MPLS forwards traffic through a carrier network on a short label attached to each packet rather than on the destination address. The first router reads the packet and pushes a label.
Every router after that reads only the label, swaps it and forwards, never consulting a routing table. Because the path is pinned at the edge, a carrier can commit to a latency figure, and that commitment is what an MPLS service actually sells.
- Push at the edge, swap in the middle, pop before the end
- The middle of the network never reads the IP header
- It is not encrypted, and private is not confidential
- The product is a service level, not speed
- SD-WAN replaced it for branches, not for everything
On this page
The ideaWhy labels instead of addresses
MPLS was invented to solve a networking problem that no longer exists, and survived because it turned out to solve a different one.
In the late 1990s, routing a packet meant finding the longest matching prefix in a large table, which was slow in software and expensive in hardware. Matching a fixed length label is a direct lookup, so early MPLS routers forwarded data far faster than routers doing the routing arithmetic properly.
Hardware caught the problem in a decade. Modern routers do line rate routing lookups without difficulty, and the performance argument for MPLS is finished.
What survived is the side effect. Because the label is assigned at the edge and every router afterward follows it, the path through the network is determined in advance rather than recalculated at every hop. A carrier that controls the path can engineer around congestion, reserve capacity, and commit to a latency figure in a contract. That is the product.
The pathHow packets actually cross an MPLS network
Three MPLS roles, and a packet meets them in order.
The label edge router, at the ingress. This is the only device that inspects the packet properly. It decides which forwarding equivalence class the packet belongs to, the group of packets that should all be treated the same way, and pushes the matching label onto the front of the data. Everything with the same class follows the same label switched path.
The label switch routers, in the middle. Each one reads the incoming label, looks it up in a small switching table, swaps it for the outgoing label the next hop expects, and forwards the packet.
It never reads the IP header, and it does no routing at all. This is what makes MPLS protocol agnostic: the data could be IPv4, IPv6 or a frame from something else entirely, and the middle of the network does not care.
The label edge router, at the egress. Pops the label and delivers the packet by normal routing. In practice the second to last router usually pops it instead, which is called penultimate hop popping and exists so the last router only has to do one lookup rather than two.
| Router | Where | Label operation | Reads the IP header |
|---|---|---|---|
| Label edge router | Ingress | Push | Yes, once |
| Label switch router | Middle | Swap | No |
| Penultimate router | Second to last | Pop | No |
| Label edge router | Egress | Pop, if not already | Yes, to deliver |
The middle column is the whole mechanism. Push once, swap as many times as the path needs, pop before the end. Nothing between the two edges ever asks where the packet is going.
The labels themselves are distributed by a label distribution protocol, usually LDP or an extension of RSVP, so each MPLS router learns which outgoing label corresponds to which incoming one. Nobody configures the labels by hand.
A packet can carry several labels at once, stacked, which is how the interesting features work. The outer label carries the data across the carrier network and the inner one identifies which customer network, or which service, it belongs to. That stack is how one physical network serves hundreds of customer networks that each see a private one.
The productWhat an MPLS service actually gives you
Stripped of vendor language, four things, and only two of them are unique.
A committed service level. The carrier states a latency, jitter, packet loss and availability figure and pays penalties for missing it. This is the real MPLS product, and no internet access circuit comes with it.
Quality of service that survives the carrier network. Packets marked as voice stay marked and are prioritized end to end. On the public internet, the marking is honored by your own equipment and ignored by every network after it.
Any to any connectivity between sites, without configuring a tunnel per pair. The carrier network handles the routing, which is why a twenty site MPLS network is administratively simpler than twenty sites of manually meshed tunnels.
Data that never touches the public internet. Worth stating precisely: MPLS is private in the sense that a carrier network is not the internet, and that is a security property with limits. The next section works through them.
SecurityThe security question, answered properly
Every MPLS conversation reaches this point and most of them get it half right, so it is worth being exact about what the technology does and does not do for data security.
MPLS traffic is not encrypted. Labels are a switching mechanism, not a security mechanism. Traffic crossing an MPLS network travels in whatever form the application sent it, and anyone with access to the carrier network could read it.
MPLS traffic is separated, and that separation is real. The label stack keeps one customer's data on its own label switched paths, and the carrier's routers will not deliver packets from one customer network into another.
That is meaningful isolation, and it is why MPLS is described as private. It is the same kind of security a locked corridor provides: strangers cannot walk in, and everyone with a key can read what is written on the walls.
The threat model that matters is the carrier itself, plus anyone who compromises it. A misconfiguration inside the provider network, an insider, or a lawful interception request all reach data an MPLS service does nothing to protect.
The practical conclusion is short. Treat an MPLS network as a private path with no confidentiality, and run encryption over the top of it for anything sensitive, exactly as you would across the internet. That costs almost nothing on modern hardware, and it removes the one security assumption that gets written into architecture diagrams and never checked.
Against SD-WANMPLS against SD-WAN
This is the comparison every current conversation is really about.
SD-WAN builds encrypted tunnels over whatever circuits a site has, usually broadband and mobile, and steers data across them based on measured performance and policy.
It replaces the carrier engineering with software at the edge of your own network. How one vendor builds it, and why its controller never carries a packet of your traffic, is on the Cisco SD-WAN page.
Where SD-WAN wins is bandwidth per dollar, deployment time, and cloud performance. A branch that mostly talks to software as a service is being poorly served by hauling everything to a datacenter across an MPLS circuit and then out to the internet, which is exactly what a traditional design does.
Where MPLS still wins is the guarantee. SD-WAN measures a path and chooses the better one. It cannot make a bad path good, and if both access circuits into a site are congested, no amount of software fixes that. For a workload where consistent latency is a requirement rather than a preference, the contract is the point.
The common answer is both. MPLS for the traffic that needs the commitment, broadband for everything else, steered by SD-WAN. That is the WAN design most carriers now sell, which tells you where the market landed.
PitfallsWhere people go wrong
Assuming MPLS provides data security. It does not encrypt anything. Private carrier network, not confidential. Encrypt sensitive data over the top of it.
Buying it for speed. The switching performance argument stopped being true fifteen years ago. Buying MPLS for anything other than the service level and the quality of service is buying the wrong product.
Backhauling cloud data across it. A branch reaching a cloud application through a datacenter over MPLS adds latency in both directions to pay for security inspection that could happen locally. This is the single most common reason an MPLS network feels slow.
Ordering circuits without checking the lead time. MPLS access circuits are ordered from a carrier and delivered in weeks or months, not days. Any project depending on new sites has to start with that number.
Comparing bandwidth prices directly. MPLS costs several times more per megabit than broadband, and that comparison ignores what is being bought. Compare the guarantee, or compare a WAN design rather than a price.
Assuming MPLS is going away. It is shrinking, not disappearing. Carriers still sell it, and organizations in banking and healthcare still buy it, because a latency figure that has to be contractual has no other answer.
ComparisonMPLS, SD-WAN and an internet VPN, on what each one actually commits to
| Criterion | MPLS | SD-WAN | Internet VPN |
|---|---|---|---|
| Committed latency and packet loss | Yes | No | No |
| Encrypted by default | No | Yes | Yes |
| Cost per megabit | High | Low | Low |
| Time to add a site | Weeks | Days | Days |
| Direct cloud access from a branch | Poor | Native | Workable |
| Quality of service end to end | Yes | Within your control only | No |
| Any to any without per pair config | Yes | Yes | No |
| Runs over whatever circuits exist | No | Yes | Yes |
| Right for a latency critical workload | Yes | Sometimes | No |
The first row and the third row are the whole trade. Everything else follows from paying a carrier to promise something about the network, or paying a fraction as much and managing the variability yourself.
FAQFrequently asked questions
What is MPLS in simple terms?
A way of moving packets through a carrier network by attaching a short label to each one, so every router in the middle follows the label instead of working out the destination.
Is MPLS a layer 2 or layer 3 technology?
Neither, exactly. The label sits between the data link layer and the network layer, which is why MPLS is often called layer 2.5. It carries any payload, which is where the multiprotocol in the name comes from.
Is MPLS encrypted?
No. The data stays on a carrier network rather than the public internet, and that is not the same as confidential. Run encryption over it for anything sensitive.
Is MPLS faster than the internet?
Not inherently. It is more consistent, because the label switched path is engineered and the carrier commits to it. Consistency is what people mean when they say an MPLS circuit feels faster.
What is a label switched path?
The route labeled packets follow across the network, decided once at the ingress router and followed by every switching router afterward without further routing decisions.
What is a forwarding equivalence class?
The group packets are assigned to at the edge. Everything in the same class gets the same label and therefore the same path and the same treatment across the network.
Does SD-WAN replace MPLS?
For most branch networks, yes, and not for workloads that need a contractual latency figure. Most organizations now run both, with SD-WAN steering traffic between them.
Why is MPLS so expensive?
Because the carrier is selling network capacity it has engineered and committed to, not capacity it hopes is available. That commitment is the cost.
What is penultimate hop popping?
The second to last router removing the label instead of the last one, so the final router does a single lookup rather than two. A small optimization that is on by default nearly everywhere.
Can MPLS carry voice traffic well?
Yes, and that was a large part of its adoption. Quality of service markings on the packets are honored across the carrier network, which is exactly what voice needs and what the public internet does not provide.
How long does it take to install?
Weeks to months per site, depending on the location and whether a circuit already exists. Plan any site rollout around that lead time rather than around the equipment.
Is MPLS still worth buying today?
For organizations with a latency sensitive workload and a contract that needs a number in it, yes. For a branch network that mostly reaches cloud applications, almost never.
What is the MPLS meaning?
MPLS means Multiprotocol Label Switching. Routers at the edge of the network attach a short label to each packet, and routers in the core forward on that label instead of looking up the destination address. Multiprotocol refers to the fact that it can carry IP and other traffic alike.
Keep readingRelated concepts
Read next · Remote access VPN vs Proxy Whether a site needs a private path at all, before deciding which kind to buy. Open this next13 min- Remote access · 11 min What Is an IPsec VPN? MPLS is private and unencrypted, so anything sensitive crossing it wants a tunnel over the top.
- Routing · 12 min What Is BGP? MPLS carries the traffic. BGP is how the networks either side of it agree on where anything is.
- Infrastructure · 11 min Quality of Service, and the Condition It Needs to Do Anything Where DSCP survives the boundary.
- Infrastructure · 12 min What Dark Fiber Is, and Why It Is Not Bandwidth What it replaced.
- Routing · 12 min The IS-IS Protocol, and Why It Runs the Networks You Never See Why the carriers were already running it.
- Infrastructure · 8 min Cisco SD-WAN, and Why the Controller Never Touches Your Traffic Cisco SD-WAN taken apart: the four components, OMP, and why its controller carries no traffic.
- Infrastructure · 9 min Metro Ethernet, and What You Are Actually Buying From the Carrier Metro Ethernet, the layer 2 service where the provider carries frames and you keep the routing.
- Network operations · 10 min Bandwidth Management, the Four Levers and When to Pull Each The managed link whose contracted rate policing and shaping enforce.
- Routing · 9 min BGP Community, the Tag That Signals Routing Policy The service that uses extended communities to separate customers.