SCU can be implemented over regular interfaces; it is also used in combination with Layer 3 VPNs. When you view SCU traffic on an ingress PE router, use the standard procedure outlined in Configuring SCU. However, when you enable packet counting for Layer 3 VPNs at the egress point of the MPLS tunnel, you need to take some additional steps.
To configure SCU on the egress router in a Layer 3 VPN, you must configure SCU on the the egress PE router and map the SCU-enabled input interface of that router to the VRF instance. This section contains these configuration procedures, an example, and commands you can issue to verify your work:
SCU over Layer 3 VPNs is not supported when the VRF table label is configured. Also, SCU is not supported over Layer 2 VPNs.