Re: BFD WG adoption for draft-haas-bfd-large-packets

"Naiming Shen (naiming)" <> Tue, 23 October 2018 21:04 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 62970130F4C for <>; Tue, 23 Oct 2018 14:04:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -14.5
X-Spam-Status: No, score=-14.5 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: (amavisd-new); dkim=pass (1024-bit key)
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id HN-39-qaQ0WK for <>; Tue, 23 Oct 2018 14:04:25 -0700 (PDT)
Received: from ( []) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 8668B130FEA for <>; Tue, 23 Oct 2018 14:04:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple;;; l=56762; q=dns/txt; s=iport; t=1540328665; x=1541538265; h=from:to:cc:subject:date:message-id:references: in-reply-to:mime-version; bh=Qjy5LWbxOgdXWlW7UqVGyff7IoqAd/kmNpgk0pm2Ig4=; b=JaRvnT2p5QeVBE+Ygh1u9yrwmBwyDnTTkE546WwzLUdd3w1WSyZG4K3k TkW8aQLuQLf4LOLlMjbtTzEAAVMtd/oszC8Ur5WWKbdnZ3VcEREE0dart n9F0qDaifhTquCs0cChis6hSwgHrP0EdCtqo3rg6/6pXl/H+a9w+IpHMQ Y=;
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-AV: E=Sophos;i="5.54,417,1534809600"; d="scan'208,217";a="190107133"
Received: from ([]) by with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 23 Oct 2018 21:04:24 +0000
Received: from ( []) by (8.15.2/8.15.2) with ESMTPS id w9NL4Oai002379 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Tue, 23 Oct 2018 21:04:24 GMT
Received: from ( by ( with Microsoft SMTP Server (TLS) id 15.0.1395.4; Tue, 23 Oct 2018 16:04:23 -0500
Received: from ([]) by ([]) with mapi id 15.00.1395.000; Tue, 23 Oct 2018 16:04:23 -0500
From: "Naiming Shen (naiming)" <>
To: "Acee Lindem (acee)" <>
CC: Albert Fu <>, "" <>, "Les Ginsberg (ginsberg)" <>
Subject: Re: BFD WG adoption for draft-haas-bfd-large-packets
Thread-Topic: BFD WG adoption for draft-haas-bfd-large-packets
Thread-Index: AQHUau/W2obCS5tWFUCJRL2ls+mZdKUtDo2AgACXVgA=
Date: Tue, 23 Oct 2018 21:04:23 +0000
Message-ID: <>
References: <5BCF503702AB073A00390757_0_57088@msllnjpmsgsv06> <>
In-Reply-To: <>
Accept-Language: en-US
Content-Language: en-US
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: []
Content-Type: multipart/alternative; boundary="_000_F1BA67503D854AE6B89D23598FB69D91ciscocom_"
MIME-Version: 1.0
Archived-At: <>
X-Mailman-Approved-At: Tue, 23 Oct 2018 14:18:03 -0700
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "RTG Area: Bidirectional Forwarding Detection DT" <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Tue, 23 Oct 2018 21:04:35 -0000

I understand in some networks (such as in the network Albert mentioned about)
it may need sub-second detection if the MTU has been impacted on the path,
but that should only be an implementation/operational option, I would think most
of the networks will not use this way.  The draft should handle it in
a general way, or are we saying other cases are not valid or we need a
different draft to do the other ways?

- Naiming

On Oct 23, 2018, at 10:02 AM, Acee Lindem (acee) <<>> wrote:

Hi Albert,

From: "Albert Fu (BLOOMBERG/ 120 PARK)" <<>>
Reply-To: Albert Fu <<>>
Date: Tuesday, October 23, 2018 at 12:45 PM
To: "<>" <<>>, "Les Ginsberg (ginsberg)" <<>>, Acee Lindem <<>>
Subject: Re: BFD WG adoption for draft-haas-bfd-large-packets

Hi Acee,

You are right in that this issue does not happen frequently, but when it does, it is time consuming to troubleshoot and causes unnecessary network downtime to some applications (e.g. between two end hosts, some applications worked fine, but others would intermittently fail when they tried to send large size packets over the failing ECMP path).

So youā€™re saying there is a problem where the data plane interfaces do not support the configured MTU due to a SW bug? I hope these are not our routers šŸ˜‰

I believe the OSPF MTU detection is a control plane mechanism to check config, and may not necessary detect a data plane MTU issue (since OSPF does not support padding). Also, most of our issues occurred after routing adjacency had been established, and without any network alarms.

Right. However, if the interface is flapped when the MTU changes, OSPF would detect dynamic MTU changes (e.g., configuration), that the control plane is aware of.



From:<> At: 10/23/18 12:30:55
To: Albert Fu (BLOOMBERG/ 120 PARK ) <> ,<>,<>
Subject: Re: BFD WG adoption for draft-haas-bfd-large-packets
Hi Albert, Les,

I tend to agree with Les that BFD doesnā€™t seem like the right protocol for this. Note that if you use OSPF as your IGP and flap the interface when the MTU changes, youā€™ll detect MTU mismatches immediately due to OSPFā€™s DB exchange MTU negotiation. Granted, control plane detection wonā€™t detect data plane bugs resulting in MTU fluctuations but I donā€™t see this as a frequent event.


From: Rtg-bfd <<>> on behalf of "Albert Fu (BLOOMBERG/ 120 PARK)" <<>>
Reply-To: Albert Fu <<>>
Date: Tuesday, October 23, 2018 at 11:44 AM
To: "<>" <<>>, "Les Ginsberg (ginsberg)" <<>>
Subject: RE: BFD WG adoption for draft-haas-bfd-large-packets

Hi Les,

Given that it takes relative lengthy time to troubleshoot the MTU issue, and the associated impact on customer traffic, it is important to have a reliable and fast mechanism to detect the issue.

I believe BFD, especially for single hop control-plane independent situation (btw, this covers majority of our BFD use case), is indeed an ideal and reliable solution for this purpose. It is also closely tied with the routing protocols, and enable traffic to be diverted very quickly.

The choice of BFD timer is also one of the design tradeoffs - low BFD detection timer will cause more network churns. We do not need extremely aggressive BFD timer to achieve fast convergence. For example, with protection, we can achieve end to end sub-second convergence by using relatively high BFD interval of 150ms.

In the case where the path will be used for a variety of encapsulations (e.g. Pure IP and L3VPN traffic), we would set the BFD padding to cater for the largest possible payload. So, in our case, our link needs to carry a mix of pure IP (1500 max payload) and MPLS traffic (1500 + 3 headers), we would set the padding so that the total padded BFD packet size is 1512 bytes.

As you rightly pointed out, ISIS routing protocol does support hello padding, but since this is a control plane process, we can not use aggressive timer. The lowest hello interval the can be configured is 1s, so with default multiplier of 3, the best we can achieve is 3s detection time.

What we would like is a simple mechanism to validate that a link can indeed carry the expected max payload size before we put it into production. If an issue occurs where this is no longer the case (e.g. due to outages or re-routing within the Telco circuit), we would like a reliable mechanism to detect this, and also divert traffic around the link quickly. I feel BFD is a good method for this purpose.


From:<> At: 10/23/18 10:45:02
To: Albert Fu (BLOOMBERG/ 120 PARK ) <> ,<>
Subject: RE: BFD WG adoption for draft-haas-bfd-large-packets
Albert ā€“

Please understand that I fully agree with the importance of being able to detect/report MTU issues. In my own experience this can be a difficult problem to diagnose. You do not have to convince me that some improvement in detection/reporting is needed. The question really is whether using BFD is the best option.

Could you respond to my original questions ā€“ particularly why sub-second detection of this issue is a requirement?

For your convenience:

It has been stated that there is a need for sub-second detection of this condition ā€“ but I really question that requirement.
What I would expect is that MTU changes only occur as a result of some maintenance operation (configuration change, link addition/bringup, insertion of a new box in the physical path etc.). The idea of using a mechanism which is specifically tailored for sub-second detection to monitor something that is only going to change occasionally seems inappropriate. It makes me think that other mechanisms (some form of OAM, enhancements to routing protocols to do what IS-IS already does ā€¢) could be more appropriate and would still meet the operational requirements.

I have listened to the Montreal recording ā€“ and I know there was discussion related to these issues (not sending padded packets all the time, use of BFD echo, etc.) ā€“ but I would be interested in more discussion of the need for sub-second detection.

Also, given that a path might be used with a variety of encapsulations, how do you see such a mechanism being used when multiple BFD clients share the same BFD session and their MTU constraints are different?
<end snip>