Courseiva
mediumMultiple Choice

MPLS L3VPN: Troubleshooting VRF Route Advertisement to BGP

A network engineer is configuring MPLS L3VPN on a Cisco IOS-XE PE router. The engineer creates a VRF named CUSTOMER_A with route-target import and export 100:1. After configuring the VRF on the interface connected to the CE router, the CE router can ping the PE's VRF interface IP, but cannot reach any remote VPNv4 routes. The BGP session between PE and route reflector is up. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that a working BGP session to the route reflector and correct route-target values alone are sufficient for VPNv4 route exchange, when in fact the VRF must be explicitly activated under BGP to enable route advertisement and import.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The VRF is not activated under BGP using the address-family ipv4 vrf CUSTOMER_A command.

The CE router can ping the PE's VRF interface IP, confirming Layer 2 and VRF interface configuration are correct. However, the CE cannot reach remote VPNv4 routes, which indicates that the PE is not advertising or installing those routes into the VRF. The most likely cause is that the VRF CUSTOMER_A has not been activated under BGP using the 'address-family ipv4 vrf CUSTOMER_A' command, which is required to exchange IPv4 routes between the PE and CE within the VRF context and to redistribute them into MP-BGP for VPNv4 propagation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The route-target import/export values are mismatched with the route reflector's configuration.

    Why it's wrong here

    Route-target values determine which VPNv4 routes a PE imports into a VRF and which routes it exports from that VRF; they are not evaluated by route reflectors. A route reflector simply re-advertises VPNv4 NLRIs it receives, leaving RT filtering to the edge PEs. Therefore mismatched RTs cannot explain why the CE sees local connectivity but no remote routes, because the real fault is that the VRF is never activated in BGP at all.

  • ✓

    The VRF is not activated under BGP using the address-family ipv4 vrf CUSTOMER_A command.

    Why this is correct

    Without the address-family ipv4 vrf CUSTOMER_A command under BGP, the PE does not establish an internal BGP session for that VRF nor inject connected/static routes into VPNv4. This means no VPNv4 routes are generated for CUSTOMER_A, and no remote VPNv4 routes are imported into the VRF, so only the directly connected CE subnet is reachable. Activating the VRF in BGP is the mandatory prerequisite for inter-site route exchange in MPLS Layer 3 VPN.

  • ✗

    The CE router is not configured with a default route pointing to the PE.

    Why it's wrong here

    The CE's ability to ping the PE's VRF interface proves IP connectivity on the local link, so the absence of a default route is not the immediate cause of failure. A default route only dictates where the CE sends packets for off-subnet destinations, and if the PE has not learned or advertised remote routes, a default route on the CE still would not make those routes appear. The root problem is on the PE's BGP VRF activation, not the CE's routing table.

  • ✗

    The PE router needs the mpls ip command on the interface facing the CE router.

    Why it's wrong here

    MPLS labels are imposed and disposed on core-facing interfaces, where the label-switched path transports VPNv4 packets across the service provider backbone. The CE-facing interface is an IPv4 edge link, and enabling mpls ip there would not affect how VRF routes are exchanged with the CE. Since the fault is missing remote route reachability, the lack of mpls ip on the CE interface is irrelevant to the BGP VRF activation issue.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.