MPLS Explained: Label Switching, Header Fields and a Packet Walkthrough
See where an MPLS label comes from, why it changes at each hop, how the shim header is encoded, and when ordinary IP forwarding resumes.
KnowledgeGate Team
Exam prep & CS education

MPLS is often compressed into “routers forward by labels”, hiding where the first label comes from, why it changes at each hop, and when a router examines the IP destination again. An ingress LER classifies a packet into an FEC, control-plane label bindings form an LSP, and the 32-bit shim header carries labels 160 and 240 as the packet crosses provider routers. Transit label lookup is a fixed-width exact match rather than IP longest-prefix matching, but modern IP routers also run at line rate, so MPLS is not a universal speed boost. For prerequisite revision, use CS Fundamentals for Exams & Placements to revisit addressing, forwarding and routing concepts.
Related reading: IP routing algorithms and IPv4 header fields.
MPLS forwarding starts with a FEC and an LSP
Multiprotocol Label Switching places one or more 32-bit labels between the link-layer header and the carried packet. “Multiprotocol” means the operation is not tied to one network-layer payload. “Layer 2.5” is informal placement shorthand, not a formal OSI layer.
An ingress label edge router (LER) classifies a packet into a forwarding equivalence class (FEC). Control-plane label bindings form a one-way label-switched path (LSP). The ingress pushes, transit label switching routers (LSRs) swap, and the penultimate or egress router pops the final transport label. Ordinary IP forwarding then resumes where required. LERs are edge LSRs, not another technology.
Destination 10.20.30.40 belongs to FEC 10.20.30.0/24. Its LSP is R1 -> R2 -> R3 -> R4: ingress R1, transit R2 and R3, then egress R4. The reverse needs its own LSP and may take another path.
The MPLS header is a 32-bit forwarding instruction
The shim header is 20-bit Label | 3-bit TC | 1-bit S | 8-bit TTL. Label selects a local entry, TC carries traffic-class information for policy, S is 1 on the bottom label, and TTL limits forwarding loops.
Encode label 240 as the 20-bit value 0000 0000 0000 1111 0000. With TC = 5 = 101₂, S = 1, and TTL = 61 = 00111101₂, the full word is:
0000 0000 0000 1111 0000 | 101 | 1 | 00111101 = 0x000F0B3D
A stack can place outer transport label 240, S=0 above inner service label 900, S=1. Each entry adds 4 bytes, so two add 8 bytes. The top label is processed first; popping 240 exposes 900, not IP.

MPLS packet walkthrough: push 160, swap to 240, then pop
At R1, an IP packet runs from 192.0.2.10 to 10.20.30.40. The destination matches 10.0.0.0/8, 10.20.0.0/16, and 10.20.30.0/24, but not 10.20.30.128/25, whose last octet spans 128 to 255. Longest-prefix matching chooses FEC 10.20.30.0/24.
Router and lookup | Incoming packet | Matching entry | Action and outgoing packet |
|---|---|---|---|
| IP destination |
| Send |
| Label |
| Swap |
| Label |
| Pop |
| IP destination | Connected or customer route via | Send IP towards the destination network |
R1 performs the IP lookup and pushes 160. R2 swaps it for 240 through Gi0/1. R3 matches 240 and performs penultimate-hop popping. R4 forwards exposed IP through Gi0/2. Alternatively, the egress may receive and pop the label.
Label 160 is meaningful to R2 in this context, while 240 is meaningful to R3. Neither is an end-to-end address; each value may mean something else elsewhere.

MPLS control plane builds state; the data plane executes it
The control plane learns reachability, groups traffic into FECs, exchanges or assigns label bindings, and installs entries. LDP, RSVP-TE and BGP-labelled services are example state-building mechanisms. The data plane executes the installed push, swap or pop per packet.
Table | What it stores |
|---|---|
RIB | Candidate routes learned by the control plane |
FIB | Installed IP forwarding actions |
LIB | Learned label bindings, including those behind the |
LFIB | Installed label actions, such as |
A label alone does not create an LSP. Reachability and label state must agree. A stale or absent LFIB entry cannot be repaired by reading the destination IP at every transit hop.
MPLS versus IP forwarding: what “faster” means
IP forwarding asks which matching destination prefix is most specific. For 10.20.30.40, that means comparing the four routes above and choosing the /24. IP Addressing and Subnetting: Worked Example, Exam Angle develops that longest-prefix reasoning.
An MPLS transit router asks what action belongs to its fixed-width incoming label and interface. Routing or label-distribution mechanisms answer how that state was installed, a distinction explored in Distance Vector vs Link State Routing: Worked Dijkstra.
Mechanism | Question answered |
|---|---|
IP forwarding | Which destination prefix is most specific? |
MPLS forwarding | What action belongs to this incoming label context? |
Control-plane mechanism | How was that forwarding state installed? |
This exact match explains MPLS's association with faster forwarding and predictable treatment. Modern IP hardware can also run longest-prefix matching at line rate. MPLS avoids repeated customer-IP inspection in the provider core and carries policy or service context in a stack.
MPLS use cases and boundaries: paths, services and isolation
Traffic engineering can select an engineered LSP instead of the normal shortest path. Provider VPNs can use outer transport label 240/S=0 over inner service label 900/S=1. TC bits support differentiated handling under provider policy.
A label does not encrypt a payload. MPLS VPN separation is not cryptographic confidentiality, MPLS does not replace the routing control plane, and label values are not globally meaningful. Incorrect state can still fail or loop, which is why MPLS retains a TTL.
The size check is direct: a 1500-byte packet becomes 1504 bytes with one label and 1508 with two. This arithmetic does not promise link acceptance. Path MTU and the complete encapsulation must accommodate the added bytes.
MPLS exam and interview traps
Prompt | Wrong shortcut | Correct answer |
|---|---|---|
Is MPLS an OSI layer? | It is formal Layer 2.5 | “Layer 2.5” is informal placement shorthand |
Does every router read the IP destination? | Yes | Transit LSRs normally act on the top label |
Does one label stay unchanged? | Yes, end to end | Labels are locally significant and may be swapped |
Does | Yes |
|
Does an MPLS VPN encrypt traffic? | Yes | It gives forwarding separation unless encryption is added |
Three closed checks settle the common errors. A: (Gi0/0,160) -> (Gi0/1,240) outputs 240 on Gi0/1. B: popping 240/S=0 from above 900/S=1 exposes 900, not IP. C: 10.20.30.40 selects 10.20.30.0/24 because .40 is outside the /25 range .128 to .255.
For a 45-second answer: define the FEC; name ingress, transit and egress; trace 160 -> 240 -> IP; decode one field; close with the performance nuance. Then practise switching-techniques questions and explain each label action without relying on memorised slogans.
MPLS explained: the short version and next step
Destination
10.20.30.40enters FEC10.20.30.0/24.R1pushes label160.R2swaps160for240.R3pops240.R4forwards the exposed IP packet.
The label is local forwarding state, not a compressed destination address. Use Computer Science Fundamentals for Placements by Sanchit Sir for a broader core-CS study path. If you can already explain the packet walk without notes and want structured interview practice, continue with the Interview & Resume Preparation Course.
Keep learning

Computer Networks Hardware Basics: Devices, Domains and Worked Examples
Learn what hubs, switches, routers, gateways and access points actually do, then count network domains and trace frames through a two-LAN topology.

Data Link Layer Framing Explained: Byte Stuffing, Bit Stuffing and a Cross-Concept Numerical
Frame one four-byte payload in two ways, decode it, and then reuse the verified frame sizes in link-load and Stop-and-Wait calculations.

Byte Stuffing in Computer Networks: Worked Framing Example and Exam Traps
Learn a precise byte-stuffing convention, trace a payload containing both FLAG and ESC, reverse it safely, and calculate frame overhead and transmission time.

Go-Back-N Protocol Explained: Sliding Windows, Worked Numericals and Exam Traps
Trace Go-Back-N through a lost frame, calculate its legal window and link utilisation, and avoid the ACK and wrap-around traps that spoil numericals.