What Is the Function of Penultimate Hop Popping (PHP)?

Answer Correct answer: A — The last P router, the penultimate LSR, pops the transport label so the egress PE receives only the VPN label and needs one LFIB lookup.

What is the function of penultimate hop popping?

  1. The last P router in the path pops off the transport label before traffic is forwarded toward the PE. Correct Answer
  2. The VPN label is popped off at the egress LSR, and unlabeled traffic is forwarded toward the CE.
  3. The transport label is popped off at the egress LSR, and unlabeled traffic is forwarded toward the CE.
  4. The second to last P router in the path pops off the VPN label before traffic is forwarded to the last P router.

Community Votes

A
80%
C
20%

80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you know which router pops which label — PHP means the penultimate LSR (the last P router) pops the outer transport label, and the trap is confusing that with the egress PE popping the VPN label.

Penultimate hop popping (PHP) is an MPLS mechanism in which the last P router in the LSP pops the transport label so the egress PE receives only the VPN label. This page confirms option A is the correct description of PHP and explains why the egress-LSR and VPN-label variations are wrong.

The most common wrong pick is C, which moves the transport-label pop to the egress LSR; that describes the non-PHP (explicit-null) behavior and forces the egress PE to perform two LFIB lookups instead of one.

Community Discussion (4 comments)

Sammy3637 👍 1 Selected: C
In Penultimate Hop Popping (PHP), the penultimate router (the second-to-last router in the path) removes (or "pops off") the MPLS transport label, not the last router (which is the egress LSR). The last P router (egress LSR) simply forwards the unlabeled packet to the Customer Edge (CE) router, without performing any label operations.
vallzo 👍 4
A is correct. This way the PE receives a packet without the LDP label, and doesn't have to do an extra lookup in the LFIB before forwarding the packet to a non-MPLS router like CE.
dapardo 👍 2 Selected: A
its A: PHP can be performed in frame-based MPLS networks. In these networks, the last P router in the LSP tunnel pops the LDP label as previously requested by the egress PE router through LDP. So, the PE router receives a labeled packet that contains only the VPN label.
d740f62 👍 1 Selected: A
Correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In an MPLS L3VPN path such as CE1-PE1-P1-P2-PE2-CE2, the egress PE2 advertises the implicit-null label through LDP, telling its upstream neighbor P2 to pop the transport (LDP/IGP) label. P2 is the last P router in the path and is by definition the penultimate LSR relative to the egress PE, which is exactly what option A describes: the last P router pops the transport label before forwarding toward the PE. The packet that arrives at PE2 still carries the VPN label, so PE2 performs a single LFIB lookup to identify the VRF and forward toward the CE. This is the operational purpose of PHP: it removes one label lookup from the egress PE and saves processing on the edge router.

Why the Other Options Are Wrong

Option C inverts the roles by saying the transport label is popped at the egress LSR, which is the behavior you get when PHP is disabled (explicit-null), not PHP. Option B is simply a description of ordinary forwarding at the egress PE — the PE does remove the VPN label before sending unlabeled frames to the CE — but that is not what penultimate hop popping does, and mislabeling it as the function of PHP makes it incorrect. Option D claims the second-to-last P router pops the VPN label, which is wrong on two counts: PHP always targets the outer transport label, and the VPN label is only swapped or removed by the egress PE2, never by a P router. Only A names the right router (the last P router) and the right label (the transport label).

Community Comment Notes

As vallzo puts it, PHP means the PE receives a packet without the LDP label, so it "doesn't have to do an extra lookup in the LFIB" before forwarding toward a non-MPLS CE — a clean statement of the efficiency rationale. dapardo adds the mechanics, noting that in frame-based MPLS the last P router pops the LDP label because the egress PE requested it through LDP, so the PE gets a packet carrying only the VPN label. Sammy3637 voted C, but interestingly his own explanation describes the penultimate router removing the transport label — evidence of how the wording trips people up, since his stated mechanism actually matches A. d740f62 simply marked A as correct, consistent with the 80-to-20 vote split in favor of the suggested answer.

Official Reference

Exam Strategy

Anchor on two keywords in the stem: "penultimate" (the second-to-last router, i.e. the last P before the PE) and "transport label" (the outer LDP/IGP label, not the VPN label). Any option that pops the VPN label or moves the pop to the egress LSR is describing a different mechanism and can be eliminated immediately.

Frequently Asked Questions

Does PHP pop the transport label or the VPN label?

PHP pops the outer transport (LDP/IGP) label at the penultimate LSR. The VPN label survives until the egress PE, which uses it to select the VRF and forward toward the CE.

Why is option C wrong if the egress LSR also removes labels?

C describes the egress LSR popping the transport label, which is the explicit-null behavior when PHP is disabled, not the function of penultimate hop popping.

More 300-410 FAQ →

Related Analysis

Practice All 300-410 Questions

Access 159 questions with complete answers and detailed explanations.

View Full 300-410 Practice Test →

← Back to 300-410 Study Guide