Metro Ethernet is a carrier Ethernet service across a metropolitan area. Each site plugs into the provider with an ordinary Ethernet port, the UNI, and the provider carries Ethernet frames between those ports as a layer 2 service.
What you choose is the shape, E-Line between two sites, E-LAN among many, or E-Tree, where branches reach a hub and not each other, and the rate: a committed information rate, often an excess rate above it, and an agreement that says what each one is worth.
- A layer 2 service: frames in at one port, out at another
- E-Line point to point, E-LAN multipoint, E-Tree hub and branches
- EPL takes the whole port, EVPL one VLAN on a shared port
- You buy a committed rate, not a port speed
On this page
How it worksHow metro Ethernet works
This is how metro Ethernet works from your side of the demarcation point, which is the only side of the provider network you can see.
Your side is an Ethernet port. The provider hands off at a user network interface, the UNI, which Juniper's MEF design documentation calls the customer demarcation point. Your router or switch plugs into it like any other Ethernet port on your network.
The service is a connection between ports. The unit is the Ethernet virtual connection, the EVC. Cisco's documentation quotes MEF's definition: an association between two or more user network interfaces that identifies a point-to-point or multipoint-to-multipoint path within the service provider network. Cisco's own shorthand is a conceptual service pipe.
The middle of the metro Ethernet network is not your business. The standards body long known as MEF, whose site now carries the name Mplify, describes Carrier Ethernet as technology agnostic layer 2 services.
The provider may carry your frames around rings of fiber or across a packet core, and RFC 8214, for one, standardizes how EVPN delivers the point to point versions. None of that is visible from the UNI.
It stays layer 2 from end to end. Frames go in at one UNI and come out at another, and the provider does not route them. That is what lets two sites on one service share a subnet, and it is also what makes them share a broadcast domain, which matters further down.
Use casesWhat businesses use metro Ethernet for
A metro Ethernet network is a metropolitan area network, a MAN: bigger than the local area network inside one building, smaller than a wide area network between cities. Providers build it on fiber in most metro areas, and businesses buy connectivity across it rather than building their own.
Connecting business locations in one city. The original use. Two or more offices, a warehouse and a clinic become one private network, and data between them never touches the public internet.
Reaching a data center. A metro Ethernet connection from the office to a colocation site carries backups, replication and application traffic at LAN like latency, because the distance is short.
Internet access on the same technology. Many providers sell dedicated internet access over a metro Ethernet port, and some carry both the private service and the internet service on one port as separate VLANs.
Private access to cloud networks. Where a cloud provider has an on-ramp in the metro area, an E-Line to it avoids the internet path altogether.
The benefits businesses get are practical ones. Ethernet is the technology your network already runs, so there is no special WAN interface to buy or learn. Bandwidth is symmetrical. And the rate can usually be raised up to the port speed without new equipment, which suits applications such as voice, video and backup data that grow over time.
One point on security. A private Ethernet service keeps your data off the internet, and the provider does not encrypt it. If the data needs encryption between locations, add it yourself, for example with MACsec or an IPsec tunnel.
The limits are as plain. Metro Ethernet covers one metropolitan area, and a location in another city needs a wide area carrier Ethernet service or a different technology. Availability also depends on the building: if the provider's fiber is not already there, construction is added to the order.
The three shapesThe three shapes: E-Line, E-LAN and E-Tree
E-Line is point to point. An EVC connecting two UNIs, in Juniper's wording: two business locations, one Ethernet pipe between them.
E-LAN is multipoint to multipoint. Every location on it can reach every other, which is what lets three or more offices behave like one Ethernet LAN across the metro area.
E-Tree is rooted multipoint, which Mplify describes as hub and spoke multipoint connectivity. Root sites can exchange traffic with any leaf, and leaf to leaf communication is isolated. That is the property a set of branches that must reach headquarters and must not reach each other is looking for, and on an E-LAN it would take filtering to get.
Access E-Line reaches sites the provider does not. Mplify describes it as extending a service to off-net subscriber sites, through another operator's network. The two operators meet at an ENNI, an external network to network interface at the boundary between them.
Port or VLANEPL vs EVPL: the whole port, or one VLAN on it
Every shape comes in two versions, and this is the difference that decides what your port can do.
Port based, the "private" versions. An Ethernet private line, EPL, is port based: in Juniper's wording, an all-to-one bundling service providing a dedicated, transparent data path. RFC 8214 puts MEF's definition more plainly still: traffic between a single pair of ports. Whatever enters the port goes to the other end, VLAN tags and all.
VLAN based, the "virtual private" versions. An Ethernet virtual private line, EVPL, supports service multiplexing: several services share one physical port, each identified by its VLAN. RFC 8214 describes MEF's EVPL as a point to point service between a pair of attachment circuits designated by VLANs.
The practical result is one port at headquarters carrying separate EVCs to several branches, and Juniper's design notes that a single UNI can carry an E-LAN and an E-Line at the same time.
The same split names the multipoint services: EP-LAN and EVP-LAN, EP-Tree and EVP-Tree.
The trade. EPL gives you the port to yourself and passes your tags through untouched. EVPL gives you several services on one port, and in exchange the VLAN numbering on that port becomes something you and the provider have to agree on.
The rateThe bandwidth profile: what CIR and EIR are
The rate you buy is not one number. Carrier Ethernet is sold with a bandwidth profile, and the two figures that matter are the committed information rate, CIR, and the excess information rate, EIR.
The mechanism behind them is a two rate, three color marker, and RFC 4115 defines one. CIR and EIR set the fill rates of two token buckets, each with a burst size measured in bytes. Traffic that fits the committed bucket is marked green, traffic that only fits the excess bucket is marked yellow, and whatever fits neither is red.
The colors are the contract. What the standard defines is the sorting. What happens to each color, which of them the provider's latency and loss figures apply to, and whether yellow traffic survives a busy evening, is set by the service agreement. Read it for the words committed and excess, and assume nothing about yellow that it does not say.
A port speed is not a rate. A 1 Gbps port with a 200 Mbps committed information rate is a 200 Mbps commitment on a port that can go faster when the agreement lets it. That is an easy distinction to lose between the sales call and the invoice.
The orderWhat an order actually specifies
Put the definitions together and an order for a metro Ethernet service comes down to five things. Everything else in a quote is price.
The UNIs. Every site on the service and the port speed at each one. Port speeds are the usual Ethernet speeds: 100 Mbps, 1 Gbps or 10 Gbps. The port speed is the physical ceiling, and it is often faster than anything you will be committed.
The EVC and its shape. E-Line, E-LAN or E-Tree, which sites sit on it, and on an E-Tree which sites are roots and which are leaves.
Port based or VLAN based. Port based services take the whole port. VLAN based services need the VLAN each EVC uses at each UNI, agreed before the circuit is built.
The bandwidth profile for each EVC. The committed information rate, any excess rate, and, in the agreement's own words, what happens to traffic in each color.
On net or off net. Whether any site sits outside the provider's own network and will be reached through another operator, which adds an ENNI and a second company to the fault path.
A quote that does not name all five has not yet described a service, which is the most useful thing to check before comparing two of them.
PitfallsWhere people go wrong
Reading the port speed as the rate. The port is the ceiling. The committed information rate is the commitment.
Assuming yellow is guaranteed. Excess traffic is sorted by the same marker as committed traffic and promised whatever the agreement says, which may be nothing.
Treating an E-LAN like a router. Every site on it is in one Ethernet broadcast domain, as if all your networks shared one switch. A loop or a broadcast storm at one office is every office's problem, which is a reason to put a router at each site rather than a switch.
Ordering EPL and then wanting a second service on the port. Several services on one port is what EVPL is for. On an EPL the whole port is one service.
Leaving the VLAN plan until the circuit is live. On EVPL the VLAN that maps to each EVC is part of the order. Get it in writing before the engineer arrives.
Forgetting the second operator. An off-net site reached through an ENNI has two providers in its path, and every fault is a conversation with both.
ComparisonMetro Ethernet, an MPLS VPN, dark fiber and a VPN over the internet
| Criterion | Metro Ethernet | MPLS VPN | Dark fiber | Internet and a VPN |
|---|---|---|---|---|
| What the provider gives you | Layer 2, frames | Layer 3, routes | Layer 1, glass | Layer 3, the public internet |
| Who routes between your sites | You | The provider | You | You |
| What caps your capacity | The bandwidth profile | The contracted rate | Your own optics | The plan |
| What the provider manages | The path, end to end | The path and the routing | Only the strands | Only the access line |
For a business that has to connect multiple locations in one metro area, metro Ethernet sits between the two ends of that table. The provider runs the path, as with an MPLS VPN, and you keep the routing, as with dark fiber, without owning optics or a single strand.
FAQFrequently asked questions
What is metro Ethernet?
A carrier's Ethernet service across a metropolitan area. Your sites connect to the provider with Ethernet ports, and the provider carries frames between them as a layer 2 service, point to point, multipoint, or hub and branches.
How does metro Ethernet work?
Each site hands off to the provider at a user network interface, an Ethernet port. The provider builds an Ethernet virtual connection between the ports and carries your frames across its own network, which you never see. You buy the shape of the connection and a bandwidth profile.
What is the difference between E-Line and E-LAN?
E-Line is point to point between two sites. E-LAN is multipoint to multipoint, so every site on it can reach every other.
What is E-Tree?
A rooted multipoint service. Root sites reach every leaf and leaves reach the roots, but leaf to leaf traffic is isolated, which suits branches that should reach headquarters and not each other.
What is the difference between EPL and EVPL?
EPL is port based: the whole port is one service, and every frame goes to the other end with its VLAN tags intact. EVPL is VLAN based: several services share one port, each identified by a VLAN, which is called service multiplexing.
What is an EVC?
An Ethernet virtual connection: the association between two or more user network interfaces that makes up the service. It is the connection you are buying, whatever the provider uses to carry it.
What is a UNI in metro Ethernet?
The user network interface: the port where the provider hands the service to you, and the demarcation point between their network and yours.
What are CIR and EIR?
The committed information rate and the excess information rate, the two figures in a bandwidth profile. A two rate marker like the one in RFC 4115 sorts traffic into green within CIR, yellow within EIR, and red beyond both. What each color is guaranteed is set by the service agreement.
Is metro Ethernet the same as carrier Ethernet?
It is carrier Ethernet delivered across a metro area. The standards call the services Carrier Ethernet, and metro Ethernet is the name the metropolitan version is usually sold under.
Is metro Ethernet the same as MPLS?
No. Metro Ethernet gives you a layer 2 connection and you do the routing; an MPLS VPN is a layer 3 service where the provider routes between your sites. A provider may well carry metro Ethernet over MPLS inside its network, and that is invisible to you.
Metro Ethernet or dark fiber?
Metro Ethernet if you want the provider to run the path. Dark fiber if you want the strands themselves and will buy and run the optics. The first is a service with a rate; the second has no rate but the one your equipment gives it.
What is an ENNI?
An external network to network interface: the boundary where two operators' Carrier Ethernet networks meet, which is how a service reaches an off-net site.
Keep readingRelated concepts
Read next · Design Ring Topology, and the Networks Where It Never Went Away The loop many metro networks are physically built as, underneath the service. Open this next11 min- Infrastructure · 11 min MPLS Explained The routed alternative, where the provider runs the routing between your sites as well.
- Infrastructure · 12 min What Dark Fiber Is, and Why It Is Not Bandwidth The option below this one: the strands themselves, with you buying and running the optics.