Multiprotocol Label Switching (MPLS)

A carrier forwarding technique that sends packets along pre-established paths by reading short labels instead of IP addresses; it separates customers' traffic but does not encrypt it.

Multiprotocol Label Switching, defined in RFC 3031, forwards traffic by label rather than by address. When a packet enters an MPLS network, the edge router assigns it a short label that stands for a path chosen in advance, a label switched path. Each router along the way reads the label, swaps it for the next one and forwards the packet without a full routing lookup on the IP header. It is called multiprotocol because it can carry IP, Ethernet and other traffic, and because it sits between the Data Link and Network layers it is sometimes described as layer 2.5. Carriers use it for wide-area services with predictable paths and quality of service.

MPLS is widely used to deliver private WAN connections, including provider-managed VPNs in which virtual routing and forwarding keeps each customer’s routes separate. The trap is the word private. An MPLS VPN separates traffic logically but does not encrypt it, so confidentiality depends on trusting the carrier and its configuration. Organisations that need confidentiality over MPLS add encryption such as IPsec. SD-WAN is commonly deployed alongside MPLS or in its place.

Exam relevance: a scenario is likely to ask whether traffic on a carrier’s MPLS service is protected in transit. Candidates are expected to recognise that MPLS provides separation and traffic engineering, not confidentiality.