MPLS VPN
Carrier-isolated private WAN — isolated, but not encrypted.
How widely is it used?
Still around, but being replacedLarge installed base, shrinking fast as contracts move to SD-WAN.
How it works
The provider tags customer traffic with MPLS labels and keeps routes in per-customer VRFs, so networks stay separated inside the provider core without any tunnel on your side.
Connects
Private enterprise networks
Protocols
MPLS, BGP, VRF
Typical users
Enterprises, Telecom customers
Main use case
Predictable, SLA-backed private WAN connectivity.
Advantages
- Consistent latency and guaranteed bandwidth
- Provider-managed
Limitations
- Traffic is isolated but not encrypted — add IPsec if confidentiality matters
- Expensive and slow to provision
Not safe on its own
This technology isolates traffic but does not encrypt it. Run IPsec or WireGuard on top if confidentiality matters.
Related VPN types
SD-WAN
Software picks the path; encrypted overlays ride on top.
Generate configIntranet VPN
Site-to-site links between networks owned by the same organisation.
Generate configVPLS / Layer-2 VPN
Remote sites share one broadcast domain as if on the same switch.
Generate config