An ingress label-switching router pushes a label, intermediate routers swap labels according to forwarding state, and an egress router removes the label or forwards the packet onward.
The resulting label-switched path can support engineered forwarding, service separation, and traffic classes across a provider or enterprise backbone. Labels have meaning within their defined context rather than serving as globally meaningful addresses. MPLS can carry different network-layer protocols and underpin services described as Layer 2 or Layer 3 virtual private networks.
Key points
ForwardingUse the active label and local forwarding entry to select the next hop and perform a push, swap, or pop operation on the label stack.
Service designDefine route separation, path selection, restoration, quality-of-service treatment, and handoff responsibilities for each service rather than inferring them from “MPLS.”
OperationsProtect management and control planes, monitor label-switched paths and provider boundaries, test failover, and understand whether nominally diverse circuits share infrastructure.
Important limitationMPLS does not inherently encrypt or authenticate customer traffic. Route separation inside a managed provider network is not equivalent to cryptographic protection, and misconfiguration or provider compromise can cross an intended boundary.