MPLS Transport Profile (MPLS-TP) Linear Protection to Match the Operational Expectations of Synchronous Digital Hierarchy, Optical Transport Network, and Ethernet Transport Network Operators
updated by
- rfc-8234 — Updates to MPLS Transport Profile (MPLS-TP) Linear Protection in Automatic Protection Switching (APS) Mode
updates
- rfc-6378 — MPLS Transport Profile (MPLS-TP) Linear Protection
Extracted elements (30)
MS-W is introduced because modifying non-revertive behavior (Capability 2) creates a need to revert from the DNR state without using Lockout of Protection—which introduces an unprotected interval. RFC 6378 required issuing LO followed by Clear to exit DNR, but MS-W provides a safer direct revert command corresponding to the 'Manual switch-over for recovery LSP/span' command mandated by RFC 5654 Requirement 83.
RFC 6378 defines FS priority higher than SF-P, which can cause an out-of-service situation when the protection path fails and PSC communication stops. This document swaps the priorities so SF-P is higher than FS, aligning MPLS-TP behavior with SDH, OTN, and Ethernet transport networks where operators expect traffic to remain protected even when a maintenance FS command is active.
RFC 6378 supports non-revertive operation only when recovering from defect conditions, but not when operator commands such as FS or MS are cleared. This document modifies non-revertive behavior so a node enters the Do-not-Revert (DNR) state whenever any switch-over condition—including operator commands—is cleared, aligning with RFC 4427 and other transport network behaviors.
The Freeze command is introduced as a local-only (non-signaled) command to allow operators to lock the protection group state, preventing the priority swap from moving traffic back to the working path when SF-P occurs and PSC communication is broken. It provides an escape hatch for operators who need to keep traffic on the protection path during maintenance.
The low priority of Clear Signal Fail (SFc) defined in RFC 6378 causes traffic disruption when a node recovers from simultaneous signal fails on both working and protection paths: once SF-P is cleared, the SFc request cannot preempt the remaining SF-W condition, leaving traffic stranded on an unavailable path. This document raises SFc priority above SF-P to correct this.
Capability advertisement is not a negotiation but a verification that both endpoints use the same mode. If the Capabilities TLVs do not match, the node must alert the operator and halt protection switching. To support backward compatibility with RFC 6378 implementations, a node supporting PSC mode MUST be configurable to either send a Capabilities TLV with Flags=0x0 or send no Capabilities TLV at all.
When the Revertive (R) bit mismatches between two endpoints, both sides will still interwork and traffic is protected according to the state transition tables in Section 11; the node configured for non-revertive operation effectively operates as revertive when the revertive peer sends WTR messages. The node SHOULD notify the operator of the mismatch.
A node MUST include its Capabilities TLV in every PSC message it transmits. Upon receiving a Capabilities TLV, the node MUST compare the received Flags to its own transmitted Flags; if they differ, the node MUST alert the operator and MUST NOT perform any protection switching until the mismatch is resolved.
Defect local inputs (SF-P, SF-W, SD-P, SD-W) SHALL be accepted and retained persistently in the Local Request Logic as long as the defect exists; they cannot be removed by higher-priority inputs but remain and become the highest request again once the higher-priority input clears. Commands LO, FS, MS, and EXER SHALL be rejected if any higher-priority local input exists.
For 1+1 unidirectional protection switching, the state transition table from Section 11.1 SHALL be reused with the received remote Request field always assumed to be no request. The OC input in WTR state stops the WTR timer and immediately transitions to Normal (replacing footnote 4), and WTR timer expiry in WTR state also transitions to Normal (replacing footnote 6). EXER is not relevant.
For equal-priority local requests (SD and MS), the first-come, first-served rule SHALL be applied; a subsequent equal-priority request requesting a different FPath action is considered lower priority. For MS commands, the subsequent conflicting local MS SHALL be rejected and cleared.
For simultaneous equal-priority conflicts, MS-W SHALL have higher priority than MS-P at both nodes. For simultaneous SD on both paths, the SD on the standby path (from which the selector does not select traffic) SHALL have higher priority than SD on the active path, preventing unnecessary switching.
If no PSC message is received on the protection path during at least 3.5 times the long PSC message interval (e.g., 17.5 seconds with default 5-second interval) and there is no defect on the protection path, the node MUST alert the operator and MUST NOT perform any protection switching until the defect is resolved.
If the Protection Type (PT) field mismatches between a permanent bridge and selector bridge configuration, the node MUST notify the operator and MUST NOT perform protection switching. If the bridge type matches but switching type mismatches (uni vs. bidirectional), the bidirectional node SHOULD fall back to unidirectional switching to allow interworking.
MS-P and MS-W are distinguished by the FPath field: FPath=1 indicates MS-P (traffic diverted from working path to protection), FPath=0 indicates MS-W (traffic diverted from protection path to working). The Path field indicates the current data path (0=working, 1=protection).
MS-P and MS-W SHALL have the same priority. When received in succession, the second command SHALL be cancelled. When both commands occur simultaneously at opposite ends, MS-W SHALL be considered to have higher priority and MS-P SHALL be cancelled and discarded.
The priorities of SD-P and SD-W SHALL be equal. Once a switch has been completed due to SD on one path, it will not be overridden by SD on the other path (first-come, first-served), avoiding protection switching that cannot improve signal quality.
Under SD conditions, a node SHALL duplicate user data traffic and feed it to both working and protection paths. Duplication SHALL continue as long as any SD condition exists in the protected domain; in revertive operation it continues through the WTR state and stops on WTR exit, while in non-revertive operation it stops immediately when SD clears.
When a node receives a remote EXER message, it SHOULD respond with a Reverse Request (RR) message with FPath and Path set to the current condition. The RR message SHALL be generated only in response to a remote EXER. If EXER is received before RR when local EXER is pending, the received EXER MUST be treated as an RR.
When the priority modification capability is in use, the local request priority order from highest to lowest SHALL be: Clear Signal Fail, Signal Fail on Protection path, Forced Switch, Signal Fail on Working path. This inverts the RFC 6378 ordering of FS and SF-P.
APS mode requires all five capabilities simultaneously (Flags=0xF8000000). It introduces: SF-P higher priority than FS, SFc highest local priority, extended non-revertive behavior, MS-W command, SD protection switching, and EXER command. The full priority order and state machine are defined in Sections 10 and 11.
PSC mode is the absence of any additional capabilities (Flags=0x0) and corresponds to the behavior defined in RFC 6378. A node may signal PSC mode by sending no Capabilities TLV or by sending one with Flags=0x0; an implementation MUST be configurable between these two options to support backward compatibility.
The APS mode priority order from highest to lowest is: Operator Clear (local only), Lockout of protection, Clear Signal Fail or Degrade (local only), SF-P, Forced Switch, SF-W, Signal Degrade, Manual Switch, WTR Timer Expiry (local only), WTR (remote only), Exercise, Reverse Request (remote only), Do-Not-Revert (remote only), No Request. Remote requests rank just below the identical local request except for NR and equal-priority cases.
Two new PSC Request field values are defined for APS mode: value 2 (Reverse Request, RR) indicates the transmitting endpoint is responding to a remote EXER; value 3 (Exercise, EXER) indicates the endpoint is exercising the protection channel without actually switching traffic.
IANA assigned two new code points in the MPLS PSC Request Registry (within G-ACh Parameters): value 2 for Reverse Request and value 3 for Exercise, both referencing RFC 7271.
IANA assigned value 1 to the Capabilities TLV type in the MPLS PSC TLV Registry (within G-ACh Parameters), referencing RFC 7271.
IANA created the MPLS PSC Capability Flag Registry within G-ACh Parameters. Allocation policy is Standards Action. Flags must be multiples of 4 octets. Five 4-octet flags are defined: bit 0 (0x80000000) priority modification, bit 1 (0x40000000) non-revertive behavior modification, bit 2 (0x20000000) MS-W support, bit 3 (0x10000000) SD protection, bit 4 (0x08000000) EXER support; bits 5-31 unassigned.
This document introduces no new security risks beyond those in RFC 6378. MPLS relies on assumptions about the difficulty of traffic injection and does not assume end-to-end security in the control plane; RFC 5920 describes MPLS security issues and generic methods for securing traffic privacy and integrity, which apply here.
APS mode defines 21 extended states including Normal (N), Unavailable states (UA:LO:L/R, UA:P:L/R, UA:DP:L/R), Protecting Failure states (PF:W:L/R, PF:DW:L/R), Switching Administrative states (SA:F:L/R, SA:MW:L/R, SA:MP:L/R), WTR, DNR, and Exercise states (E::L, E::R). Transitions are triggered by local inputs (OC, LO, SFDc, SF-P, FS, SF-W, SD-P, SD-W, MS-W, MS-P, WTRExp, EXER) and remote messages.
The Capabilities TLV carries a Type field (value=1), a Length field (length of Flags in octets, must be a multiple of 4 and the minimum needed), and a 32-bit Flags field. Five capabilities occupy the five most significant bits: 0x80000000 (priority modification), 0x40000000 (non-revertive modification), 0x20000000 (MS-W), 0x10000000 (SD protection), 0x08000000 (EXER). APS mode sets Flags=0xF8000000.