MPLS L3VPNs

Discovered MPLS L3VPNs (RFC 4364), rolled up from per-PE VRFs walked from the MPLS-L3VPN-STD-MIB (RFC 4382) by the SNMP poller and written directly to the store. A VRF is one PE's view of a VPN; an L3VPN is a route-target equivalence class of VRFs spanning one or more PE sites (computed server-side, with full-mesh vs hub-and-spoke classified from the import/export route-targets). Read-only โ€” there is no create/update/delete surface. Scoped per network.

Auth: All roles (admin, engineer, operator). Read-only observed state; license state never gates reads.

List L3VPN VRFs

GET /api/v1/networks/{networkID}/l3vpn/vrfs

Flat per-PE VRF observations for a network.

Query parameters:

Response: 200 OK (paginated envelope)

{
  "data": [
    {
      "id": "uuid",
      "network_id": "uuid",
      "area_id": "uuid",
      "device_id": "uuid",
      "vrf_name": "RED",
      "rd": "65000:1001",
      "description": "",
      "oper_status": 1,
      "admin_status": 1,
      "active_interfaces": 1,
      "associated_interfaces": 1,
      "route_count": 12,
      "first_seen": "2026-07-05T12:00:00Z",
      "last_seen": "2026-07-05T12:05:00Z",
      "updated_at": "2026-07-05T12:05:00Z"
    }
  ],
  "total": 1,
  "limit": 100,
  "offset": 0
}

oper_status / admin_status per RFC 4382; route_count is omitted when the agent lacks the perf table (e.g. Cisco IOL). area_id is omitted when unresolved. The flat list does not attach route_targets โ€” use the by-id endpoint. Data is [] (not null) when empty.

Error responses:


List L3VPNs

GET /api/v1/networks/{networkID}/l3vpns

VRFs rolled up into L3VPNs by route-target equivalence class. No query parameters; returns a plain JSON array (not the paginated envelope).

Response: 200 OK

[
  {
    "name": "RED",
    "topology": "mesh",
    "route_targets": ["65000:100"],
    "site_count": 3,
    "total_routes": 36,
    "oper_status": 1,
    "sites": [
      {
        "device_id": "uuid",
        "vrf_name": "RED",
        "rd": "65000:1001",
        "role": "mesh",
        "oper_status": 1,
        "route_count": 12
      }
    ]
  }
]

topology is mesh (every site imports exactly what it exports) or hub-spoke (asymmetric RTs); each site's role is mesh, hub, or spoke. oper_status is the worst across sites (2 = at least one site down). total_routes / route_count are omitted when no site reports a route count. The array is [] when empty.


Get L3VPN VRF

GET /api/v1/l3vpn/vrfs/{id}

Returns a single VRF row by ID with its route_targets array attached (each {rt_value, rt_type, address_family}; rt_type {import=1, export=2, both=3}).

Error responses: