-
Notifications
You must be signed in to change notification settings - Fork 2
mpls
Pre-Alpha. This page describes behavior that may change.
Ze can act as a Linux MPLS label-switching router (LSR). BGP labeled-unicast routes (RFC 8277) received from peers are programmed into the kernel MPLS FIB as label-push entries via netlink lwtunnel, so Ze forwards labeled traffic without VPP.
Labeled-unicast next-hops become label-push entries in the Linux MPLS FIB. Labels are validated as 20-bit values, and the label stack is limited to 16 entries deep. The dataplane is owned by a single producer: fib-kernel. Other control-plane components (BGP labeled-unicast, LDP, RSVP-TE) emit push/swap/pop forwarding entries on the mpls-fib event bus, and fib-kernel programs them into the kernel (IP route plus label for push, AF_MPLS routes for swap/pop). This keeps fib-kernel the single kernel-FIB owner.
BGP labeled-unicast routes (RFC 8277) received from peers carry an MPLS label per prefix. fib-kernel programs each into the Linux MPLS FIB as a label-push entry over the resolved next-hop (an IP route plus the label, via netlink lwtunnel), so Ze forwards labeled traffic without VPP. See Labeled Unicast for the BGP family that feeds these labels.
MPLS label processing is per-interface. Enable it on each interface that should accept labeled packets:
interface {
ethernet eth0 {
unit 0 {
mpls {
enable true
}
}
}
}
This sets net.mpls.conf.eth0.input=1. The global label-table size is governed by the net.mpls.platform_labels sysctl (configure it via the sysctl {} block; it defaults to off, which disables MPLS entirely).
The Linux kernel must have the mpls_router and mpls_iptunnel modules loaded. ze doctor warns (doctor-mpls-unavailable) when they are missing.
ze show mpls forwarding # all installed MPLS entries
ze show mpls forwarding --limit 500 # cap the response size
Each row reports the incoming label (in-label), the operation (swap or pop), any outgoing out-labels, the next-hop, and the egress device. The data is read directly from the kernel AF_MPLS routing table.
| Metric | Meaning |
|---|---|
ze_fibkernel_mpls_routes_installed |
Current MPLS labeled-route count. |
ze_fibkernel_mpls_installs_total |
MPLS routes successfully programmed. |
Two label-distribution protocols are available (both experimental):
- LDP (RFC 5036) for IGP-shortest-path label distribution.
- RSVP-TE (RFC 3209) for traffic-engineered explicit-path LSPs with bandwidth reservation, including RFC 4090 facility-backup fast reroute. See RSVP-TE.
LDP implements UDP multicast Hello discovery, a TCP session FSM, and a label information base of FEC-to-label bindings.
ldp {
lsr-id 10.0.0.1
transport-address 10.0.0.1
interfaces eth0
interfaces eth1
}
| Field | Meaning |
|---|---|
lsr-id |
This router's LSR identifier (IPv4 address format). |
transport-address |
Address advertised for the LDP TCP session. |
interfaces |
One entry per interface on which LDP Hello discovery runs (repeat the leaf for each interface). |
hello-interval / hello-hold-time / keepalive-time
|
Optional soft-state timers (defaults 5s / 15s / 60s). |
Inspect LDP state with show ldp neighbor (session state, transport address) and show ldp binding (FEC-to-label bindings). A label binding learned from a neighbor programs an ingress push entry in the kernel MPLS FIB toward that neighbor.
LDP binds UDP/TCP port 646. ze doctor warns (doctor-ldp-port-unavailable) when the port cannot be bound: it needs CAP_NET_BIND_SERVICE or root, or the port is already in use.
LDP and RSVP-TE are working in the control plane and emit to the mpls-fib bus, but end-to-end and FRR interop validation on a live kernel is still pending. Use for evaluation, not production forwarding.
- RSVP-TE for traffic-engineered explicit-path LSPs.
- FIB for the route-installation pipeline.
- Kernel FIB for the netlink backend that owns the kernel FIB.
- Labeled Unicast for the BGP family that feeds MPLS labels.
- VPP Data Plane for MPLS forwarding on the VPP dataplane.
-
sysctl for tuning
net.mpls.*.
Adapted from main/docs/guide/mpls.md.
Unreviewed draft. This wiki was authored in bulk and has not been reviewed. File corrections on the issue tracker.
- Overview
- YANG Model
- Editor Workflow
- Archive and Rollback
- System
- Interfaces
- VRRP
- BFD
- FIB
- OSPF
- IS-IS
- MPLS / LDP / RSVP-TE
- RSVP-TE
- SRv6
- Static Routes
- Policy Routing
- Firewall
- Traffic Control
- Class of Service
- L2TP/PPP
- PPPoE
- VPP Data Plane
- RPKI
- IPsec VPN
- TACACS+ AAA
- RADIUS AAA
- AS112 DNS
- Authorization
- Fleet
- BGP
- Starting and Stopping
- Show Commands
- Monitoring
- Flow Export
- DDoS Mitigation
- Anomaly Detection
- Health Checks
- Audit Trail
- Production Diagnostics
- Logging
- Operational Reports
- Healthcheck
- Self-Update
- Zero-Touch Provisioning
- MRT Analysis
- Upgrade and Restart
- Storage
- Policy
- Core
- Resilience
- Validation
- Capabilities
- Address Families
- Protocol
- Subsystems
- Infrastructure
- Route Server at an IXP
- Transit Edge with RPKI
- Public Looking Glass
- ExaBGP Migration Walkthrough
- FlowSpec Injection
- Chaos-Tested Peering
- AS Path Topology