MPLS VPN Forwarding with Two Labels
Inside the provider core, an MPLS VPN packet carries two labels. The outer one, the transport label, carries the packet to the egress PE. The inner one, the VPN label, tells the egress PE which VRF to hand the packet to and where to send it. Section 5 of RFC 4364 calls them the tunnel label and the VPN route label.
The ingress PE first turns the IP packet it received from the CE into an MPLS packet carrying the VPN label alone.
The IP packet is turned into an MPLS packet with the VPN route label as the sole label on the label stack.
It then pushes a transport label on top to carry the packet to the BGP next hop, which is the egress PE. A P router in the core only ever looks at the outer label; the inner VPN label is read by the egress PE only.
MPLS will then carry the packet across the backbone to the BGP Next Hop, where the VPN label will be examined.
| Segment | Labels |
|---|---|
| CE-A1 to PE1 | None (a plain IP packet) |
| PE1 to P1 | Two (transport plus VPN) |
| P1 to P2 | Two (only the outer value changes) |
| P2 to PE2 | One (PHP has removed the outer label) |
| PE2 to CE-A2 | None (a plain IP packet) |
What Each Device Does
| Device | Action |
|---|---|
| Ingress PE | Pushes the VPN label, then the transport label on top of it |
| Transit P | Swaps the outer label only. It never looks at the inner one |
| P one hop before the egress | Pops the outer label (PHP) |
| Egress PE | Uses the remaining VPN label to pick the VRF and the exit, pops it and hands plain IP to the CE |
Because the P routers never look at the inner label, overlapping customer addresses are not a problem for the core. A P router holds nothing but IGP routes and labels (see What Is MPLS VPN).
Both labels use the same 32-bit format, and the S bit (bottom of stack) says which one is the last (see MPLS Labels and the Label Stack). Push, swap, pop and PHP themselves are covered in MPLS Label Operations.
Section 5 of RFC 4364 describes what the last P router sends when PHP is in use.
if penultimate hop popping is used, the packet is then sent to the IGP Next Hop, carrying only the VPN route label
The Transport Label Does Not Have to Come from LDP
Section 5 of RFC 4364 requires LDP support for interoperability, but allows the label switched paths to be built in other ways.
To ensure interoperability among different implementations, it is required to support LDP for setting up the label switched paths across the backbone. However, other methods of setting up these label switched paths are also possible.
It also says that a traffic engineering tunnel to the BGP next hop is chosen when one is available, and that the tunnel’s label becomes the tunnel label.
If there are any traffic engineering tunnels to the BGP next hop, and if one or more of those is available for use by the packet in question, one of these tunnels is chosen. This tunnel will be associated with an MPLS label, the “tunnel label”.
| How the outer label is built | How labels are distributed | The label value |
|---|---|---|
| LDP | Per IGP route, to the neighbors | Local to each device, so it changes on every segment |
| RSVP-TE | Along the path of the tunnel | Same as above |
| SR-MPLS | The IGP distributes it as a prefix SID | Start of the SRGB plus an index, the same value domain-wide, so it does not change from segment to segment |
Whichever one is used, nothing on the VPN side changes — the VRF, the RD, the RT, MP-BGP and the VPN label are all the same. The outer label exists only to carry the packet to the egress PE and says nothing about what the inner label means.
Lab Setup
Six XRd routers in a row, with two P routers. With a single P router the P would sit next to the egress PE, PHP would remove the outer label there, and the swap of the outer label would never be visible.
| Node | Role |
|---|---|
| PE1 / PE2 | vrf CUST-A (RD 65001:1, RT 65001:100), with redistribute connected and redistribute static |
| P1 / P2 | Core only (OSPF area 0) |
| CE-A1 / CE-A2 | Customer A site 1 / 2, with LANs 10.1.1.0/24 and 10.1.2.0/24 |
LDP, RSVP-TE and SR-MPLS are all three configured in the core from the start, and each STEP changes only the single line that decides which one the PEs use. Nothing on the VPN side is touched in any STEP.
Each device uses its own label range so that a label value names the device that allocated it: 41000s for PE1, 42000s for PE2, 31000s for P1 and 32000s for P2. SR prefix SIDs start at 16000.
| STEP | Outer transport | Change | What it shows |
|---|---|---|---|
| 0 | LDP | None (initial state) | The labels on each segment, the outer swap, PHP, and no labels on PE-CE |
| 1 | RSVP-TE | autoroute announce on tunnel-te1 of the PEs | The outer label becomes an RSVP-TE label; the inner one stays the same |
| 2 | SR-MPLS | Remove autoroute announce, add segment-routing sr-prefer to OSPF | The outer label becomes a prefix SID; the inner one stays the same |
| 3 | Back to LDP (final state) | Remove segment-routing sr-prefer | The values return to those of STEP 0 |
All observations use traffic from CE-A1 to the LAN behind CE-A2 (10.1.2.1).
STEP 0: LDP as the Transport
A traceroute from CE-A1 shows the labels segment by segment.
RP/0/RP0/CPU0:CE-A1#traceroute 10.1.2.1 source 10.1.1.1 timeout 1 probe 2 maxttl 8
Sun Oct 4 05:02:35.175 UTC
Type escape sequence to abort.
Tracing the route to 10.1.2.1
1 172.16.1.1 8 msec 6 msec
2 10.0.13.3 [MPLS: Labels 31005/42007 Exp 0] 23 msec 20 msec
3 10.0.34.4 [MPLS: Labels 32005/42007 Exp 0] 69 msec 21 msec
4 10.0.24.2 [MPLS: Label 42007 Exp 0] 21 msec 18 msec
5 172.16.2.2 25 msec * Hops 2 and 3 carry two labels, and only the outer one changes from 31005 to 32005 while the inner one stays 42007. Hop 4 carries a single label (PHP). Hop 5 is CE-A2, with no label at all. The labels appear in the traceroute because MPLS carries a TTL of its own (see MPLS TTL and MTU).
What the ingress PE1 pushes is in the VRF forwarding table.
RP/0/RP0/CPU0:PE1#show cef vrf CUST-A 10.1.2.0/24 detail
Sun Oct 4 05:03:22.449 UTC
10.1.2.0/24, version 6, internal 0x5000001 0x30 (ptr 0x88519cd0) [1], 0x0 (0x0), 0x208 (0x899b2458)
Updated Oct 4 05:01:02.071
Prefix Len 24, traffic index 0, precedence n/a, priority 3
gateway array (0x89597950) reference count 2, flags 0x2038, source rib (7), 0 backups
[1 type 1 flags 0x48441 (0x899eb880) ext 0x0 (0x0)]
LW-LDI[type=0, refc=0, ptr=0x0, sh-ldi=0x0]
gateway array update type-time 1 Oct 4 05:01:02.070
LDI Update time Oct 4 05:01:02.070
via 2.2.2.2/32, 3 dependencies, recursive [flags 0x6000]
path-idx 0 NHID 0x0 [0x8856e948 0x0]
recursion-via-/32
next hop VRF - 'default', table - 0xe0000000
next hop 2.2.2.2/32 via 41005/0/21
next hop 10.0.13.3/32 GigabitEthernet0/0/0/1 labels imposed {31005 42007}
Load distribution: 0 (refcount 1)
Hash OK Interface Address
0 Y recursive 41005/0 labels imposed {31005 42007} is the pair, outer first.
P1 replaces the outer label only.
RP/0/RP0/CPU0:P1#show mpls forwarding
Sun Oct 4 05:04:25.313 UTC
Local Outgoing Prefix Outgoing Next Hop Bytes
Label Label or ID Interface Switched
------ ----------- ------------------ ------------ --------------- ------------
16001 Pop SR Pfx (idx 1) Gi0/0/0/0 10.0.13.1 0
16002 16002 SR Pfx (idx 2) Gi0/0/0/1 10.0.34.4 0
16004 Pop SR Pfx (idx 4) Gi0/0/0/1 10.0.34.4 0
31000 Pop SR Adj (idx 0) Gi0/0/0/0 10.0.13.1 0
31001 Pop SR Adj (idx 0) Gi0/0/0/1 10.0.34.4 0
31002 Pop 1.1.1.1/32 Gi0/0/0/0 10.0.13.1 8973
31003 Pop 4.4.4.4/32 Gi0/0/0/1 10.0.34.4 1074
31004 Pop 10.0.24.0/24 Gi0/0/0/1 10.0.34.4 0
31005 32005 2.2.2.2/32 Gi0/0/0/1 10.0.34.4 8063
31006 32006 TE: 1 Gi0/0/0/1 10.0.34.4 0
31007 Pop TE: 1 Gi0/0/0/0 10.0.13.1 0 The entry for 2.2.2.2/32, the egress PE2, is the LDP entry that swaps 31005 for 32005. The same table also holds a TE: 1 entry (RSVP-TE) and an SR Pfx (idx 2) entry (SR-MPLS). All three are configured, so all three sets of labels are distributed, and what changes in each STEP is only which one PE1 uses.
P2 sits one hop before the egress PE2, so it removes the outer label.
RP/0/RP0/CPU0:P2#show mpls forwarding
Sun Oct 4 05:04:53.078 UTC
Local Outgoing Prefix Outgoing Next Hop Bytes
Label Label or ID Interface Switched
------ ----------- ------------------ ------------ --------------- ------------
16001 16001 SR Pfx (idx 1) Gi0/0/0/0 10.0.34.3 0
16002 Pop SR Pfx (idx 2) Gi0/0/0/1 10.0.24.2 0
16003 Pop SR Pfx (idx 3) Gi0/0/0/0 10.0.34.3 0
32000 Pop SR Adj (idx 0) Gi0/0/0/0 10.0.34.3 0
32001 Pop SR Adj (idx 0) Gi0/0/0/1 10.0.24.2 0
32002 31002 1.1.1.1/32 Gi0/0/0/0 10.0.34.3 8176
32003 Pop 3.3.3.3/32 Gi0/0/0/0 10.0.34.3 1277
32004 Pop 10.0.13.0/24 Gi0/0/0/0 10.0.34.3 0
32005 Pop 2.2.2.2/32 Gi0/0/0/1 10.0.24.2 8687
32006 Pop TE: 1 Gi0/0/0/1 10.0.24.2 0
32007 31007 TE: 1 Gi0/0/0/0 10.0.34.3 0 The outgoing label is Pop. That is PHP.
The egress PE2 uses the remaining VPN label to pick the VRF and the exit.
RP/0/RP0/CPU0:PE2#show mpls forwarding
Sun Oct 4 05:03:49.196 UTC
Local Outgoing Prefix Outgoing Next Hop Bytes
Label Label or ID Interface Switched
------ ----------- ------------------ ------------ --------------- ------------
16001 16001 SR Pfx (idx 1) Gi0/0/0/1 10.0.24.4 0
16003 16003 SR Pfx (idx 3) Gi0/0/0/1 10.0.24.4 0
16004 Pop SR Pfx (idx 4) Gi0/0/0/1 10.0.24.4 0
42000 Pop SR Adj (idx 0) Gi0/0/0/1 10.0.24.4 0
42001 32002 1.1.1.1/32 Gi0/0/0/1 10.0.24.4 7261
42002 32003 3.3.3.3/32 Gi0/0/0/1 10.0.24.4 520
42003 Pop 4.4.4.4/32 Gi0/0/0/1 10.0.24.4 715
42004 32004 10.0.13.0/24 Gi0/0/0/1 10.0.24.4 0
42005 Pop 10.0.34.0/24 Gi0/0/0/1 10.0.24.4 0
42006 32007 TE: 1 Gi0/0/0/1 10.0.24.4 0
42007 Unlabelled 10.1.2.0/24[V] Gi0/0/0/0 172.16.2.2 6400
42008 Aggregate CUST-A: Per-VRF Aggr[V] \
CUST-A 0 The Prefix or ID column of the 42007 entry reads 10.1.2.0/24[V], where [V] marks a VRF route. The outgoing label is Unlabelled, so the label is removed here and plain IP goes to CE-A2. PE2 picked that value itself and advertised it through MP-BGP; how many labels it allocates is covered in MPLS VPN label allocation.
The packets themselves show the same thing. Between PE1 and P1 there are two labels, the outer with S=0 and the inner with S=1.
MultiProtocol Label Switching Header, Label: 31005, Exp: 0, S: 0, TTL: 254
0000 0111 1001 0001 1101 .... .... .... = MPLS Label: 31005 (0x0791d)
.... .... .... .... .... 000. .... .... = MPLS Experimental Bits: 0
.... .... .... .... .... ...0 .... .... = MPLS Bottom Of Label Stack: 0
.... .... .... .... .... .... 1111 1110 = MPLS TTL: 254
MultiProtocol Label Switching Header, Label: 42007, Exp: 0, S: 1, TTL: 254
0000 1010 0100 0001 0111 .... .... .... = MPLS Label: 42007 (0x0a417)
.... .... .... .... .... 000. .... .... = MPLS Experimental Bits: 0
.... .... .... .... .... ...1 .... .... = MPLS Bottom Of Label Stack: 1
.... .... .... .... .... .... 1111 1110 = MPLS TTL: 254
Internet Protocol Version 4, Src: 10.1.1.1, Dst: 10.1.2.1Between P2 and PE2 a single label is left, and its S bit is 1.
MultiProtocol Label Switching Header, Label: 42007, Exp: 0, S: 1, TTL: 252
0000 1010 0100 0001 0111 .... .... .... = MPLS Label: 42007 (0x0a417)
.... .... .... .... .... 000. .... .... = MPLS Experimental Bits: 0
.... .... .... .... .... ...1 .... .... = MPLS Bottom Of Label Stack: 1
.... .... .... .... .... .... 1111 1100 = MPLS TTL: 252
Internet Protocol Version 4, Src: 10.1.1.1, Dst: 10.1.2.1From PE2 to CE-A2 there is no label, and the Ethernet type is 0x0800 (IPv4).
$ tshark -r mpls-vpn-fwd-step0-pe2ce.pcap -Y 'icmp.type == 8 && ip.src == 10.1.1.1' \
-T fields -e frame.number -e eth.type -e mpls.label -e ip.src -e ip.dst
3 0x0800 10.1.1.1 10.1.2.1
5 0x0800 10.1.1.1 10.1.2.1
7 0x0800 10.1.1.1 10.1.2.1
9 0x0800 10.1.1.1 10.1.2.1STEP 1: RSVP-TE as the Transport
autoroute announce on the TE tunnel of the PEs puts the IGP route through the tunnel.
interface tunnel-te1
autoroute announce
!
!
endPE1’s route to 2.2.2.2/32 now goes through the tunnel.
Gateway of last resort is not set
L 1.1.1.1/32 is directly connected, 00:09:01, Loopback0
O 2.2.2.2/32 [110/4] via 2.2.2.2, 00:02:14, tunnel-te1
O 3.3.3.3/32 [110/2] via 10.0.13.3, 00:08:45, GigabitEthernet0/0/0/1
O 4.4.4.4/32 [110/3] via 10.0.13.3, 00:08:34, GigabitEthernet0/0/0/1
C 10.0.13.0/24 is directly connected, 00:08:55, GigabitEthernet0/0/0/1
L 10.0.13.1/32 is directly connected, 00:08:55, GigabitEthernet0/0/0/1
O 10.0.24.0/24 [110/3] via 10.0.13.3, 00:08:34, GigabitEthernet0/0/0/1
O 10.0.34.0/24 [110/2] via 10.0.13.3, 00:08:45, GigabitEthernet0/0/0/1The outer label becomes 31006 and then 32006, the labels of the RSVP-TE LSP, and the inner label is still 42007. The values are compared below.
STEP 2: SR-MPLS as the Transport
Remove autoroute announce and tell OSPF to prefer SR.
interface tunnel-te1
no autoroute announce
!
router ospf 1
segment-routing sr-prefer
!
endThe pair PE1 imposes changes with it.
RP/0/RP0/CPU0:PE1#show cef vrf CUST-A 10.1.2.0/24 detail
Sun Oct 4 05:13:55.658 UTC
10.1.2.0/24, version 6, internal 0x5000001 0x30 (ptr 0x88519cd0) [1], 0x0 (0x0), 0x208 (0x899b2458)
Updated Oct 4 05:01:02.070
Prefix Len 24, traffic index 0, precedence n/a, priority 3
gateway array (0x89597950) reference count 2, flags 0x2038, source rib (7), 0 backups
[1 type 1 flags 0x40441 (0x899eb880) ext 0x0 (0x0)]
LW-LDI[type=0, refc=0, ptr=0x0, sh-ldi=0x0]
gateway array update type-time 5 Oct 4 05:11:12.258
LDI Update time Oct 4 05:11:12.259
via 2.2.2.2/32, 3 dependencies, recursive [flags 0x6000]
path-idx 0 NHID 0x0 [0x8856e788 0x0]
recursion-via-/32
next hop VRF - 'default', table - 0xe0000000
next hop 2.2.2.2/32 via 16002/0/21
next hop 10.0.13.3/32 GigabitEthernet0/0/0/1 labels imposed {16002 42007}
Load distribution: 0 (refcount 1)
Hash OK Interface Address
0 Y recursive 16002/0 The outer label is now 16002: the start of the SRGB (16000) plus PE2’s prefix SID index (2).
STEP 3: Back to LDP
Removing segment-routing sr-prefer brings the outer label back to the LDP one.
Comparing the Three Transports
The same traceroute across the four STEPs.
RP/0/RP0/CPU0:CE-A1#traceroute 10.1.2.1 source 10.1.1.1 timeout 1 probe 2 maxttl 8
Sun Oct 4 05:02:35.175 UTC
Type escape sequence to abort.
Tracing the route to 10.1.2.1
1 172.16.1.1 8 msec 6 msec
2 10.0.13.3 [MPLS: Labels 31005/42007 Exp 0] 23 msec 20 msec
3 10.0.34.4 [MPLS: Labels 32005/42007 Exp 0] 69 msec 21 msec
4 10.0.24.2 [MPLS: Label 42007 Exp 0] 21 msec 18 msec
5 172.16.2.2 25 msec * RP/0/RP0/CPU0:CE-A1#traceroute 10.1.2.1 source 10.1.1.1 timeout 1 probe 2 maxttl 8
Sun Oct 4 05:07:48.420 UTC
Type escape sequence to abort.
Tracing the route to 10.1.2.1
1 172.16.1.1 5 msec 4 msec
2 10.0.13.3 [MPLS: Labels 31006/42007 Exp 0] 16 msec 15 msec
3 10.0.34.4 [MPLS: Labels 32006/42007 Exp 0] 15 msec 15 msec
4 10.0.24.2 [MPLS: Label 42007 Exp 0] 16 msec 15 msec
5 172.16.2.2 16 msec * RP/0/RP0/CPU0:CE-A1#traceroute 10.1.2.1 source 10.1.1.1 timeout 1 probe 2 maxttl 8
Sun Oct 4 05:13:11.608 UTC
Type escape sequence to abort.
Tracing the route to 10.1.2.1
1 172.16.1.1 6 msec 4 msec
2 10.0.13.3 [MPLS: Labels 16002/42007 Exp 0] 36 msec 15 msec
3 10.0.34.4 [MPLS: Labels 16002/42007 Exp 0] 15 msec 29 msec
4 10.0.24.2 [MPLS: Label 42007 Exp 0] 18 msec 16 msec
5 172.16.2.2 17 msec * RP/0/RP0/CPU0:CE-A1#traceroute 10.1.2.1 source 10.1.1.1 timeout 1 probe 2 maxttl 8
Sun Oct 4 05:18:30.877 UTC
Type escape sequence to abort.
Tracing the route to 10.1.2.1
1 172.16.1.1 8 msec 5 msec
2 10.0.13.3 [MPLS: Labels 31005/42007 Exp 0] 17 msec 14 msec
3 10.0.34.4 [MPLS: Labels 32005/42007 Exp 0] 15 msec 38 msec
4 10.0.24.2 [MPLS: Label 42007 Exp 0] 17 msec 18 msec
5 172.16.2.2 20 msec * | STEP | Outer | PE1 to P1 | P1 to P2 | P2 to PE2 | Inner (VPN label) |
|---|---|---|---|---|---|
| 0 | LDP | 31005 | 32005 | (removed by PHP) | 42007 |
| 1 | RSVP-TE | 31006 | 32006 | (removed by PHP) | 42007 |
| 2 | SR-MPLS | 16002 | 16002 | (removed by PHP) | 42007 |
| 3 | LDP | 31005 | 32005 | (removed by PHP) | 42007 |
The outer label takes different values under the three mechanisms, and the inner VPN label stays 42007 throughout. The VPN works because of that inner label; the outer one is only the means of carrying it to the egress PE.
Only the SR-MPLS row has the same value on both segments. An SR label is the start of the SRGB plus an index, and every node computes it the same way, so P1’s forwarding table swaps 16002 for 16002.
References
| RFC | Title | Sections used |
|---|---|---|
| RFC 4364 | BGP/MPLS IP Virtual Private Networks (VPNs) | 5 (forwarding: the tunnel label and the VPN route label, PHP, and methods other than LDP), 4.3.2 (VPN label allocation) |
| RFC 3031 | Multiprotocol Label Switching Architecture | 3.15 (label stack), 3.16 (PHP) |
Book: Luc De Ghein, MPLS Fundamentals (Cisco Press, 2006), Chapter 7
Verification Configs and show Output
Every STEP was captured on all six routers, one file per router and kind. The verification config is the ..._run.txt file (the final state is the one from the last STEP).
| File | Contents |
|---|---|
..._show.txt | The full state at that STEP: OSPF (show ospf neighbor, show ospf database), LDP (show mpls ldp neighbor brief, show mpls ldp bindings), MPLS forwarding (show mpls forwarding, show mpls label table), MP-BGP (show bgp vpnv4 unicast, show bgp vpnv4 unicast labels), the VRF (show vrf all detail, show route vrf CUST-A, show cef vrf CUST-A), RSVP-TE (show mpls traffic-eng tunnels, show rsvp session) and SR-MPLS. 48 commands on a PE, 28 on a P |
..._log.txt | show logging limited to that STEP |
..._run.txt | show running-config at that STEP (the verification config) |
..._ping.txt | ping and traceroute between the CEs |
..._trace.txt | show bgp trace on the PEs |
..._commit.cfg | The configuration actually committed in that STEP (only for the routers that changed) |
STEP 0: LDP (initial state)
| Router | show | syslog | running-config | ping | trace | committed config |
|---|---|---|---|---|---|---|
| CE-A1 | show | log | run | ping | - | - |
| PE1 | show | log | run | ping | trace | - |
| P1 | show | log | run | ping | - | - |
| P2 | show | log | run | ping | - | - |
| PE2 | show | log | run | ping | trace | - |
| CE-A2 | show | log | run | ping | - | - |
STEP 1: RSVP-TE (autoroute announce)
| Router | show | syslog | running-config | ping | trace | committed config |
|---|---|---|---|---|---|---|
| CE-A1 | show | log | run | ping | - | - |
| PE1 | show | log | run | ping | trace | commit |
| P1 | show | log | run | ping | - | - |
| P2 | show | log | run | ping | - | - |
| PE2 | show | log | run | ping | trace | commit |
| CE-A2 | show | log | run | ping | - | - |
STEP 2: SR-MPLS (segment-routing sr-prefer)
| Router | show | syslog | running-config | ping | trace | committed config |
|---|---|---|---|---|---|---|
| CE-A1 | show | log | run | ping | - | - |
| PE1 | show | log | run | ping | trace | commit |
| P1 | show | log | run | ping | - | commit |
| P2 | show | log | run | ping | - | commit |
| PE2 | show | log | run | ping | trace | commit |
| CE-A2 | show | log | run | ping | - | - |
STEP 3: Back to LDP (final state)
| Router | show | syslog | running-config | ping | trace | committed config |
|---|---|---|---|---|---|---|
| CE-A1 | show | log | run | ping | - | - |
| PE1 | show | log | run | ping | trace | commit |
| P1 | show | log | run | ping | - | commit |
| P2 | show | log | run | ping | - | commit |
| PE2 | show | log | run | ping | trace | commit |
| CE-A2 | show | log | run | ping | - | - |
Packet captures were taken per STEP (a dash means the segment was not captured).
| STEP | PE1-P1 | P1-P2 | P2-PE2 | PE2-CE-A2 |
|---|---|---|---|---|
| 0 | pcap | pcap | pcap | pcap |
| 1 | pcap | pcap | pcap | — |
| 2 | pcap | pcap | pcap | — |
| 3 | pcap | pcap | pcap | — |
Related Articles
- What Is MPLS VPN (L3VPN)
- MPLS VPN VRF (Virtual Routing and Forwarding)
- MPLS VPN RD (Route Distinguisher)
- MPLS VPN Route Target (RT)
- MPLS VPN MP-BGP (Propagating VPNv4 Routes)
- MPLS VPN Label Allocation (per-prefix / per-CE / per-VRF)
- MPLS VPN Forwarding with Two Labels (Transport Label and VPN Label)
- MPLS VPN PE-CE Routing with Static Routes
- MPLS VPN PE-CE Routing with eBGP
- When Several MPLS VPN Sites Share One AS Number (as-override)