You are on page 1of 2

9.

5 Designing Service Provider-Managed VPNs

PE Router Architecture 

The PE routers in the MPLS VPN implementation are the most important components in the
MPLS VPN architecture. The routers perform multiple functions.

The PE router architecture overview

The first goal of the PE router is to isolate the customer traffic. Because the routing should be
separate and private for each customer on a PE router, each VPN should have its own routing
table. This table is called the VRF routing table. Each interface toward the CE router can
belong to only one VRF. Therefore, each packet that is received on the interface is
unambiguously identified as belonging to this VRF. This implementation is similar to having
one router for each customer.

The PE router must establish the IGP routing adjacency with the CE routers to get the routes
from the customer. These routes are installed in the isolated routing table. Alternatively, the
PE router could have a static route in the isolated routing table. It can be an operational
burden when you manually need to configure many static routes. Because the routing tables
are completely isolated, the different customers could use overlapping address space.

The PE routers exchange routes that are installed in the VRF routing table with the other PE
routers that have MP-BGP. The problem is that when BGP carries these IPv4 prefixes across
the P-network, they must be unique. If the customers have overlapping IP addressing, the
routing would be wrong. To solve this problem, the concept of RD was introduced. The basic
idea is that each prefix from each customer receives a unique identifier to distinguish the
same prefix from different customers. When a router prepends the RD to the route, the route
becomes the VPNv4 prefix in MP-BGP.
The PE router has a global routing table as well. The router uses this global routing table to
establish BGP connections with other PE routers. The router also uses this routing table to
define MPLS labels to the other PE routers for traffic forwarding over the core P-network.

You might also like