Virtual Private LAN Service (VPLS) is a carrier technology that connects several sites, usually over a provider’s MPLS network so they act like one shared Ethernet LAN. Each site plugs into the provider with an Ethernet port, and devices at different sites can reach each other as if they were on the same switch. Providers use VPLS to deliver multipoint Layer 2 services, often sold as E-LAN. It was standardized by the IETF in 2007 and is a mature technology, increasingly complemented or replaced by EVPN.
At a glance
- VPLS joins multiple sites into one virtual Ethernet LAN, usually over a provider’s MPLS network.
- The provider forwards Ethernet frames; you keep control of your own IP addressing and routing.
- Useful when applications need Layer 2 connectivity between sites, such as some clustering or legacy systems.
- Broadcasts and loops travel across the whole service, so one site’s problem can affect others.
- It isolates your traffic from other customers but does not encrypt it.
What problem it solves
Some applications and network designs expect servers and devices to share one network segment: server clusters, some virtual machine moves between data centers, industrial and legacy systems, and networks built around VLANs that span sites. Routed WAN services put each site on its own subnet, which breaks those designs. Point-to-point Ethernet circuits can connect two sites at Layer 2, but meshing many sites that way multiplies circuits and cost.
VPLS gives each site one connection into a multipoint service that behaves like a LAN switch spanning all locations. The provider handles the mesh, and your team keeps full control of addressing and routing because the provider is not involved at Layer 3.
How it works
- Customer edge. Each site connects a router or switch to the provider over Ethernet.
- Provider edge. The provider’s edge routers create a virtual switch for your service. Between them, they build a mesh of tunnels, called pseudowires, across the MPLS core.
- MAC learning. Like a LAN switch, each provider edge router learns which MAC addresses are behind which site and forwards frames there. Unknown destinations, broadcasts and multicast are flooded to all sites in the service.
- Signaling. The pseudowires are set up using either BGP or LDP, the two standard approaches. Larger deployments often use a hierarchical design (H-VPLS) to reduce the number of tunnels.
Because the service behaves like one LAN, everything a LAN does travels across it, including broadcasts, ARP traffic, and any loop in a site’s switching. Providers usually limit the number of MAC addresses per site and may rate-limit broadcast traffic to protect the service.
When it matters for buyers
- When an application truly needs Layer 2 between sites. Confirm the requirement first. Many designs that once needed it can now run over routed networks.
- At contract renewal. Legacy VPLS and other private WAN services are often priced well above current alternatives. Renewal is the time to compare E-LAN on EVPN, an MPLS Layer 3 VPN and SD-WAN over internet links.
- When growing the number of sites. Ask about MAC-address limits, how new sites are added and what happens to the whole service if one site floods it.
- When designing resilience. Dual-homing a site to two provider edge routers is harder with VPLS than with EVPN. Ask how redundancy and failover work.
- When security requirements apply. Plan your own encryption if regulations or policy require it, and check that your equipment can encrypt at the speed you need.
Our global WAN services page covers how to compare private WAN options across regions.
Questions to ask vendors
- Is this E-LAN service built on VPLS or EVPN, and does that affect scale or failover?
- How many sites and MAC addresses per site does the service support?
- How do you limit broadcast, multicast and unknown traffic, and what happens if one site floods the service?
- Can a site connect to two provider edge routers for redundancy, and how fast is failover?
- What are the SLA commitments for latency, jitter, packet loss and availability between our sites?
- Is encryption available, or should we encrypt on our own equipment?
- What migration options do you offer if we move to a Layer 3 VPN or SD-WAN later?
How it differs from an MPLS Layer 3 VPN
Both run over a provider’s MPLS network and keep your traffic separate from other customers. The difference is the layer. With VPLS, the provider acts like a big Ethernet switch: your sites share one LAN segment and you run your own routing. With an MPLS Layer 3 VPN, the provider routes your IP traffic: each site has its own subnet, and the provider’s routers exchange your routes. Layer 3 VPNs scale more easily and contain broadcast problems at each site; VPLS suits designs that need sites on the same segment and teams that want full control of routing.
