Re: [Idr] draft-uttaro-idr-bgp-persistence-00

"UTTARO, JAMES" <> Wed, 26 October 2011 16:44 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 826D921F8B70 for <>; Wed, 26 Oct 2011 09:44:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -105.399
X-Spam-Status: No, score=-105.399 tagged_above=-999 required=5 tests=[AWL=0.600, BAYES_00=-2.599, J_CHICKENPOX_13=0.6, RCVD_IN_DNSWL_MED=-4, USER_IN_WHITELIST=-100]
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id nklvSNVKDYVa for <>; Wed, 26 Oct 2011 09:44:38 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id A035521F8B6B for <>; Wed, 26 Oct 2011 09:44:38 -0700 (PDT)
X-Originating-IP: []
X-StarScan-Version: 6.3.6; banners=-,-,-
X-VirusChecked: Checked
Received: (qmail 11716 invoked from network); 26 Oct 2011 16:44:35 -0000
Received: from (HELO ( by with DHE-RSA-AES256-SHA encrypted SMTP; 26 Oct 2011 16:44:35 -0000
Received: from (localhost.localdomain []) by (8.14.4/8.14.4) with ESMTP id p9QGj1qC013602; Wed, 26 Oct 2011 12:45:02 -0400
Received: from ( []) by (8.14.4/8.14.4) with ESMTP id p9QGj1tu013595 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Wed, 26 Oct 2011 12:45:01 -0400
Received: from ([]) by ([]) with mapi id 14.01.0339.001; Wed, 26 Oct 2011 12:44:33 -0400
From: "UTTARO, JAMES" <>
To: "" <>, " List" <>
Thread-Topic: [Idr] draft-uttaro-idr-bgp-persistence-00
Thread-Index: AQHMkEAnLP0iAkRlVkChUYWtkZqOMZWKuQoAgAQhplA=
Date: Wed, 26 Oct 2011 16:44:33 +0000
Message-ID: <>
References: <> <>
In-Reply-To: <>
Accept-Language: en-US
Content-Language: en-US
x-originating-ip: []
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: Re: [Idr] draft-uttaro-idr-bgp-persistence-00
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Inter-Domain Routing <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 26 Oct 2011 16:44:39 -0000


	The introduction of this technology needs to be carefully evaluated when being deployed into the network. Your example clearly calls out how a series of independent design can culminate in incorrect behavior. Certainly the deployment of persistence on a router that has interaction with a router that does not needs to be clearly understood by the network designer. The goal of this draft is to provide a fairly sophisticated tool that will protect the majority of customers in the event of a catastrophic failure.. The premise being the perfect is not the enemy of the good.. I will add text in the deployment considerations section to better articulate that..

	Jim Uttaro

-----Original Message-----
From: [] On Behalf Of Robert Raszuk
Sent: Sunday, October 23, 2011 5:32 PM
To: List
Subject: [Idr] draft-uttaro-idr-bgp-persistence-00


Actually when discussing this draft a new concern surfaced which I would 
like to get your answer on.

The draft in section 4.2 says as one of the forwarding rules:

    o  Forwarding to a "stale" route is only used if there are no other
       paths available to that route.  In other words an active path
       always wins regardless of path selection.  "Stale" state is always
       considered to be less preferred when compared with an active path.

In the light of the above rule let's consider a very simple case of dual 
PE attached site of L3VPN service. Two CEs would inject into their IBGP 
mesh routes to the remote destination: one marked as STALE and  one not 
marked at all. (Each CE is connected to different PE and each PE RT 
imports only a single route to a remote hub headquarter to support 
geographic load balancing).

Let me illustrate:

  VPN Customer HUB

    PE3      PE4
    PE1      PE2
     |        |
     |        |
    CE1      CE2
     |        |
    1|        |10
     |        |
    R1 ------ R2

CE1,CE2,R1,R2 are in IBGP mesh. IGP metric of CE1-R1 and R1-R2 are 1 and 
R2-CE2 is 10.

Prefix X is advertised by remote hub in the given VPN such that PE1 vrf 
towards CE1 only has X via PE3 and PE2's vrf towards CE2 only has X via PE4.

Let's assume EBGP sessions PE3 to HUB went down, but ethernet link is 
up, next hop is in the RIB while data plane is gone. Assume no data 
plane real validation too. /* That is why in my former message I 
suggested that data plane validation would be necessary */.

R1 has X via PE1/S (stale) and X via PE2/A (active) - it understands 
STALE so selects in his forwarding table path via CE2.

R2 has X via PE1/S (stale) and X via PE2/A (active) - it does not 
understand STALE, never was upgraded to support the forwarding rule 
stated above in the draft and chooses X via CE1 (NH metric 2 vs 10).

R1--R2 produce data plane loop as long as STALE paths are present in the 
system. Quite fun to troubleshoot too as the issue of PE3 injecting such 
STALE paths may be on the opposite site of the world.

The issue occurs when some routers within the customer site will be able 
to recognize STALE transitive community and prefer non stale paths in 
their forwarding planes (or BGP planes for that matter) while others 
will not as well as when both stale and non stale paths will be present.

Question 1: How do you prevent forwarding loop in such case ?

Question 2: How do you prevent forwarding loop in the case when customer 
would have backup connectivity to his sites or connectivity via 
different VPN provider yet routers in his site only partially understand 
the STALE community and only partially follow the forwarding rules ?

In general as the rule is about mandating some particular order of path 
forwarding selection what is the mechanism in distributed systems like 
today's routing to be able to achieve any assurance that such rule is 
active and enforced across _all_ routers behind EBGP PE-CE L3VPN 
boundaries in customer sites ?

Best regards,

-------- Original Message --------
Subject: [Idr] draft-uttaro-idr-bgp-persistence-00
Date: Sat, 22 Oct 2011 00:23:55 +0200
From: Robert Raszuk <>
To: List <>


I have read the draft and have one question and one observation.


What is the point of defining DO_NOT_PERSIST community ? In other words
why not having PERSIST community set would not mean the same as having
path marked with DO_NOT_PERSIST.


I found the below statement in section 4.2:

    o  Forwarding must ensure that the Next Hop to a "stale" route is

Of course I agree. But since we stating obvious in the forwarding
section I think it would be good to explicitly also state this in the
best path selection that next hop to STALE best path must be valid.

However sessions especially those between loopbacks do not go down for
no reason. Most likely there is network problem which may have caused
those sessions to go down. It is therefor likely that LDP session went
also down between any of the LSRs in the data path and that in spite of
having the paths in BGP and next hops in IGP the LSP required for both
quoted L2/L3VPN applications is broken. That may particularly happen
when network chooses to use independent control mode for label allocation.

I would suggest to at least add the recommendation statement to the
document that during best path selection especially for stale paths a
validity of required forwarding paradigm to next hop of stale paths
should be verified.

For example using techniques as described in:

Best regards,

Idr mailing list

Idr mailing list