Which Tag Sends MPLS L3VPN Packets to the Correct Customer VRF?

Describe MPLS Layer 3 VPN Describe MPLS operations (LSR, LDP, label switching, LSP)
Answer Correct answer: C — The route target (RT) extended community tags VPNv4 routes so each PE imports them into the correct customer VRF; the RD only makes prefixes unique.

Which tag is used by the PE router to forward the packet to the correct customer?

  1. RD
  2. extended-community
  3. RT Correct Answer
  4. VNI

Community Votes

C
75%
A
25%

75% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the RD-versus-RT distinction in MPLS L3VPN: RT tags VPN membership so the PE installs the customer's routes in the right VRF, while the RD only makes overlapping prefixes unique — the trap is picking RD because it also looks like a VRF identifier.

In an MPLS Layer 3 VPN, the route target (RT) extended community is the tag that identifies a customer's VPN membership and drives route import into the correct VRF. This page shows why RT (C) beats the RD, a generic extended community, and a VXLAN VNI on this 300-410 question.

Picking RD (A), as roughly a quarter of voters did, because the route distinguisher is prepended to the customer prefix and is associated with a VRF; but the RD's only job is to make identical IPv4 prefixes unique in the VPNv4 table — it does not decide which customer receives the routes or the traffic.

Community Discussion (5 comments)

9410480 👍 1 Selected: A
Route Targets are not appended to the packet or "tagged" like an RD prefix is. Because of that, I'm going with A (RD). The answer should really be VPN label, but RD is the closest.
bb90403 👍 1 Selected: C
Correct answer is C
[Removed] 👍 4 Selected: C
C is correct RTs are used to control the import and export of routes in a VRF. When the route is received on another PE router, the RT value is examined to determine which VRFs should import the route. https://forum.networklessons.com/t/route-targets-and-route-distinguishers-mpls-l3-vpns/39562#:~:text=RTs%20are%20used%20to%20control%20which%20routes%20are%20imported%20and%20exported%20from%20a%20VRF.%20When%20a%20route%20is%20exported%20from%20a%20VRF%2C%20the%20RT%20value%20is%20added%20to%20the%20route%20as%20a%20BGP%20extended%20community.%20When%20the%20route%20is%20received%20on%20another%20PE%20router%2C%20the%20RT%20value%20is%20examined%20to%20determine%20which%20VRFs%20should%20import%20the%20route.
Pietjeplukgeluk 👍 4 Selected: C
I feel the answer is RT, however, the question is in bad english and if you read it often enough their is no good answer at all.
d740f62 👍 2 Selected: A
Correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The route target is a BGP extended community that a PE attaches to every VPNv4 route it advertises out of a VRF. On the receiving PE, each VRF is configured with import RTs (and export RTs on the originating side), and MP-BGP installs a VPNv4 prefix into a VRF only when the RT carried in the update matches that VRF's import RT; the prefix then arrives together with the VPN label that the egress PE assigned to it. That RT match is what binds a specific customer's routes — and therefore that customer's forwarded traffic — to the correct VRF, which is why RT is the tag this question is after. The RD, in contrast, is only a prefix modifier: it is prepended to the IPv4 NLRI to make otherwise identical customer prefixes unique in the VPNv4 table, and it plays no part in choosing which customer VRF a route is delivered into. Of the four listed items, C is the only one that performs customer/VPN membership tagging.

Why the Other Options Are Wrong

A (RD) is the strongest distractor because a route distinguisher also "identifies" a VRF in local configuration terms, but it exists purely to disambiguate overlapping IPv4 prefixes inside VPNv4 NLRI — the remote PE never compares an RD against import policy to decide the customer. B (extended-community) is not wrong in the way A or D are, because RT is a type of extended community, but it is the generic attribute family rather than the specific community used for VPN membership, so it fails in a single-best-answer question. D (VNI) is a VXLAN construct, where a 24-bit VNI identifies a VXLAN segment; VXLAN has nothing to do with MPLS L3VPN route tagging. It is also worth knowing that the data-plane label that actually carries customer separation across the MPLS core is the inner VPN label, which is not among the choices — the exam here is asking about the control-plane VPN membership tag, and that is the RT.

Community Comment Notes

Several voters landed on C, and one summarized the doctrine almost verbatim: "RTs are used to control the import and export of routes in a VRF". Pietjeplukgeluk also selected RT but flagged the wording, saying "I feel the answer is RT, however, the question is in bad english and if you read it often enough their is no good answer at all", which is a fair warning that the stem is loosely written. A dissenting voter argued the data-plane truth: "The answer should really be VPN label, but RD is the closest" — correct about the forwarding label, but choosing RD because the better answer is absent is exactly the trap this question sets. The anonymous vote split (roughly three to one for RT over RD) matches the control-plane framing that Cisco expects here.

Official Reference

Exam Strategy

When both RD and RT appear as options, classify them before reading the rest of the stem: RD = unique VPNv4 prefix, RT = VPN membership plus import/export policy. Words such as "customer", "VRF", or "import" point to RT, while "overlapping addresses", "unique prefix", or "BGP next hop" point to RD. If a stem ever asks about the labels on the wire, the real answer is the inner VPN label, but select RT when no label choice is offered.

Frequently Asked Questions

Why is the RD not the tag that selects the customer VRF on the receiving PE?

The RD is prepended to the IPv4 prefix only to create a unique VPNv4 NLRI. It never drives which VRF receives the route — the route target's import/export matching does that.

Is the RT or the VPN label used to forward packets to the customer?

The RT is the control-plane tag that imports routes into a VRF; the inner VPN label actually forwards the data. Only the RT is offered among these answer choices.

Related Analysis

Practice All 300-410 Questions

Access 159 questions with complete answers and detailed explanations.

View Full 300-410 Practice Test →

← Back to 300-410 Study Guide