Multiprotocol Label Switching (MPLS) is a technique carriers use to forward traffic through their networks using short labels, read at each hop instead of looking up the full destination address at every hop. For business buyers, “MPLS” usually means the service built on it: an MPLS VPN, a private WAN that connects offices, data centers and sometimes cloud providers over the carrier’s network, with traffic kept separate from other customers and from the public internet. For years it was the default way to link business sites; today it is often one option alongside or underneath SD-WAN.
At a glance
- MPLS is a forwarding technique inside carrier networks; what businesses buy is usually an MPLS VPN service between their sites.
- Traffic is logically separated from other customers on a shared carrier core, but it is not encrypted by default.
- Carriers can prioritize traffic classes such as voice, and many contracts include service level commitments for latency, jitter and loss; the specifics vary by contract.
- Each site needs an access circuit into the carrier’s network, which drives cost and lead times.
- Many organizations now run SD-WAN over internet links, keeping MPLS at some sites or retiring it.
What problem it solves
Before cheap, fast internet access was widespread, businesses needed a private, predictable way to connect branches to headquarters and data centers. Leased point-to-point lines worked but got expensive as sites multiplied, and early internet VPNs were unpredictable for voice and business applications.
MPLS solved that by letting a carrier carry many customers’ private networks over one shared core, keeping each customer’s traffic separate, and treating different kinds of traffic differently. A company could connect every site to one any-to-any network, mark voice and critical applications for priority, and hold the carrier to a service level agreement. That predictability, and a single provider responsible for the whole network, is why many organizations still keep MPLS at important sites.
How it works
Labels. When a packet enters the carrier’s MPLS network at a provider edge router, the router assigns it a short label based on its destination and service. Routers in the core forward the packet by reading only the label, swapping it at each hop, along a label-switched path. The label is removed at the far edge.
Separation. In a Layer 3 MPLS VPN, a common business service, each customer gets its own routing table on the carrier’s edge routers, so customers’ routes and traffic stay apart even though they share the same core. Layer 2 services such as VPLS and pseudowires use MPLS to carry Ethernet between sites instead.
Traffic classes. The customer’s router marks traffic, for example voice as highest priority, and the carrier maps those markings to its own quality of service (QoS) classes. Each class has its own bandwidth share and handling, and many carriers attach SLA targets per class. How much bandwidth each class gets is set in the contract and router configuration.
Traffic engineering. Carriers can steer label-switched paths around congestion or failures, and some offer fast reroute that switches paths quickly after a link failure in the core. These features are carrier-side and vary by network.
Access. Each site connects to the nearest carrier point of presence over an access circuit, such as Ethernet over fiber, and sometimes a backup circuit or wireless path. The access circuit is often the weakest link and the main driver of cost and installation time.
Multiprotocol. The “multiprotocol” in the name means MPLS can carry different types of traffic, such as IP or Ethernet, over the same core.
When it matters for buyers
- At contract renewal. Benchmark per-site pricing, review which sites still need MPLS, and check early termination and site-removal terms before deciding to renew, shrink or exit.
- Moving to the cloud. Backhauling SaaS and cloud traffic through a central site over MPLS can add latency; consider cloud interconnects or local internet breakout.
- Adopting SD-WAN. Decide whether MPLS stays as one transport under SD-WAN, stays only at some sites, or is retired.
- Opening new sites. Lead times for MPLS access circuits can be long, especially internationally; plan around them.
- Voice and real-time applications. If you depend on traffic classes for call quality, confirm how they will be handled in any replacement.
Questions to ask vendors
- What service level commitments do you offer per traffic class for latency, jitter, packet loss and availability, and what are the credits?
- How many traffic classes do you support, and how is bandwidth allocated between them?
- What access options and backup paths are available at each of our sites, and what are the lead times?
- Can you connect our MPLS network directly to our cloud providers, and at what cost?
- Is the core network protected with fast reroute, and how are access circuit failures handled?
- Can MPLS run as one transport under an SD-WAN service, and who manages the routers?
- What are the terms for adding or removing sites mid-contract, and what happens at renewal?
We compare MPLS, SD-WAN and other private WAN options in our private networking and global WAN services overviews. Our post on controlling telecom costs covers renewal tactics.
How it differs from SD-WAN
MPLS is a carrier service: the carrier runs the network, separates your traffic, prioritizes it and commits to service levels on its own infrastructure. SD-WAN is an overlay you or a managed provider run on top of whatever links each site has, such as broadband, dedicated internet, 5G or MPLS, steering application traffic across them based on policy and measured performance. SD-WAN does not replace the transport; it decides how to use it. Many organizations use SD-WAN over internet links instead of MPLS, while others keep MPLS as one SD-WAN transport at sites where predictability matters most. See four questions to ask a potential SD-WAN provider.
