What Is EVPL (Ethernet Virtual Private Line)?

Related problems: Headquarters needs links to many branches without a separate port for each; We want to add circuits to a site without installing new hardware; Point-to-point private lines to every site cost too much

An Ethernet Virtual Private Line (EVPL) is a point-to-point Carrier Ethernet service that is VLAN-aware: the provider assigns your traffic to a circuit based on its VLAN tags or other classification rules, which allows several circuits to share one customer port. MEF, the body that standardizes Carrier Ethernet, calls this service multiplexing. A given EVPL design may use it heavily, as at a hub site with circuits to many branches, or not at all, with one circuit per port. EVPL is the VLAN-based sibling of the port-based Ethernet Private Line (EPL), and both are forms of E-Line, MEF’s point-to-point service type.

At a glance

  • Each EVPL circuit is point-to-point, and the service permits several circuits at one port; whether they share a port is a design choice.
  • Traffic is mapped to circuits by VLAN tags or other agreed rules, so your equipment needs to mark frames as the provider expects.
  • A circuit may have a bandwidth profile with a committed rate and an excess, best-effort rate; the rules vary by provider.
  • It is common for hub-and-spoke designs, such as a data center port with circuits to many branches.
  • Branch ends can be EVPL ports too, or other access types, depending on the provider.

What problem it solves

With port-based EPL, each circuit takes its own port at each end. A headquarters connecting to twenty branches would need twenty ports and twenty hand-offs, with the cost and rack space that implies. Because EVPL permits multiple circuits at one port, the hub can use a single larger port carrying a separate virtual circuit to each branch, if that suits the design.

That can make it quicker and cheaper to add sites: a new branch circuit can often be provisioned as a new VLAN on an existing hub port, without a new physical install at headquarters. It also suits connecting to partners or cloud on-ramps where each destination gets its own circuit.

How it works

Ports and circuits. Each site has an Ethernet port, the user-network interface (UNI). Each point-to-point connection across the provider’s network is an Ethernet virtual connection (EVC). EVPL permits more than one EVC at a UNI; how many you actually use is up to the design.

Classification. Your router or switch tags traffic for each circuit with an agreed VLAN ID, and the provider maps each VLAN, or a group of VLANs, to the matching EVC. Some providers translate VLAN IDs between ends; others require them to match. Getting this mapping right is a common source of install delays.

Bandwidth profiles. An EVC may have a bandwidth profile with a committed information rate (CIR), which can be zero, and an excess information rate (EIR) for traffic above it that is carried on a best-effort basis. Profiles can apply per circuit, per class of service or across a port. Whether commitments on a port can add up to more than the port speed, and how bursting and oversubscription work, vary by provider.

Transparency. EVPL generally passes less of the customer’s Layer 2 control traffic than EPL, because the port is VLAN-aware and may be shared among circuits. Check which protocols and frame sizes are supported if you rely on particular features.

Off-net delivery. When a provider does not reach a branch, it may lease access from another carrier and receive the circuit at a network-to-network interface (NNI), where many customers’ circuits are carried on one link and kept separate.

For more on combining access from several carriers into one design, see our network aggregation page.

When it matters for buyers

  • Hub-and-spoke networks. A central site connecting to many branches or stores is a classic EVPL design.
  • Adding sites quickly. If the hub port has capacity, new circuits can often be added without new hardware at the hub.
  • Connecting to clouds and partners. Data center ports often carry EVPL circuits to several cloud providers or partners at once.
  • When you need one transparent link. If a site has a single, high-volume connection and needs its Layer 2 traffic passed through as sent, EPL may be simpler.

Questions to ask vendors

  • Is the service VLAN-based EVPL or port-based EPL, and can it be changed later?
  • How is traffic classified to each circuit, and do VLAN IDs need to match at both ends?
  • What bandwidth profile applies to each circuit: CIR, EIR, and per circuit or per port?
  • Can the commitments on a port exceed the port speed, and where can contention occur?
  • Which classes of service are available, and how is priority traffic marked?
  • Which Layer 2 control protocols and maximum frame sizes (MTU) pass through?
  • Which sites are on-net, and how are off-net circuits handed off and supported?
  • What do latency, loss and availability targets cover, per circuit or per port?

How it differs from EPL

Both are point-to-point E-Line services. An EPL is port-based: one circuit uses the port, and your traffic passes through largely as sent, which makes it simple and transparent. An EVPL is VLAN-aware: the provider classifies traffic by VLAN or other rules, which permits several circuits at one port and can make hub-and-spoke networks easier to grow. Choose EPL for a single link where you want minimal interaction with the provider’s network, and consider EVPL when one site needs connections to several others.

Frequently Asked Questions

What is the difference between EPL and EVPL?
An Ethernet Private Line (EPL) is port-based: one point-to-point circuit uses the whole port and passes your traffic through largely as sent. EVPL is VLAN-aware: the service permits several point-to-point circuits at the same port, with traffic assigned to each by VLAN or other classification rules. Whether you actually put several circuits on a port depends on your design. EVPL often suits hub sites; EPL suits a single link where you want maximum transparency.
Is EVPL less secure than EPL?
Both keep your traffic separate from other customers' traffic within the provider's network. The difference is mainly that an EVPL port can be shared among several of your own circuits, and in some networks capacity is shared more closely. Encrypt traffic if your policies require it, on either service.
Is the bandwidth on an EVPL guaranteed?
It depends on the bandwidth profile. A circuit may have a committed information rate (CIR), which can be anything from zero upward, and an excess information rate (EIR) for best-effort bursts. Whether commitments on a port can add up to more than the port speed, and how bursting and oversubscription work, vary by provider. Ask what is committed and where contention can occur.
Can I mix EVPL with other services on the same port?
Often, yes. Many providers let a VLAN-aware port carry EVPL circuits alongside a multipoint E-LAN service or internet access, each on its own VLAN. Availability depends on the provider and product.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.