Re: [Isis-wg] WG Last Call for draft-ietf-isis-segment-routing-msd-07

Jeff Tantsura <> Wed, 20 December 2017 19:37 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 9E327126D05; Wed, 20 Dec 2017 11:37:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, MIME_QP_LONG_LINE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (2048-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id dmcESAqBi9yY; Wed, 20 Dec 2017 11:37:39 -0800 (PST)
Received: from ( [IPv6:2607:f8b0:4003:c0f::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id D00C0126CBF; Wed, 20 Dec 2017 11:37:38 -0800 (PST)
Received: by with SMTP id q39so14133457otb.8; Wed, 20 Dec 2017 11:37:38 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=user-agent:date:subject:from:to:cc:message-id:thread-topic :references:in-reply-to:mime-version:content-transfer-encoding; bh=NCMeftjZ8PramH8dR1GdZIrP2IvaVUA6dNdltaO7LhE=; b=l9H9vK1hL+Hx/MwZJiqNK7wpgZ+TPCM1MuPr5h4D3cFFac2DLifdq2bVLU/o4eyN/R yo7e5b2mhe54CElj09FYKeGzoeDLO2AJcUFfSuvMm0Qmdygaub14yeD2HddW9gPYAIFB XeOxmZ1tIojHgNzMB87A7Ubw0ffaE5kEXBK6w7SexDzBkbdB+BmsYGCRniMAUoi2YbgI /WgqGrEmyhc5tlo9Z08uD622jats6BZAYdroxv1BtJj+MFTvJ7k8H9Ny/LgLDgCa5T2h gwILrPP/+5j32uok9G4LCJOUr/HpsAxwaXKN9IQIg6FaCHMu4dkQ0pau645O+QZ+OSIE aEYw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20161025; h=x-gm-message-state:user-agent:date:subject:from:to:cc:message-id :thread-topic:references:in-reply-to:mime-version :content-transfer-encoding; bh=NCMeftjZ8PramH8dR1GdZIrP2IvaVUA6dNdltaO7LhE=; b=WplGrHapcPHPPjxoHkihVadMZdGpSiwEZr1Di3rXJYkylXNNT4PPhfieYSZ9hlNIod XH/J3XAj1z7F1iqiyTmAuGUh0MN4EwFzNqR+xqLgbWvZ8xrm20vlGuO0ucY7tybjBhiz 7pVUhi52g9fLALWfzZR2+EBPsUpQT3J/KSJHgLFammfnPok8WxRJ5MoUaConrdk5LLew LtNjFxdq1tIBhvd6DQjUnmVwUuuoovecdfhmepLp5HhANzGRFKDtXaW+eW2YRwmPrerV kcm6L/qcV/iPsd6mwtCLIitgQ25CT7z8X4iiX7NZOp4uhxBBYjc2qm3DkD8HgUtIlZ10 8B+Q==
X-Gm-Message-State: AKGB3mJKYKMt9sTfFNOZGrazsUNquwEj/NmqTVN3YeA8SNwvndrIdl/e afluZF0xZZ8i9reyokuF+6m3fA==
X-Google-Smtp-Source: ACJfBoup1eifB3olDeiHYk4BGtYw/CaX4qvvFgKocz3z8EkwjUaB/OqwtSpGPW2ZdeMFDWiTBb2zvQ==
X-Received: by with SMTP id h29mr3699320otc.0.1513798658062; Wed, 20 Dec 2017 11:37:38 -0800 (PST)
Received: from [] ([]) by with ESMTPSA id x6sm8562687ota.10.2017. (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 20 Dec 2017 11:37:37 -0800 (PST)
User-Agent: Microsoft-MacOutlook/f.29.0.171205
Date: Wed, 20 Dec 2017 11:37:34 -0800
From: Jeff Tantsura <>
To: <>, "" <>
CC: "" <>, "" <>, Christian Hopps <>
Message-ID: <>
Thread-Topic: [Isis-wg] WG Last Call for draft-ietf-isis-segment-routing-msd-07
References: <> <30285_1513764651_5A3A372B_30285_488_1_53C29892C857584299CBF5D05346208A47926D1B@OPEXCLILM21.corporate.adroot.infra.ftgroup>
In-Reply-To: <30285_1513764651_5A3A372B_30285_488_1_53C29892C857584299CBF5D05346208A47926D1B@OPEXCLILM21.corporate.adroot.infra.ftgroup>
Mime-version: 1.0
Content-type: text/plain; charset="UTF-8"
Content-transfer-encoding: quoted-printable
Archived-At: <>
Subject: Re: [Isis-wg] WG Last Call for draft-ietf-isis-segment-routing-msd-07
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: IETF IS-IS working group <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 20 Dec 2017 19:37:42 -0000

Hi Bruno,

Many thanks for your valuable comments and see in line


-----Original Message-----
From: <>
Date: Wednesday, December 20, 2017 at 02:10
To: "" <>
Cc: "" <>rg>, "" <>rg>, Christian Hopps <>
Subject: RE: [Isis-wg] WG Last Call for draft-ietf-isis-segment-routing-msd-07
Resent-From: <>
Resent-To: <>om>, <>om>, <>om>, <>
Resent-Date: Wed, 20 Dec 2017 02:10:57 -0800 (PST)

    Hi authors,
    Please find below WGLC comments on this document.
    "the provisioned MSD
       of the router originating the Router Capability TLV.  Node MSD is the
       lowest MSD supported by the node of any interface and can be
       provisioned in IS-IS instance."
    I don't see the MSD as a provisioned value, but as a hardware capability. (Note that as a network operator, I'd be happy to be able to provision this capability without changing the hardware/software, but that has not been my experience so far.)
    Let's not put the burden on the network operator to configure this, while the node should know the value better. (as a priori, in the absence this extension, the node would report an error if instructed to push more labels than it is capable of). Especially for WAN routers, when Line Card may be changed (e.g. upgraded), so this would requires the network operator to keep track of all Line card change and update the MSD capability accordingly.(in which case, it may be just simpler to configure it directly on the controler, rather than requiring IS-IS, OSPF, BGP-LS protocol extensions, plus new features on all (involded) nodes)

[jeff] In ideal situation, the MSD capabilities should come from the HW SDK, while in a vertically integrated device, it might be vendor provisioned, however in a disaggregated case (HW and SW are from different vendors), ability to query HW for its MSD capabilities becomes crucial.
I have brought this point and discussed with BCM, Barefoot and few other HW vendors:
everyone agreed that would be a useful functionality, and would require quite simple API to add. Now it is up to their customers to demand an implementation, CP is standardized here, and, as usual, HW vendors have preference for a formal specification, that is stable.
For the time being, while there are no implementations we need to provide means to configure the value
Please also note, MSD configuration is covered by SR YANG model, in case the MSD value is communicated from HW(ro), it would go into operational data store

    "the provisioned MSD of the interface associated with the link."
    Please explicit whether the controller/reader need to use the MSD of the incoming link or of the outgoing link.
    If you believe this may be hardware dependent, this need to be signaled.

[jeff] always from outgoing link prospective, so the internals (ingress/egress/spitted MSD imposition) of a device are not of importance
    "MSD of type 1 (IANA Registry), called Base MSD, is used to signal the total number of SIDs a node is capable of imposing,"
    I think that this is limited to MPLS-SID. It would be good to state this somewhere. e.g. :s/SIDs/MPLS SIDs
[jeff] No, it doesn’t have to, IPv6 data plane could be covered as well, however topic for future and would be done thru a separate draft.
    "MSD: Maximum SID Depth"
    IMHO, I'm not a big fan of the term "depth".
    I find that it can be mislead with RLD (Readable Label Depth Capability). I don't feel that pushing N SID requires looking/going deep into the packet. Looking at the surface of the incoming label looks enough.
    Obviously, the comment is late.
[jeff] Let’s agree to disagree on this one, the draft explicitly mentions RLD and spells out the difference. 
    Related comment: I don't find the definition to be explicit enough. e.g. You now need to define what "SID depth" is or provide or reference.
[jeff] Point taken, will include in the terminology section – would definition such as “ SID depth is a number of SID’s a node or a link on a node is capable of imposing” work? Any text you would like to propose?
    1.1.1.  Terminology
    Given that the term are very very briefly explained, may be adding a reference to the RFC defining/explaining them.
    "In order, for BGP-LS to signal MSD for
       the all nodes and links in the network MSD is relevant, MSD
       capabilites SHOULD be distributed to every IS-IS router in the
    I don't think that the "SHOULD" is related to interoperability. Hence a "should" is probably enough. 
[jeff] agreed, will change
       "Value field consists of a 1 octet sub-type (IANA Registry) and 1 octet value."
    I don't see the value (sic) to hard code the legnth of the "sub-value":
    - this restrict the use of future MSD Sub-type Codepoints
    - if we hard code it, there is no use of the "length" field. (and "Length is variable " becomes not true)
           |    Type       |   Length      |      Sub-Type and Value       |
    "Value field consists of a 1 octet sub-type (IANA Registry) and 1
       octet value."
    Text and figure do not match: the value field is either 'Sub-Type and value" as per the text, or just "value without the Sub-type" as per the figure.  

[jeff]point taken, will update
    *2 (link and node MSD)
    § MSD Advertisement
    "   Sub-Type 1 (IANA Section), MSD and the Value field contains Link MSD
       of the router originating the corresponding TLV's 22, 23, 141, 222,
       and 223.  Link MSD is a number in the range of 0-254. 0 represents
       lack of the ability to impose MSD stack of any depth; any other value
       represents that of the particular link MSD value."
    It's not clear whether the text related to the MSD value is specific to the Sub-type 1 or to the whole Link MSD Advertisment. (i.e. would restrict the usage of future sub-Types). May be using two sections would help: one defining the Link MSD, one defining Sub-type 1. In which case the last paragraph of the introduction may be move to this new sub-type 1 section.
[jeff]point taken, will update

    *2 (link and node MSD)
    " Other Sub-types other than defined above are reserved for future extensions.  This sub-TLV is optional."
    It's not clear whether you mean this sub-TLV 1, or any sub-TLV n, or the presence of a sub-TLV. 

[jeff]point taken, will update
    "the ability to impose MSD stack of any depth"
    Were are not imposing an "MSD stack", but SID stack. Actually the SR architecture tends to use the term "list of segments" (or "ordered list of segments")

[jeff] agreed, will correct
    "   This document describes a mechanism to signal Segment Routing MSD
       supported at node and/or link granularity through IS-IS LSPs and does
       not introduce any new security issues."
    Improved fingerprinting capability would be one. Which may help target the right vulnerability of the advertising router.
[jeff] I don’t see how exposing MSD would increase the risk, please elaborate     
    "supported by a node at node and/or link granularity"
    May be NEW: supported by a node or link
[jeff] declined, both could be signaled at the same time
    "In order, for BGP-LS to signal MSD for
       the all nodes and links in the network MSD is relevant, MSD
       capabilites SHOULD be distributed to every IS-IS router in the
    In my understandind:
    :s/the all nodes/all the nodes
    :s/distributed to every IS-IS router/advertised by every IS-IS router

[jeff] agreed, will correct
       "A new sub-TLV within the body of IS-IS Router Capability TLV
       [RFC7981], Node MSD sub-TLV is defined to carry the provisioned MSD
       of the router originating the Router Capability TLV. ""
    May be the following would be easier to read
       A new sub-TLV "Node MSD sub-TLV" is defined within the body of IS-IS Router Capability TLV
       [RFC7981],  to carry the provisioned MSD
       of the router originating the Router Capability TLV.

[jeff] agreed will correct
       "Sub-Type 1 (IANA Section), MSD and the Value field contains Link MSD
       of the router originating the corresponding TLV's 22, 23, 141, 222,
       and 223.  Link MSD is a number in the range of 0-254."   
    Please use two paragraphs. One for "Sub-type" field, one for "MSD value" field.

[jeff] agreed will correct
    "0 represents lack of the ability to impose MSD stack of any depth "
    May be NEW: "0 represents lack of the ability to impose any SID"
    "Maximum MSD"
    NEW: MSD
    ("M" already stands for Maximum)
    Multiple times in the doc, with "Maximum" or "maximum"
[jeff] agreed will correct
    The document has 2 "Terminology" sections. You should probably merge them.
[jeff] agreed will correct
     > -----Original Message-----
     > From: Isis-wg [] On Behalf Of Christian Hopps
     > Sent: Wednesday, December 20, 2017 9:33 AM
     > To:
     > Cc:;
     > Subject: [Isis-wg] WG Last Call for draft-ietf-isis-segment-routing-msd-07
     > The authors have asked for and we are starting a WG Last Call on
     > which will last an extended 4 weeks to allow for year-end PTO patterns.
     > An IPR statement exists:
     > Authors please reply to the list indicating whether you are aware of any
     > *new* IPR.
     > Thanks,
     > Chris.
     > _______________________________________________
     > Isis-wg mailing list
    Ce message et ses pieces jointes peuvent contenir des informations confidentielles ou privilegiees et ne doivent donc
    pas etre diffuses, exploites ou copies sans autorisation. Si vous avez recu ce message par erreur, veuillez le signaler
    a l'expediteur et le detruire ainsi que les pieces jointes. Les messages electroniques etant susceptibles d'alteration,
    Orange decline toute responsabilite si ce message a ete altere, deforme ou falsifie. Merci.
    This message and its attachments may contain confidential or privileged information that may be protected by law;
    they should not be distributed, used or copied without authorisation.
    If you have received this email in error, please notify the sender and delete this message and its attachments.
    As emails may be altered, Orange is not liable for messages that have been modified, changed or falsified.
    Thank you.