MPLS Layer-3 VPNs provide IP connectivity among CE sites MPLS VPNs enable full-mesh, hub-and-spoke, and hybrid IP connectivity CE sites connect to the MPLS network via IP peering across PE-CE links MPLS Layer-3 VPNs are implemented via VRFs on PE edge nodes VRFs providing customer routing and forwarding segmentation BGP used for signaling customer VPN (VPNv4) routes between PE nodes To ensure traffic separation, customer traffic is encapsulated in an additional VPN label when forwarded in MPLS network Key applications are layer-3 business VPN services, enterprise network segmentation, and segmented layer-3 Data Center access Reference: https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2018/pdf/BRKMPL-1100.pdf