Courseiva
Layer 3 Technologies →mediumMultiple Choice

300-410 Layer 3 Technologies Practice Question

A network engineer is deploying MPLS Layer 3 VPNs. The engineer must ensure that the PE routers can forward VPN traffic correctly. The following configuration is applied on a PE router:

ip vrf CUSTOMER

rd 65000:1 route-target export 65000:1 route-target import 65000:1 !

interface GigabitEthernet0/1
 ip vrf forwarding CUSTOMER
 ip address 192.168.1.1 255.255.255.0

After configuration, the engineer notices that the CE router cannot reach remote sites. The MPLS core is operational, and MP-BGP is configured. What is the most likely missing configuration?

⚠ Common exam trap

The trap here is focusing on the VRF and interface configuration while overlooking the need for a BGP address-family per VRF to exchange VPN routes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The BGP process must be configured with address-family ipv4 vrf CUSTOMER and the necessary redistribution or network statements.

In MPLS L3 VPN, the PE router must have a BGP address-family ipv4 vrf for each VRF to exchange VPN routes with other PE routers. The VRF definition and interface assignment are necessary but not sufficient. Without the address-family configuration and route redistribution or network statements, the PE will not advertise the customer routes, and remote sites will be unreachable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The route-target must be configured under the interface GigabitEthernet0/1.

    Why it's wrong here

    Route targets are configured under the VRF definition, not on the interface. The interface only needs ip vrf forwarding to associate the interface with the VRF. The missing configuration is the BGP address-family for the VRF.

  • ✗

    The PE router must have a route distinguisher configured under the BGP process.

    Why it's wrong here

    The route distinguisher is configured under the VRF definition, not under the BGP process. It is already present as rd 65000:1. The missing piece is not related to the RD; it is the lack of a loopback interface for BGP peering.

  • ✗

    The PE router must have a loopback interface configured and used for BGP peering.

    Why it's wrong here

    While a loopback interface is recommended for BGP peering stability, its absence alone would not prevent VPN traffic forwarding if BGP peering is established via physical interfaces. The more critical missing configuration is the address-family ipv4 vrf under BGP.

  • ✓

    The BGP process must be configured with address-family ipv4 vrf CUSTOMER and the necessary redistribution or network statements.

    Why this is correct

    For MPLS L3 VPN, the PE router must have a BGP address-family for each VRF to exchange routes with other PEs. Without address-family ipv4 vrf CUSTOMER, the PE will not advertise or receive VPN routes for that customer, preventing connectivity. The VRF configuration alone is insufficient.

Go deeper

Related to this question

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.