Courseiva
mediumMultiple Choice

350-401 Practice Question: An engineer is designing an MPLS L3VPN service…

An engineer is designing an MPLS L3VPN service for a customer that requires overlapping IP addresses between two sites. The customer uses OSPF as the PE-CE protocol. The engineer configures VRFs on the PE routers and assigns unique route distinguishers (RDs) and route targets (RTs). However, the customer reports that routes from one site are not being installed in the other site's VRF. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates confuse the role of route distinguishers (RDs) with route targets (RTs), thinking that unique RDs are sufficient for route exchange, when in fact RTs control the import/export policy between VRFs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The route-target export on PE1 does not match the route-target import on PE2.

In MPLS L3VPN, route targets (RTs) control the import and export of VPN routes between VRFs. For routes from one site to be installed in another site's VRF, the route-target export on the exporting PE must match the route-target import on the importing PE. If they do not match, the routes are not imported, even if route distinguishers (RDs) are unique and OSPF is properly configured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The route-target export on PE1 does not match the route-target import on PE2.

    Why this is correct

    In MPLS L3VPN, route targets (RTs) are BGP extended communities that control the redistribution of VPN routes between VRFs. The exporting PE attaches an export RT to a VPNv4 route; the importing PE only places that route into a VRF if the route's RT matches the VRF's import RT. In this scenario, PE1's export RT does not match PE2's import RT, so even though the VPNv4 route reaches PE2 via BGP, it is not installed in the VRF routing table, leaving the prefix unreachable.

  • ✗

    The overlapping IP addresses cause a routing loop in OSPF.

    Why it's wrong here

    Overlapping IP addresses cannot cause an OSPF loop because each VRF runs its own isolated OSPF instance with a separate routing table and link-state database. The PE maintains completely independent forwarding contexts per VRF, and routes learned in one VRF are never redistributed into another by OSPF. Since OSPF's SPF algorithm computes routes within a single VRF's topology, a duplicate prefix in another VRF is simply not visible to that instance, so no loop path can form.

  • ✗

    OSPF cannot carry overlapping prefixes in different VRFs.

    Why it's wrong here

    OSPF is designed to run multiple independent processes or instances, and each VRF can have its own OSPF process with its own interface associations, router ID, and LSDB. There is no protocol restriction preventing overlapping prefixes in different VRFs; in fact, that is a primary use case for MPLS L3VPN, where many customers reuse the same RFC 1918 space. The PE simply associates each OSPF process with a VRF, and the separate routing tables keep the overlapping prefixes fully isolated.

  • ✗

    The route distinguisher is not unique between the two sites.

    Why it's wrong here

    The route distinguisher (RD) only needs to be unique within a single PE; it does not have to be globally unique across different PEs or sites. The RD is prepended to the IPv4 prefix to create a VPNv4 address, and because it is part of the address itself, reuse of the same RD at another site is harmless—the routes are still distinct entries in the BGP VPNv4 table. The actual decision to import a VPNv4 route into a VRF is made based on RT matching, not RD matching, so an RD mismatch is never the reason for a missing route.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.