Courseiva
hardMultiple Choice

300-410 Practice Question: Is troubleshooting an MPLS L3VPN where CE1…

A network engineer is troubleshooting an MPLS L3VPN where CE1 (10.1.1.0/24) cannot reach CE2 (10.2.2.0/24). The PE routers are using eBGP with the CEs. On PE1, the show ip bgp vpnv4 vrf CUSTOMER command shows the route for 10.2.2.0/24 with a next-hop of 192.168.1.2, and the show ip route vrf CUSTOMER command shows the route. However, traffic from CE1 to CE2 fails. The show ip bgp vpnv4 vrf CUSTOMER 10.2.2.0/24 command on PE1 shows the route is received and best, but the show ip bgp vpnv4 vrf CUSTOMER 10.2.2.0/24 command on PE1 also shows the route has the 'r' flag (RIB-failure). What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

There is a static route in the VRF for 10.2.2.0/24 with a lower administrative distance.

A RIB-failure indicates that the route is received and best in BGP but is not installed in the routing table because another route with a lower administrative distance exists. This could be due to a static route or an IGP route for the same prefix in the VRF.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    There is a static route in the VRF for 10.2.2.0/24 with a lower administrative distance.

    Why this is correct

    The 'r' flag means BGP selected the prefix as best but failed to install it in the VRF routing table. A static route with a lower administrative distance already occupies that prefix, so the BGP path is rejected despite being valid.

  • ✗

    The route-target import on PE1 is misconfigured.

    Why it's wrong here

    A wrong import route-target would stop the VPNv4 prefix entering the VRF table entirely, so it would not appear as best in the BGP table. Import route-targets are tuned when you need to control which VPN communities a VRF accepts.

  • ✗

    The MP-BGP session is not using the loopback interface.

    Why it's wrong here

    The 'r' flag denotes RIB-failure, meaning BGP could not install the prefix into the VRF routing table; MP-BGP peering over a loopback affects session stability, not RIB installation. Loopback sourcing is chosen when you need a peering address that survives interface failures.

  • ✗

    The VRF on PE1 has a different route-target export.

    Why it's wrong here

    A mismatched export route-target would prevent the prefix arriving at PE1 at all, yet the route shows as received and best. Route-target export is configured correctly when you want a VRF's prefixes advertised into a particular VPN community.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.