Under attack?
Layer 2 Ethernet

Your frames arrive the way you sent them

Transparent Ethernet between our European sites over EVPN-MPLS - tags intact, MTU intact, no addressing or routing decisions in between. What runs inside the circuit is entirely yours.

The pipe

Transparent, and none of our business

A Layer 2 service from us is a transparent pipe between ports on our network. We do not look inside it, we do not learn anything from it that we need to tell you about, and we do not renumber anything at either end.

circuit · evpl-0142
> show l2circuit customer-a
encap      dot1q + QinQ transparent
your vlans 1-4094  untouched
your macs  learned in control plane
# we carry frames; what they mean is yours
One fabric

The control plane the IP network already trusts

EVPN-MPLS carries these circuits over the same backbone as the IP services - the same diverse paths, the same capacity planning. It is also why a multipoint service gains a site without touching the endpoints that are already up: MAC learning lives in the control plane, not flooded across the fabric.

E-LINEtwo ports, one circuit (EVPL)
E-LANany-to-any, one broadcast domain
E-TREEspokes reach the hub, never each other
Failure

Protection is stated, not implied

Where a route has physical diversity we deliver the circuit protected. Where it does not, we say so before you order - and you decide whether your own equipment should handle failover instead.

<50 ms“carrier grade”, unspecified protection switching, where the route is physically diverse

Three shapes, one platform

E-Line · point to point

Two endpoints, one transparent circuit

The simplest service and where most customers start, whether it carries replication, a peering handoff or an internal VLAN stretched between two of your own rooms. Delivered as EVPL.

E-LAN · any to any

One broadcast domain shared by every site

Every location on the service sees every other. Add a site later and it joins the existing domain without a change on the endpoints that are already up. Delivered as EVPN.

E-Tree · hub and spoke

Spokes reach the hub, not each other

Rooted multipoint, which is what you want when aggregating branch or customer traffic into one core site and those spokes have no business talking directly. Delivered as EVPN.

Speeds1G-400GRates may differ per endpoint
MTU9000Jumbo frames, subject to the path
Protection<50 msOn routes with diverse paths
Reach10 sitesAny pair or any group across Europe

Technical detail

Service types
EVPL point to point; EVPN for any-to-any and rooted multipoint; VPLS where a customer’s existing design requires it.
Port speeds
1G, 10G, 25G, 100G and 400G, with the committed rate policed below port speed if you want it.
Encapsulation
Dot1Q and QinQ (802.1ad) with transparent tag handling; VXLAN hand-off in selected domains.
MTU
Up to 9000 bytes end to end, path dependent and confirmed before turn-up rather than assumed.
Protection
1+1 or 1:1 with sub-50 ms switching where physical diversity exists on the route.
MAC learning
Per service instance in the EVPN control plane, so a new site does not flood the existing ones.
OAM
Y.1731 and 802.1ag, with per-circuit graphs available to you.
Optics
SFP+, SFP28, QSFP28 and QSFP-DD; 10GBASE-LR, 100GBASE-LR4, 400G LR4.
Handoff
Single-mode LC at any of our sites, cross connect arranged by us.

Typical builds

The same fabric carries our own filtering. Every scrubbing cluster, every span between sites and every customer circuit rides the same EVPN-MPLS core. That is not a coincidence of design - it is why a link, a line card or a whole node failing is a re-convergence rather than an outage, for your traffic exactly as much as for ours.
In combination

Circuits keep good company

Most Layer 2 customers hold at least one of these beside the circuit - the combinations below are the ones that actually happen.

Optical

Outgrow the circuit, keep the route

When the E-Line is permanently full, the same corridor sells as a dedicated wavelength - your own channel, same endpoints, no re-engineering of the path. DWDM wavelengths →

IP transit

Internet at either end

A circuit between two sites plus transit at one or both of them - delivered on the same physical handoff, with the DDoS filter in front of every announced prefix. Protected IP transit →

Protection

The DR site inherits the filter

Replication rides the circuit; the public faces of both sites sit behind the same mitigation. One attack cannot follow your failover, because both ends were protected before it started. DDoS protection →

Frequently asked

Is the circuit really transparent?

Your VLAN tags survive untouched (dot1q and QinQ), your MACs are learned in the control plane rather than flooded, and we neither inspect nor renumber anything. We carry frames; what they mean is yours.

What MTU can I get?

Up to 9000 bytes end to end - path dependent, and confirmed before turn-up rather than assumed, because a jumbo circuit that silently fragments is worse than an honest 1500.

Can a multipoint service grow without downtime?

Yes - E-LAN and E-Tree run on EVPN, so a new site joins the existing domain without touching the endpoints that are already up.

What protection does the circuit get?

Sub-50 ms switching where the route has physical diversity; stated plainly where it does not, so you can decide if your own equipment should handle failover.

Can I monitor it myself?

Y.1731 and 802.1ag OAM, with per-circuit graphs visible to you - the same telemetry we watch, not a monthly PDF.