ietf-corpus

rfc-5884

Bidirectional Forwarding Detection (BFD) for MPLS Label Switched Paths (LSPs)

R. Aggarwal, K. Kompella, T. Nadeau, G. Swallow
date2010-06 streamIETF areartg wgbfd statusPROPOSED STANDARD pages12 canonicalhttps://www.rfc-editor.org/rfc/rfc5884 doi10.17487/RFC5884 errataview
One desirable application of Bidirectional Forwarding Detection (BFD) is to detect a Multiprotocol Label Switching (MPLS) Label Switched Path (LSP) data plane failure. LSP Ping is an existing mechanism for detecting MPLS data plane failures and for verifying the MPLS LSP data plane against the control plane. BFD can be used for the former, but not for the latter. However, the control plane processing required for BFD Control packets is relatively smaller than the processing required for LSP Ping messages. A combination of LSP Ping and BFD can be used to provide faster data plane failure detection and/or make it possible to provide such detection on a greater number of LSPs. This document describes the applicability of BFD in relation to LSP Ping for this application. It also describes procedures for using BFD in this environment. [STANDARDS-TRACK]

updated by

updates

Extracted elements (26)

design-rationale §3.1

BFD is used for MPLS LSP fault detection instead of LSP Ping alone because BFD has lower computational cost, a fixed packet format suitable for hardware/firmware implementation, and supports sub-second fault detection intervals. LSP Ping is retained for bootstrapping and periodic control-plane verification because BFD cannot associate a fault detection message with a FEC in PHP or next-hop label allocation scenarios.

mpls

design-rationale §5

LSP Ping is used to bootstrap BFD sessions because in PHP, explicit-null, and next-hop label allocation scenarios, BFD Control packets alone do not carry enough information to identify the FEC, making demultiplexing impossible without first exchanging discriminators via LSP Ping.

mpls

design-rationale §7

The destination IP address range 127/8 (IPv4) / 0:0:0:0:0:FFFF:7F00/104 (IPv6) is used for BFD Control packets sent by the ingress LSR, following the same motivation as RFC 4379 Section 2.1, to ensure the packet is processed by the egress LSR's control plane. This is an explicit exception to the behavior defined in RFC 1122.

mpls, ip

interoperability-note §4

For MPLS PW fault detection, this document assumes that the PW control channel type [RFC5085] is configured and LSP Ping support is also configured. The presence of a fault detection message may alternatively be indicated by setting a bit in the control word.

mpls

interoperability-note §4

When MPLS fast-reroute is active, the BFD fault detection interval MUST be set greater than the fast-reroute switchover time; otherwise BFD will declare a fault during a legitimate local repair, causing a false positive.

mpls

normative-requirement §4 MUST

A BFD session MUST be established for a particular MPLS LSP to use BFD for fault detection on that LSP. BFD Control packets MUST be sent along the same data path as the LSP being verified.

mpls, security

normative-requirement §4 SHOULD

An implementation SHOULD provide configuration options to control the BFD fault detection interval, so it can be set greater than the MPLS fast-reroute switchover time to avoid false fault detections.

mpls

normative-requirement §7 MUST

BFD Control packets sent by the egress LSR to the ingress LSR MUST use destination port 4784 if routed (BFD-MHOP), or destination port 3784 if encapsulated in an MPLS label stack.

mpls

normative-requirement §7 MUST

BFD Control packets sent by the ingress LSR MUST be encapsulated in the MPLS label stack corresponding to the FEC under test. The packet MUST be a UDP packet with destination port 3784 and the IP TTL or hop limit MUST be set to 1.

mpls

normative-requirement §4 SHOULD

For multiple alternate paths to an egress LSR for an LDP IP FEC, a BFD session SHOULD be established for each alternate path discovered via LSP Ping traceroute.

mpls

normative-requirement §4 SHOULD

If an LSP is associated with multiple FECs (e.g., due to next-hop label allocation), a BFD session SHOULD be established for each FEC.

mpls

normative-requirement §6.1 MUST

If the BFD session is not in UP state, the periodic LSP Ping Echo request messages MUST include the BFD Discriminator TLV.

mpls

normative-requirement §5 MUST

In PHP or explicit-null or next-hop-label-allocation scenarios, demultiplexing of BFD Control packets MUST be done using the remote discriminator field in the received BFD Control packet, since the packet does not contain sufficient information otherwise.

mpls

normative-requirement §6 MUST

On receipt of an LSP Ping Echo request, the egress LSR MUST send a BFD Control packet to the ingress LSR if FEC validation succeeds; this packet MUST set the Your Discriminator field to the discriminator received from the ingress LSR.

mpls

normative-requirement §7 MUST

Once the BFD session for an MPLS LSP is UP, either end MUST NOT change the source IP address or local discriminator values of its BFD Control packets unless it first brings the session down. An LSR MUST ignore BFD packets for a session in UP state if the My Discriminator or Source IP address do not match the established session values.

mpls, security

normative-requirement §4 SHOULD

Periodic LSP Ping Echo request messages SHOULD be sent by the ingress LSR to the egress LSR along the same data path as the LSP, to periodically verify the control plane against the data plane. The rate of these messages SHOULD be significantly less than the rate of BFD Control packets.

mpls

normative-requirement §7 MUST

The destination IP address of BFD Control packets sent by the ingress LSR MUST be randomly chosen from the 127/8 range for IPv4 or 0:0:0:0:0:FFFF:7F00/104 for IPv6, except when exercising a specific alternate path discovered by LSP Ping traceroute.

mpls, ip

normative-requirement §6 MUST

The local discriminator assigned by the egress LSR MUST be used as the My Discriminator field in BFD session packets sent by the egress LSR. The egress LSR MUST also send Control packets to the ingress LSR with the Your Discriminator field set to the ingress LSR's local discriminator.

mpls

normative-requirement §6 MUST

To establish a BFD session, an LSP Ping Echo request message MUST carry the local discriminator assigned by the ingress LSR; this MUST subsequently be used as the My Discriminator field in BFD session packets sent by the ingress LSR.

mpls

protocol-element §6

BFD session bootstrapping uses LSP Ping asynchronous mode only; BFD demand mode and the Echo function are outside the scope of this specification. The <MPLS LSP, FEC> combination drives initiation of fault detection.

mpls

registry §9

IANA has assigned type value 15 to the BFD Discriminator TLV in the LSP Ping TLVs and sub-TLVs registry.

registry, mpls

security-consideration §8

Security considerations from [BFD], [BFD-MHOP], and [RFC4379] all apply. For MPLS-encapsulated BFD Control packets, MPLS security considerations apply. When BFD Control packets sent by the egress LSR are routed, the authentication considerations in [BFD-MHOP] should be followed.

security, mpls

state-machine §6

BFD session state transitions follow [BFD] procedures. A key trigger: when the session is not yet UP, LSP Ping Echo requests carry the BFD Discriminator TLV; once UP, source IP and discriminator values are frozen until the session is explicitly brought down.

mpls

wire-format §7

BFD Control packets from the ingress LSR are UDP-over-MPLS: encapsulated in the LSP's label stack, destination port 3784, source port per BFD-IP procedures, source IP a routable address of the sender, destination IP from 127/8 (IPv4) or 0:0:0:0:0:FFFF:7F00/104 (IPv6), TTL/hop-limit set to 1.

mpls, ip

wire-format §7

For bidirectional LSPs or MPLS PWs, BFD Control packets from the egress LSR may be encapsulated in an MPLS label stack with destination IP randomly chosen from 127/8 (IPv4) or 0:0:0:0:0:FFFF:7F00/104 (IPv6) and destination port 3784.

mpls

wire-format §6.1

The BFD Discriminator TLV in LSP Ping has type value 15, length 4, and a 4-byte value containing the local discriminator that the sending LSR associates with the BFD session.

mpls, registry