Re: [Technical Errata Reported] RFC5884 (5085)

Balaji Rajagopalan <balajir@juniper.net> Tue, 22 August 2017 09:09 UTC

Return-Path: <balajir@juniper.net>
X-Original-To: rtg-bfd@ietfa.amsl.com
Delivered-To: rtg-bfd@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E97C1321B6 for <rtg-bfd@ietfa.amsl.com>; Tue, 22 Aug 2017 02:09:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.019
X-Spam-Level:
X-Spam-Status: No, score=-2.019 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=juniper.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bHKLH0ziF_A2 for <rtg-bfd@ietfa.amsl.com>; Tue, 22 Aug 2017 02:09:23 -0700 (PDT)
Received: from NAM01-BY2-obe.outbound.protection.outlook.com (mail-by2nam01on0136.outbound.protection.outlook.com [104.47.34.136]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5B992132732 for <rtg-bfd@ietf.org>; Tue, 22 Aug 2017 02:09:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=juniper.net; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=WZAwHYH+fFoyg495Mg5cHwdhFsCN46EKxT4XDu4yH1M=; b=SJLx2FGivaQJO4u3GBiWLykGcp/4g7y3fg91efV4mLpfvo9xywaIk8zjVM8/q3Tr9nkVMSnXD5+CqBmEWnUjfev5QvgSwLw0Dg6Zd8vJa1Qh/ddpbnTxw/7lTnnm5yhfP+/sNjOL7uZ8mxrGE31sQm7FLf6Vb1HJN+wRWhdnWeo=
Received: from MWHPR05MB3215.namprd05.prod.outlook.com (10.173.229.146) by MWHPR05MB3134.namprd05.prod.outlook.com (10.173.229.12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.1.1385.4; Tue, 22 Aug 2017 09:09:21 +0000
Received: from MWHPR05MB3215.namprd05.prod.outlook.com ([10.173.229.146]) by MWHPR05MB3215.namprd05.prod.outlook.com ([10.173.229.146]) with mapi id 15.01.1385.008; Tue, 22 Aug 2017 09:09:20 +0000
From: Balaji Rajagopalan <balajir@juniper.net>
To: Greg Mirsky <gregimirsky@gmail.com>
CC: Jeffrey Haas <jhaas@pfrc.org>, Kireeti Kompella <kireeti@juniper.net>, Thomas Nadeau <tnadeau@lucidvision.com>, "rtg-bfd@ietf.org" <rtg-bfd@ietf.org>, "Reshad Rahman (rrahman)" <rrahman@cisco.com>, Alia Atlas <akatlas@gmail.com>
Subject: Re: [Technical Errata Reported] RFC5884 (5085)
Thread-Topic: [Technical Errata Reported] RFC5884 (5085)
Thread-Index: AQHTEmO6It6KBy1xuUWF7JOUmCVKk6J/bMuAgAAJToCAB2B3AIAARImAgAlo/4A=
Date: Tue, 22 Aug 2017 09:09:20 +0000
Message-ID: <57C9C1D0-5876-499D-8C2A-6F8B14F5C38D@juniper.net>
References: <20170811053550.27303B81263@rfc-editor.org> <20170811173930.GJ24942@pfrc.org> <CA+RyBmWYRAT3g=zCN+ot9mFDYuPCOGCwyPQJp-+9AfA6oJjttA@mail.gmail.com> <DDFD74A7-D09D-43AE-9BAD-24273A53C55B@juniper.net> <CA+RyBmVzL4Gq0nGetTHSJevtywDwGULyA0grcFAG7ieWB7dqHg@mail.gmail.com>
In-Reply-To: <CA+RyBmVzL4Gq0nGetTHSJevtywDwGULyA0grcFAG7ieWB7dqHg@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/f.1d.0.161209
x-originating-ip: [116.197.184.14]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; MWHPR05MB3134; 6:nyD+bX1jI//SI/G8STTcHsmW1KVNaKwV5XONq57SEqy7v7ZkY54ow6XbQk86G+x+hfYfAS+mqEP6t9JPOepzCGWGjXMG5WeCkvw75qKffuC82LLjUZPubPUlOSzBfObSpP9jwUYBnb4pLXPu8HNvN6gc1cho/avyOfB3B/qRAVRNBzRkMfKIFM5x9tU1z/7AgQmGtNGj9TZMrOdXnnZ7LxZrTaJPpfNGm/0JdpLqgBiRraVvxHRIN+tPtknUfsl5ZffUyZ9EJGdMjjNS2eBQjIEKxPoI4NR7lzx0FuhOrQeL8yqjcczzV3XfyXE972FxQbCsednhcgumVW1TVXOpjg==; 5:wuJjk1AHjzYhcc5g1FcbEJBsk/baDtZmQSDcsxUD7K5K+w0QXrwz1S5dUU6zQwhHHTrxg0k0uE16cSPFPzFqY8tTZ5pP3HfjzvDZUVR9pX3OY5v97iHydTzTIPYbQ+gkI49ddUbn7byXHZsxDQKbyQ==; 24:jNw+kCLAPtdTxQCHcCGrlTIsT4FE8iIpIiyBCXDkxCSig8p2bRAuyTaW+yGdUQvGVuCaFeLTo0AIRYOuR1L2zX5Vt8SHwYivaq57ZL1Jdxs=; 7:yNhA7rrWWjyjbk651Y+CkXOoN5CIVmW4RGBzrJcvWRIm/jVdhCapwufSosD7vkmNoB6ONWWpT+eFA05x6NqXwY3twknQNBg3oyllhNAdxSioOtW4X2kXxzN0cwPddIWERHDsXtb0jUrGHezW+Ft/yZn+stl/WBgktpAsEX6O+cEIJk49+zFtmILtC5kZmGybLgykG/8oNpNgXnIQCPRGbc9Fu+DOKdPzHbw9SyLt8Ro=
x-ms-exchange-antispam-srfa-diagnostics: SSOS;SSOR;
x-forefront-antispam-report: SFV:SKI; SCL:-1; SFV:NSPM; SFS:(10019020)(39860400002)(189002)(24454002)(199003)(377454003)(6306002)(7736002)(53936002)(229853002)(54896002)(1411001)(8676002)(236005)(54356999)(6116002)(76176999)(3846002)(561944003)(6512007)(478600001)(50986999)(86362001)(102836003)(345774005)(2950100002)(6916009)(6506006)(6436002)(733005)(68736007)(101416001)(99286003)(66066001)(4326008)(25786009)(54906002)(77096006)(189998001)(6486002)(18926415007)(93886005)(8936002)(33656002)(81156014)(106356001)(82746002)(97736004)(6246003)(9326002)(2906002)(110136004)(14454004)(4001350100001)(2900100001)(39060400002)(81166006)(5660300001)(53546010)(36756003)(3660700001)(83506001)(105586002)(83716003)(3280700002); DIR:OUT; SFP:1102; SCL:1; SRVR:MWHPR05MB3134; H:MWHPR05MB3215.namprd05.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
x-ms-office365-filtering-correlation-id: 62937625-0e52-403e-73ce-08d4e93d797a
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(300000502095)(300135100095)(22001)(2017030254152)(48565401081)(300000503095)(300135400095)(2017052603166)(201703131423075)(201703031133081)(201702281549075)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:MWHPR05MB3134;
x-ms-traffictypediagnostic: MWHPR05MB3134:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=balajir@juniper.net;
x-exchange-antispam-report-test: UriScan:(138986009662008)(95692535739014)(21748063052155)(6911010853514)(225473673943800);
x-microsoft-antispam-prvs: <MWHPR05MB31344A6ED244312D9154677CAB840@MWHPR05MB3134.namprd05.prod.outlook.com>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(601004)(2401047)(8121501046)(5005006)(93006095)(93001095)(10201501046)(3002001)(100000703101)(100105400095)(6055026)(6041248)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123564025)(20161123558100)(20161123555025)(20161123560025)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:MWHPR05MB3134; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:MWHPR05MB3134;
x-forefront-prvs: 04073E895A
received-spf: None (protection.outlook.com: juniper.net does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_57C9C1D05876499D8C2A6F8B14F5C38Djunipernet_"
MIME-Version: 1.0
X-OriginatorOrg: juniper.net
X-MS-Exchange-CrossTenant-originalarrivaltime: 22 Aug 2017 09:09:20.5333 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: bea78b3c-4cdb-4130-854a-1d193232e5f4
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR05MB3134
Archived-At: <https://mailarchive.ietf.org/arch/msg/rtg-bfd/OvvmI-bK6xkQ22oTw64cgVxEkUg>
X-BeenThere: rtg-bfd@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "RTG Area: Bidirectional Forwarding Detection DT" <rtg-bfd.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtg-bfd>, <mailto:rtg-bfd-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rtg-bfd/>
List-Post: <mailto:rtg-bfd@ietf.org>
List-Help: <mailto:rtg-bfd-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtg-bfd>, <mailto:rtg-bfd-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Aug 2017 09:09:26 -0000

Hi Greg,

In all the three cases, the return mode field in the Echo request packet was set to 2 (Reply via an IPv4/IPv6 UDP packet).

--
Balaji Rajagopalan

From: Greg Mirsky <gregimirsky@gmail.com>
Date: Wednesday, 16 August 2017 at 8:27 PM
To: Balaji Rajagopalan <balajir@juniper.net>
Cc: Jeffrey Haas <jhaas@pfrc.org>, Kireeti Kompella <kireeti@juniper.net>, Thomas Nadeau <tnadeau@lucidvision.com>, "rtg-bfd@ietf.org" <rtg-bfd@ietf.org>, "Reshad Rahman (rrahman)" <rrahman@cisco.com>, Alia Atlas <akatlas@gmail.com>
Subject: Re: [Technical Errata Reported] RFC5884 (5085)

Hi Balaji,
thank you for sharing your experience with the issue. Had you captured what are the values of the Return Mode field in Echo request packets in each case? Perhaps these would explain the behavior of the egress LSR.

Regards,
Greg

On Tue, Aug 15, 2017 at 10:23 PM, Balaji Rajagopalan <balajir@juniper.net<mailto:balajir@juniper.net>> wrote:
I’m aware of three different behaviours from three different vendors that I came across in the course of inter-op:

-         Always respond to an LSP-Ping request carrying a BFD disc

-         Never send a response to an LSP-Ping request carrying a BFD disc

-         Don’t respond to the first LSP-Ping request carrying a BFD disc, but respond to the subsequent ones


This experience leads me to believe that this procedure is NOT well-understood.  So, publication of errata on this issue is necessary.

As some of the co-authors have clarified in further emails, inclusion of BFD discriminator in the LSP-Ping request does not change LSP-Ping’s basic function. So, the egress must send a reply. This is what the erratum clarifies.

--
Balaji Rajagopalan



From: Rtg-bfd <rtg-bfd-bounces@ietf.org<mailto:rtg-bfd-bounces@ietf.org>> on behalf of Greg Mirsky <gregimirsky@gmail.com<mailto:gregimirsky@gmail.com>>
Date: Friday, 11 August 2017 at 11:42 PM
To: Jeffrey Haas <jhaas@pfrc.org<mailto:jhaas@pfrc.org>>
Cc: Kireeti Kompella <kireeti@juniper.net<mailto:kireeti@juniper.net>>, Thomas Nadeau <tnadeau@lucidvision.com<mailto:tnadeau@lucidvision.com>>, "rtg-bfd@ietf.org<mailto:rtg-bfd@ietf.org>" <rtg-bfd@ietf.org<mailto:rtg-bfd@ietf.org>>, "Reshad Rahman (rrahman)" <rrahman@cisco.com<mailto:rrahman@cisco.com>>, Alia Atlas <akatlas@gmail.com<mailto:akatlas@gmail.com>>
Subject: Re: [Technical Errata Reported] RFC5884 (5085)

Re-sending to the corrected list (apologies for duplicates).

Dear All,
I suggest to reject this proposal. The current text is clear and the mechanics of bootstrapping BFD session over MPLS LSP is well understood - remote peer MUST start sending BFD control packets first and BFD peer MAY send Echo Reply with its Local Discriminator as value in BFD Discriminator TLV.

Regards,
Greg


On Fri, Aug 11, 2017 at 10:39 AM, Jeffrey Haas <jhaas@pfrc.org<mailto:jhaas@pfrc.org>> wrote:
[Note that I have adjusted the addresses in the headers to try to catch the
RFC authors' current accounts.]


The 5884 interop issue keeps bubbling up.  Balaji submitted an errata, which
provides us with a good place to start technical discussion.

Please note I also spent some time off-list discussing this errata with
Balaji.


On Thu, Aug 10, 2017 at 10:35:50PM -0700, RFC Errata System wrote:
> Section: 6
>
> Original Text
> -------------
> The egress LSR MAY respond with an LSP Ping Echo
> reply message that carries the local discriminator assigned by it for
> the BFD session.
>
> Corrected Text
> --------------
> The egress LSR MUST respond with an LSP Ping Echo reply message that
> MAY carry the local discriminator assigned by it for the BFD session.
>
>
> Notes
> -----
> It is not clear from the original text which of the following is optional:
>   -  The egress MUST send a reply, but the discriminator in the reply is optional
>   -  The reply itself is optional
>
> Technically, the reply cannot be optional, because the egress needs to report LSP-Ping verification status to the ingress.
>
> The proposed text recommends to include BFD discriminator in the reply. This was the intent of the original text.

My opinion follows:

In section 6 -

:    On receipt of the LSP Ping Echo request message, the egress LSR MUST
:    send a BFD Control packet to the ingress LSR, if the validation of
:    the FEC in the LSP Ping Echo request message succeeds.  This BFD
:    Control packet MUST set the Your Discriminator field to the
:    discriminator received from the ingress LSR in the LSP Ping Echo
:    request message.  The egress LSR MAY respond with an LSP Ping Echo
:    reply message that carries the local discriminator assigned by it for
:    the BFD session.  The local discriminator assigned by the egress LSR
:    MUST be used as the My Discriminator field in the BFD session packets
:    sent by the egress LSR.

In the text above, I consider it quite clear that the receipt of the BFD
packet contains sufficient state to bring up the BFD session.  The receipt
of the same Discriminator in the LSP Ping Echo Reply is optional.

This makes sense partially because the reply may be dropped and we want the
BFD session to come up as fast as possible.

The point of contention appears to be what to do if we *never* get such
replies.  It's worth pointing out additional text in RFC 5884, section 3.2.

:    Hence, BFD is used in conjunction with LSP Ping for MPLS LSP fault
:    detection:
:
:       i) LSP Ping is used for bootstrapping the BFD session as described
:          later in this document.
:
:      ii) BFD is used to exchange fault detection (i.e., BFD session)
:          packets at the required detection interval.
:
:     iii) LSP Ping is used to periodically verify the control plane
:          against the data plane by ensuring that the LSP is mapped to
:          the same FEC, at the egress, as the ingress.

iii above reminds us that the LSP may be torn down because LSP Ping fails.
Thus, it seems problematic that we do not get a reply ever.

However, with the BFD session in the Up state, we have information proving
that the LSP is up.  Thus we have contradictory intent.

---

My opinion is that the MAY in the RFC 5884 procedures is intended to have
the BFD session come up by the most expedient means.  I do not believe the
likely intent was to say "don't send Echo Reply".  Among other things, that
seems contrary to the intent of the general LSP Ping procedures.

Having given my personal observations, we now get to the business of the
Working Group: Debating intent and related text.

-- Jeff