MPLS Traffic Engineering
Configuring MPLS L3VPN services with explicit traffic-engineering tunnels across a provider-style core.
Overview
This lab recreates a small service-provider backbone: a six-router MPLS core with an OSPF underlay, LDP switching labels, and MP-BGP carrying customer VPNv4 routes between provider edges. Two customer sites are multihomed to different edges, so the design has to survive a PE failure without leaking routes back.
Traffic engineering is layered on top with explicit-path tunnels: voice traffic takes the low-latency path while bulk traffic is pinned to the high-capacity links, and the split stays in place even when links flap.
Lab facts
- PlatformEVE-NG · Cisco IOS
- UnderlayOSPF + LDP
- ServicesMPLS L3VPN, VRFs
- TERSVP explicit paths
- Loop controlBGP SOO communities
What this lab covers
- OSPF underlay with LDP label distribution on every core link
- VRF per customer with MP-BGP VPNv4 between provider edges
- Multihomed CE pair with SOO communities stopping loops
- Explicit-path TE tunnels with bandwidth reservations
- Traffic split: voice on low-latency path, bulk on capacity path
- Core link failure drill with tunnel re-optimisation
Key configuration
! PE — VRF with SOO against multihome loops ip vrf CUSTOMER-A rd 65000:10 route-target export 65000:10 route-target import 65000:10 interface Gi0/1 ip vrf forwarding CUSTOMER-A ip address 192.168.10.1 255.255.255.252 ip vrf sitemap CUSTOMER-A-SOO ! TE tunnel with an explicit low-latency path interface Tunnel10 ip unnumbered Loopback0 tunnel mode mpls traffic-eng tunnel mpls traffic-eng autoroute announce tunnel mpls traffic-eng path-option 1 explicit name LOW-LATENCY
Results & takeaways
Both customer sites stayed reachable through either provider edge, and the SOO community correctly suppressed routes that tried to loop back through the second CE. TE tunnels held their explicit paths under load, and voice-class traffic kept its low-latency route when a core link was shut.
The main lesson: draw the explicit paths before configuring them. Tunnels that looked right in the CLI but crossed the same physical link defeated the purpose — the topology map caught what the config hid.