.1.1.10 to 192.168.50.20 crossing four routers, R1 to R4. The label values below are illustrative.

  1. R1 is the ingress LER. It matches the destination to a FEC and pushes label 1001.

  2. R2 is a transit LSR. Its LFIB says incoming label 1001 maps to outgoing label 2002 on its link toward R3, so it swaps the label.

  3. R3 is the penultimate hop. R4 advertised an implicit null label for this FEC, so R3 pops the label and sends a plain IP packet to R4.

  4. R4 is the egress router. It performs a normal IP lookup and delivers the packet.

At no point after R1 did a core router need to examine the destination address.

LFIB, Label Switched Paths, and label distribution

The control plane and data plane do separate jobs. The control plane builds the state. An IGP such as OSPF or IS-IS still computes reachability, and a label distribution mechanism assigns and advertises label bindings. The data plane then forwards packets using the LFIB entries that result.

A Label Switched Path (LSP) is the unidirectional path a labeled packet follows. The Label Distribution Protocol (LDP) is the most common way to build LSPs that follow IGP shortest paths (see our article on LDP explained). It is not the only way. RSVP-TE signals explicitly routed LSPs for MPLS traffic engineering, and Segment Routing carries path instructions as labels without per-flow signaling. Each fits different designs, so check what your own network uses.

Troubleshooting Common MPLS Forwarding Problems

When MPLS traffic fails to reach its destination, engineers should verify that the control plane and data plane agree.

Useful checks include confirming IP reachability between provider routers, verifying label bindings, examining LFIB entries, and checking whether the outgoing interface and label operation match the expected path. For VPN traffic, engineers should also verify that the correct service label and customer routing context exist at the egress router.

For example, if a packet reaches the egress router but enters the wrong customer forwarding context, checking the VPN label and associated forwarding entry can help narrow down the problem. The precise commands vary by router vendor and operating system.

Conclusion

MPLS forwarding comes down to classifying once, then swapping labels along an LSP until the final label is popped. Routing protocols still decide reachability, and the label state makes the forwarding fast and flexible. As a next step, trace a labeled path on a lab router by comparing the FIB with the LFIB, then read about MPLS VPNs and Segment Routing.

Frequently Asked Questions (FAQs)

What is the difference between an LER and an LSR?

A Label Edge Router handles traffic entering or leaving an MPLS domain. A Label Switching Router forwards labeled packets through the MPLS network using its label forwarding information.

Does MPLS replace IP routing?

No. IP routing remains important for establishing network reachability and supporting control-plane decisions. MPLS uses labels to forward packets across configured label-switched paths.

What is penultimate-hop popping?

It is when the second-to-last router removes the top label, so the egress router avoids a redundant label lookup before its IP or service lookup.

Do all MPLS networks use LDP?

No. Some use RSVP-TE for traffic-engineered LSPs, and many modern networks use Segment Routing. LDP is common but optional.

Why do MPLS labels have only local significance?

Each router assigns the labels it advertises, and its neighbors use them only for that link. This avoids global coordination and lets label values be reused across the network.

Don’t Miss Out – Limited Seats, Register Today!

Don’t Miss Out – Limited Seats, Register Today!

Insights That Accelerate Your Career

Insights That Accelerate Your Career