[ippm] Re: WG Last Call: draft-ietf-ippm-alt-mark-deployme nt-05 (Ends 2026-05-28)

"Pinkert, Tjeerd" <tjeerd.pinkert=40siemens.com-Tr9gZwTxerDR74oF6e/[email protected]> Thu, 28 May 2026 16:12:41 +0000
Newsgroups gmane.ietf.ippm,gmane.ietf.bmwg
Message-ID <DB9PR10MB59314877654629661A44EBB686092@DB9PR10MB5931.EURPRD10.PROD.OUTLOOK.COM>
--===============1081513057947601024==
Content-Language: en-US
Content-Type: multipart/related;
 boundary="_004_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_";
 type="multipart/alternative"

--_004_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_
Content-Type: multipart/alternative;
 boundary="_000_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_"

--_000_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Dear Guiseppe,

A clarification in the draft would be appreciated.
VPNs or IPsec tunnels are rigid methods of creating user-domains, so that i=
s always possible.

When asking the question, I was thinking about something else, namely, the =
cases where such virtual networks are not used or not necessarily needed.
E.g. in situations where the network is controlled by entity A and entity B=
 uses that network.
When entity B, partially trusts entity A (e.g. that the network provided is=
 private), but still has need to check the quality.
When entity A and B use the same alternate marker technology (and B signs),=
 what measures must the network owner (A) take to honour the network user (=
B) his alternate markers?
Is that possible with the currently designed methods? (Should it be?)

Slightly OT some thoughts on use of the DSCP field:
When using DSCP, or the reserved Flag on IPv4 (these were exactly the field=
s I had in mind as usable).
A signature over the IP header, added as IP option could be a possibility f=
or the user to ensure that the packet was not manipulated.
Internal to the controlled domain, the DSCP field should than not be change=
d uncontrolled (e.g. it should be reset to the original value on exit of th=
e controlled domain).
DSCP has the disadvantage of being designed to be changed by nodes an-route=
, especially when certain traffic classes are used.
The DSCP field is thus basically only possible for a controlled domain, not=
 for an end-user, unless this would be explicitly specified by the network =
owner how to do this.

In my I-D for the IP measurement option, I added a flag field as alternate =
marker, that could be used when the DSCP field is not feasible.
All other fields can be zeroed out in that case. Next to that, it contains =
the possibility of adding a cryptographic signature.
In that sense it would be usable for both controlled and end-user domains.

Best regards,


Tjeerd


From: Giuseppe Fioccola <[email protected]>
Sent: Donnerstag, 28. Mai 2026 16:20
To: Pinkert, Tjeerd (SMO RI ML COC SM 2) <[email protected]>; draf=
[email protected]; IPPM Chairs <[email protected]=
>; [email protected]; [email protected]; [email protected]
Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202=
6-05-28)

Hi Tjeerd,

I agree with you regarding the use of cryptography for the controlled domai=
n. Indeed, if you look at section 2.1 of RFC9343, it is also mentioned that=
 multiple domains can create a whole controlled domain while traversing the=
 external domain by employing IPsec authentication and encryption or other =
VPN technology. I can clarify this point in draft-ietf-ippm-alt-mark-deploy=
ment too.

Regarding the AltMark encapsulations, note that RFC9343 defines the extensi=
on for IPv6, while in RFC9714 it is defined the extension for MPLS. There i=
s no standard extension for IPv4, but, just to satisfy your curiosity, we i=
nitially experimented the method by marking the DSCP field (see RFC8321) or=
 the last reserved bit of the Flag field (see draft-chen-ippm-coloring-base=
d-ipfpm-framework).
Other extensions are in progress, as you can notice in section 8 of draft-i=
etf-ippm-alt-mark-deployment.


Regards,

Giuseppe


From: Pinkert, Tjeerd <[email protected]<mailto:tjeerd.pinkert@sie=
mens.com>>
Sent: Wednesday, May 27, 2026 3:10 PM
To: Giuseppe Fioccola <[email protected]<mailto:giuseppe.fioccol=
[email protected]>>; [email protected]<mailto:draft-i=
[email protected]>; IPPM Chairs <[email protected]<m=
ailto:[email protected]>>; [email protected]<mailto:[email protected]>; bmwg@iet=
f.org<mailto:[email protected]>; [email protected]<mailto:[email protected]=
rg>
Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202=
6-05-28)

Dear Guiseppe,

OK, so that scenario is possible.
You may notice that I am interested in the network performance from the net=
work user perspective.

It is the question if the user domain could form such a controlled domain, =
and the packets are allowed to travel though a foreign domain.
>From a security perspective, one needs to know one thing: was my packet (th=
e alternate marker) manipulated by the foreign domain?
This can be achieved with cryptographic signatures, so that would need to b=
e designed into the measurement protocols (alternate marker data).
(Removal of alternate marker data is also a manipulation of the packet and =
can be detected by the user.)
I think a controlled user domain would be characterised by a shared secret =
for signing / encryption.

A user on the network edge, owning ten- to hundred-thousand machines formin=
g a distributed system, is a common use-case.
In particular, when the distributed system must be capable of adjusting to =
the network conditions, alternate marking methods could also be used.
Then the use of alternate markers by the user and the network owner should =
not collide.

One (off topic) thing I would be interested in, is what fields are typicall=
y used for alternate marking methods, and if signatures come into question =
for that?

Best regards,


Tjeerd


From: Giuseppe Fioccola <[email protected]<mailto:giuseppe.fiocc=
[email protected]>>
Sent: Donnerstag, 21. Mai 2026 10:32
To: Pinkert, Tjeerd (SMO RI ML COC SM 2) <[email protected]<mailto=
:[email protected]>>; [email protected]=
<mailto:[email protected]>; IPPM Chairs <ippm-ch=
[email protected]<mailto:[email protected]>>; [email protected]<mailto:ippm@ietf=
.org>; [email protected]<mailto:[email protected]>; [email protected]<mailto:bmw=
[email protected]>
Subject: RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202=
6-05-28)

Hi Tjeerd,
Thank you for the question.
Yes, it would be possible. But, for security reasons, In-Data-Packet OAM me=
thods, such as Alternate-Marking and IOAM, should be applied to limited/con=
trolled domains. You can find more details about this requirement in RFC 93=
41 and RFC 9197. It was initially discussed in RFC 8799.

Regards,

Giuseppe

From: Pinkert, Tjeerd <[email protected]<mailto:tjeerd.pinkert@sie=
mens.com>>
Sent: Wednesday, May 20, 2026 4:19 PM
To: [email protected]<mailto:draft-ietf-ippm-alt=
[email protected]>; IPPM Chairs <[email protected]<mailto:ippm-c=
[email protected]>>; [email protected]<mailto:[email protected]>; [email protected]<mailto=
:[email protected]>; [email protected]<mailto:[email protected]>
Subject: Re: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (Ends 202=
6-05-28)

Dear all,

I'm just wondering, can internet users form a controlled (boundary) domain =
and apply the alternate marking method independently of the controlled netw=
ork domain?
This should be possible, but is not very deeply explored?
(Or maybe I'm just missing the point, and the remarks on encapsulating traf=
fic cover this sufficiently?)

With best regards,
Dr. Tjeerd Pinkert

Siemens Mobility GmbH
Mobility
Rail Infrastructure
System Management 2
SMO RI ML COC SM 2
Ackerstr. 22
38126 Braunschweig, Germany
Phone: +49 (1520) 2884088
Mobile: +49 (1520) 2884088
mailto:[email protected]
www.siemens.com<https://www.siemens.com>
[Logo]
Siemens Mobility GmbH; Chairman of the Supervisory Board: Roland Busch; Man=
agement Board: Beatrice Bock, Michael Peter; Registered office: Munich, Ger=
many; Commercial registry Munich, HRB 237219; WEEE-Reg.-No. DE 92917817

--_000_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	font-size:10.0pt;
	font-family:"Calibri",sans-serif;
	mso-ligatures:standardcontextual;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;
	mso-ligatures:none;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-GB" link=3D"#0563C1" vlink=3D"#954F72" style=3D"word-wrap:=
break-word">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Dear Guiseppe,<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">A clarification in =
the draft would be appreciated.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">VPNs or IPsec tunne=
ls are rigid methods of creating user-domains, so that is always possible.<=
o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When asking the que=
stion, I was thinking about something else, namely, the cases where such vi=
rtual networks are not used or not necessarily needed.<o:p></o:p></span></p=
>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">E.g. in situations =
where the network is controlled by entity A and entity B uses that network.=
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When entity B, part=
ially trusts entity A (e.g. that the network provided is private), but stil=
l has need to check the quality.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When entity A and B=
 use the same alternate marker technology (and B signs), what measures must=
 the network owner (A) take to honour the network user (B) his alternate ma=
rkers?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Is that possible wi=
th the currently designed methods? (Should it be?)<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Slightly OT some th=
oughts on use of the DSCP field:<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">When using DSCP, or=
 the reserved Flag on IPv4 (these were exactly the fields I had in mind as =
usable).<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">A signature over th=
e IP header, added as IP option could be a possibility for the user to ensu=
re that the packet was not manipulated.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Internal to the con=
trolled domain, the DSCP field should than not be changed uncontrolled (e.g=
. it should be reset to the original value on exit of the controlled domain=
).<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">DSCP has the disadv=
antage of being designed to be changed by nodes an-route, especially when c=
ertain traffic classes are used.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">The DSCP field is t=
hus basically only possible for a controlled domain, not for an end-user, u=
nless this would be explicitly specified by the network owner how to do thi=
s.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">In my I-D for the I=
P measurement option, I added a flag field as alternate marker, that could =
be used when the DSCP field is not feasible.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">All other fields ca=
n be zeroed out in that case. Next to that, it contains the possibility of =
adding a cryptographic signature.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">In that sense it wo=
uld be usable for both controlled and end-user domains.<o:p></o:p></span></=
p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Best regards,<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><br>
Tjeerd<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;ms=
o-ligatures:none">From:</span></b><span lang=3D"EN-US" style=3D"font-size:1=
1.0pt;mso-ligatures:none"> Giuseppe Fioccola &lt;[email protected]=
om&gt;
<br>
<b>Sent:</b> Donnerstag, 28. Mai 2026 16:20<br>
<b>To:</b> Pinkert, Tjeerd (SMO RI ML COC SM 2) &lt;tjeerd.pinkert@siemens.=
com&gt;; [email protected]; IPPM Chairs &lt;ippm=
[email protected]&gt;; [email protected]; [email protected]; [email protected]<br=
>
<b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (E=
nds 2026-05-28)<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Hi T=
jeerd,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p=
>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">I ag=
ree with you regarding the use of cryptography for the controlled domain. I=
ndeed, if you look at section 2.1 of RFC9343, it is also mentioned that mul=
tiple domains can create a whole controlled
 domain while traversing the external domain by employing IPsec authenticat=
ion and encryption or other VPN technology. I can clarify this point in dra=
ft-ietf-ippm-alt-mark-deployment too.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p=
>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Rega=
rding the AltMark encapsulations, note that RFC9343 defines the extension f=
or IPv6, while in RFC9714 it is defined the extension for MPLS. There is no=
 standard extension for IPv4, but, just
 to satisfy your curiosity, we initially experimented the method by marking=
 the DSCP field (see RFC8321) or the last reserved bit of the Flag field (s=
ee draft-chen-ippm-coloring-based-ipfpm-framework).<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Othe=
r extensions are in progress, as you can notice in section 8 of draft-ietf-=
ippm-alt-mark-deployment.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p=
>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p=
>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Rega=
rds,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p=
>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Gius=
eppe<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p=
>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p=
>&nbsp;</o:p></span></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;ms=
o-ligatures:none">From:</span></b><span lang=3D"EN-US" style=3D"font-size:1=
1.0pt;mso-ligatures:none"> Pinkert, Tjeerd &lt;<a href=3D"mailto:tjeerd.pin=
[email protected]">[email protected]</a>&gt;
<br>
<b>Sent:</b> Wednesday, May 27, 2026 3:10 PM<br>
<b>To:</b> Giuseppe Fioccola &lt;<a href=3D"mailto:giuseppe.fioccola@huawei=
.com">[email protected]</a>&gt;;
<a href=3D"mailto:[email protected]">draft-ietf-=
[email protected]</a>; IPPM Chairs &lt;<a href=3D"mailto:ip=
[email protected]">[email protected]</a>&gt;;
<a href=3D"mailto:[email protected]">[email protected]</a>; <a href=3D"mailto:bmwg@=
ietf.org">
[email protected]</a>; <a href=3D"mailto:[email protected]">bmwg-chairs@ietf=
.org</a><br>
<b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (E=
nds 2026-05-28)<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Dear Guiseppe,<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">OK, so that scenari=
o is possible.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">You may notice that=
 I am interested in the network performance from the network user perspecti=
ve.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">It is the question =
if the user domain could form such a controlled domain, and the packets are=
 allowed to travel though a foreign domain.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">From a security per=
spective, one needs to know one thing: was my packet (the alternate marker)=
 manipulated by the foreign domain?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">This can be achieve=
d with cryptographic signatures, so that would need to be designed into the=
 measurement protocols (alternate marker data).<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">(Removal of alterna=
te marker data is also a manipulation of the packet and can be detected by =
the user.)<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">I think a controlle=
d user domain would be characterised by a shared secret for signing / encry=
ption.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">A user on the netwo=
rk edge, owning ten- to hundred-thousand machines forming a distributed sys=
tem, is a common use-case.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">In particular, when=
 the distributed system must be capable of adjusting to the network conditi=
ons, alternate marking methods could also be used.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Then the use of alt=
ernate markers by the user and the network owner should not collide.<o:p></=
o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">One (off topic) thi=
ng I would be interested in, is what fields are typically used for alternat=
e marking methods, and if signatures come into question for that?<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Best regards,<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Tjeerd<o:p></o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;ms=
o-ligatures:none">From:</span></b><span lang=3D"EN-US" style=3D"font-size:1=
1.0pt;mso-ligatures:none"> Giuseppe Fioccola &lt;</span><span lang=3D"EN-US=
"><a href=3D"mailto:[email protected]"><span style=3D"font-size:=
11.0pt;mso-ligatures:none">[email protected]</span></a></span><s=
pan lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">&gt;
<br>
<b>Sent:</b> Donnerstag, 21. Mai 2026 10:32<br>
<b>To:</b> Pinkert, Tjeerd (SMO RI ML COC SM 2) &lt;</span><span lang=3D"EN=
-US"><a href=3D"mailto:[email protected]"><span style=3D"font-size=
:11.0pt;mso-ligatures:none">[email protected]</span></a></span><sp=
an lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">&gt;;
</span><span lang=3D"EN-US"><a href=3D"mailto:draft-ietf-ippm-alt-mark-depl=
[email protected]"><span style=3D"font-size:11.0pt;mso-ligatures:none">draft-=
[email protected]</span></a></span><span lang=3D"EN-US=
" style=3D"font-size:11.0pt;mso-ligatures:none">;
 IPPM Chairs &lt;</span><span lang=3D"EN-US"><a href=3D"mailto:ippm-chairs@=
ietf.org"><span style=3D"font-size:11.0pt;mso-ligatures:none">ippm-chairs@i=
etf.org</span></a></span><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso=
-ligatures:none">&gt;;
</span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span style=3D=
"font-size:11.0pt;mso-ligatures:none">[email protected]</span></a></span><span =
lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">;
</span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span style=3D=
"font-size:11.0pt;mso-ligatures:none">[email protected]</span></a></span><span =
lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">;
</span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span s=
tyle=3D"font-size:11.0pt;mso-ligatures:none">[email protected]</span></a=
></span><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">=
<br>
<b>Subject:</b> RE: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (E=
nds 2026-05-28)<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Hi T=
jeerd,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Than=
k you for the question.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Yes,=
 it would be possible. But, for security reasons,</span><span lang=3D"EN-US=
">
</span><span lang=3D"EN-US" style=3D"font-size:11.0pt">In-Data-Packet OAM m=
ethods, such as Alternate-Marking and IOAM, should be applied to limited/co=
ntrolled domains. You can find more details about this requirement in RFC 9=
341 and RFC 9197. It was initially discussed
 in RFC 8799.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p=
>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Rega=
rds,<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p=
>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt">Gius=
eppe<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span lang=3D"EN-US" style=3D"font-size:11.0pt"><o:p=
>&nbsp;</o:p></span></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;ms=
o-ligatures:none">From:</span></b><span lang=3D"EN-US" style=3D"font-size:1=
1.0pt;mso-ligatures:none"> Pinkert, Tjeerd &lt;</span><span lang=3D"EN-US">=
<a href=3D"mailto:[email protected]"><span style=3D"font-size:11.0=
pt;mso-ligatures:none">[email protected]</span></a></span><span la=
ng=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">&gt;
<br>
<b>Sent:</b> Wednesday, May 20, 2026 4:19 PM<br>
<b>To:</b> </span><span lang=3D"EN-US"><a href=3D"mailto:draft-ietf-ippm-al=
[email protected]"><span style=3D"font-size:11.0pt;mso-ligatures:n=
one">[email protected]</span></a></span><span la=
ng=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">;
 IPPM Chairs &lt;</span><span lang=3D"EN-US"><a href=3D"mailto:ippm-chairs@=
ietf.org"><span style=3D"font-size:11.0pt;mso-ligatures:none">ippm-chairs@i=
etf.org</span></a></span><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso=
-ligatures:none">&gt;;
</span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span style=3D=
"font-size:11.0pt;mso-ligatures:none">[email protected]</span></a></span><span =
lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">;
</span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span style=3D=
"font-size:11.0pt;mso-ligatures:none">[email protected]</span></a></span><span =
lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">;
</span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><span s=
tyle=3D"font-size:11.0pt;mso-ligatures:none">[email protected]</span></a=
></span><span lang=3D"EN-US" style=3D"font-size:11.0pt;mso-ligatures:none">=
<br>
<b>Subject:</b> Re: WG Last Call: draft-ietf-ippm-alt-mark-deployment-05 (E=
nds 2026-05-28)<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><span lang=3D"EN-US"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">Dear all,<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">I&#8217;m just wond=
ering, can internet users form a controlled (boundary) domain and apply the=
 alternate marking method independently of the controlled network domain?<o=
:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">This should be poss=
ible, but is not very deeply explored?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt">(Or maybe I&#8217;m=
 just missing the point, and the remarks on encapsulating traffic cover thi=
s sufficiently?)<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:12.0pt"><o:p>&nbsp;</o:p></=
span></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Arial&quot;,sans-se=
rif;color:black;mso-ligatures:none">With best regards,<br>
Dr. Tjeerd Pinkert<br>
<br>
Siemens Mobility GmbH<br>
Mobility<br>
Rail Infrastructure<br>
System Management 2<br>
SMO RI ML COC SM 2<br>
Ackerstr. 22<br>
38126 Braunschweig, Germany<br>
Phone: +49 (1520) 2884088<br>
Mobile: +49 (1520) 2884088<br>
</span><span lang=3D"EN-US"><a href=3D"mailto:[email protected]"><=
span lang=3D"EN-GB" style=3D"font-family:&quot;Arial&quot;,sans-serif;color=
:blue;mso-ligatures:none">mailto:[email protected]</span></a></spa=
n><span style=3D"font-family:&quot;Arial&quot;,sans-serif;color:black;mso-l=
igatures:none"><br>
</span><span lang=3D"EN-US"><a href=3D"https://www.siemens.com" target=3D"_=
blank"><span lang=3D"EN-GB" style=3D"font-family:&quot;Arial&quot;,sans-ser=
if;color:blue;mso-ligatures:none">www.siemens.com</span></a></span><span st=
yle=3D"font-family:&quot;Arial&quot;,sans-serif;color:black;mso-ligatures:n=
one"><br>
<img border=3D"0" width=3D"202" height=3D"80" style=3D"width:2.1041in;heigh=
t:.8333in" id=3D"Picture_x0020_1" src=3D"cid:image001.gif-I/[email protected]=
" alt=3D"Logo"><br>
</span><span style=3D"font-size:8.0pt;font-family:&quot;Arial&quot;,sans-se=
rif;color:black;mso-ligatures:none">Siemens Mobility GmbH; Chairman of the =
Supervisory Board: Roland Busch; Management Board: Beatrice Bock, Michael P=
eter; Registered office: Munich, Germany; Commercial
 registry Munich, HRB 237219; WEEE-Reg.-No. DE 92917817</span><o:p></o:p></=
p>
</div>
</body>
</html>

--_000_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_--

--_004_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_
Content-Type: image/gif; name="image001.gif"
Content-Description: image001.gif
Content-Disposition: inline; filename="image001.gif"; size=2730;
 creation-date="Thu, 28 May 2026 16:12:40 GMT";
 modification-date="Thu, 28 May 2026 16:12:41 GMT"
Content-ID: <image001.gif-I/[email protected]>
Content-Transfer-Encoding: base64

R0lGODlhygBQAPcAAAAAAP///wCZmQCamgCYmACXlwCUlACTkwCRkQCOjgCNjQCLiwKamgKZmQKT
kwOXlwSZmQSVlQWamgWXlwabmwaXlweZmQiYmAmbmwmXlwqdnQqamgqWlguZmQ2eng2amg6cnA2X
lw6amhCfnxGcnBGbmxKcnBOenhKWlhSfnxWdnRafnxeiohehoRednRihoRmfnxqiohugoBygoBub
mx2jox6kpB6ioiCkpB+hoSCjoyChoSKlpSKioiWnpySkpCenpyelpSqrqymoqCmnpyikpCqoqCun
pyqlpSqjoyyqqiypqS6pqS+qqi6npzCrqzKrqzGoqDOsrDStrTWurjatrTWrqzeurjeqqjmtrTuw
sDqsrD2xsT+ysj2trT+xsT6urj+vr0Kzs0GxsUCurkCtrUO0tEKxsUOyska0tEe1tUezs0m2tkex
sUm1tUiysku2tky3t0y1tU+4uE63t020tE2zs1C4uE+1tVG3t1K4uFW7u1W5uVe6ule5uVq8vFu7
u129vV27u1+9vWC+vmG/v2C9vWK/v2TBwWPAwGfDw2bAwGnCwmvDw2nAwGrAwG3ExGzCwm/FxXPH
x3HDw3XGxn3Ly3rGxn3JyYDMzH/Ly4HLy4XOzofPz4XMzIfNzYnPz4jNzYrPz43S0ovQ0IzQ0I7R
0ZHS0pHR0ZTU1JPT05LR0ZfW1pXT05fV1ZjV1ZnW1prW1prU1J3Y2J3X15/Y2J7X153V1aLa2qHY
2KXb26PZ2afb26nc3Kve3qnb263f36vd3azd3a/f37Lh4bHg4LDf37Xh4bfi4rbg4Lvk5L3m5rvj
473l5b/m5r7l5cHn58Ln58bp6cTn58nq6sbn58rq6sjo6Mzr687s7NHt7dPt7dXu7tnw8Nrw8Nnv
793y8tzx8d/z8+H09OL09OHz8+T19eLz8+f29un39+f19ev4+Or39+75+fH6+u/4+PH5+fX8/PP6
+vX7+/f8/Pb7+/n9/fv+/vr9/fz+/v7//////wAAAAAAAAAAAAAAACH/C05FVFNDQVBFMi4wAwEA
AAAh+QQFAAD7ACwAAAAAygBQAAAI/wADCBxIsKDBgwgTKlzIsKHDhxAjSpxIsaLFixgzatzIsaPH
jyBDihxJsqTJkyhTqlzJsqXLlzBjypxJs6bNmzhz6tzJs6fPn0CDCh1KtKjRo0iTKl3KtKnTp1Cj
Sp1KtarVq1izat3KtavXr2DDih1LtqzZs2gh5ku37Zo2cvX0GcxHt27Bunjz0pUrMN+9vAv16b37
V29evgEEA55rF6G7btaseWuXbym2UGhaUIBAYcQQOpe0EZwEBg0aL47aDUwnqLTp17DRlME1sNQW
2GEI2UPYrc6X12H8mBt4D5OX2MjBWBqIjMyZ115q3V0U5ksd0QTR2QLEQwMECRpsfP95FAypKBMI
DhQgwL5AgQMKQBHkksCAgQRO0A0Ul6O+/f8A3qfJQIQoAOABByCDkCUG/oeACt0MZI8dDQYIYAJs
DMRKAgf8l8AQ9BB0DxEIIMDBMwQpEwWC67FHQAEGKEDFUad0OIAABnQIo30ImEKQGgYIIMABVqQz
EDlBBCnAADsGmEAmAyFygJBUGqDHQflMYcCNQhpwQzgS5jHlkgRYeB8cA81iAAFU4piKiFAYUEAJ
0QyEzQkILPnefx0i0IVR2qgQ5ItMaNJLMKxAUgUKpfyoJJFGCoSkkgS0sIQRmGaaxCtRjkllASZQ
Y9AzD7SJ45dhjkmAB5dmimkSkKT/uWabBuCgDnFxzllnAPjAkacABazAyC7C5GKJGzT8WVQnB7Bp
ABD6EUTPNN84KiSkRyZ5rSbyvOPtt++EKJCUpg65XEF6eNolqgLZI2aXcXQLrrfzyMomlQQcgAmu
ctIpEDYqFADsB8MYxM00RiHyqwFUVLYQkNcWme2jnTBELrBUHnBGvXaSIPC9p4LZ7rtDXrmQmmyC
fMARkd6Tq78B+DKBwAWoYI1TiqhKAB7VPPyoxJJqOyQnFjfLgBD3FvAAigNZggB7PkiwrsgBuDvm
AXcwhLIAFAh8bcUBuNzvrsNU4HUBRNjiDlM1qrzBIcSIaxDEQwIdwKTXNrqQlC9y/+KD1wcEMpA8
Y6jXAiMXTJ3qtXtovaYBd1yhZAEtgBP2y7tyA4OSOGoMSzlKmaODp0wicEEWvSA2EN3YBj35FIkU
Irvsf0hDELkHAPPJmAVgUG0AyERAAAKE6FJqyIsDa0PssxcCiC4EoXxAJcQ0KyQCklw+tkD6JPKr
kPka0IMm7yQVTAfqAtshHzdbW3ekdwutPoL0K0DL7VMe4Is2D9x7wLnpIkAEiCEMJXmJalb7FP3q
54jorekAjEjHEcZkAB7cCnMDOQcTEFAALgmgTAhgwi7wgRRkYKFDpspXCWizup/BD29Ces8C4TML
/A0JF/OowtW4oA9tWKBMVaAHLf8oyK6qkWx+C1TAIxyYr0MEgBUOSJm+AiCF7Q0EHIEwwNNMlaNF
qOYo7IhFFuzjtSUd4ALKaGHEXii0AiyhD3qIYxzrwLRx5a+GprBeATogjVLkr1GxICICSVaAGPBB
jnG0wy2YeABCBGAeX5hcCrLBBSsOJB/HAMQF1AOyAiTgXEipRy64kIFZXW8RfGGd3WB4gIrp45Ww
LAjuaiiOGxjwD1xYjwW4EYBAKm5kV7sSLGPJSEcGoBeeQkAlxGDJgkwjEC5QT8Z+QI6l2OMYfVjP
taqwDoGoko2PItre7igQSHCuAWbsg1x8iTxgXitrJ3ugMd1hhS0B6wUseBHMEIL/jUyA4GwFaEZT
6OEGAwZhHN504cSuJU6FzFIgyiijiwrADIGw84DJw5rj8mXMABjDlNrUFUNOQSkDAIMo+FDdaK62
hfIF4JsLHZKPxjmkGgaAHk3g3JDWwLGLFjGBQ2pcPDlKHD58L4Ywy8duDoKN/n2wANAgCjUM4Qpl
ZIMc7niHN3pRA68hoBFqfF9MDTCHWMDirGhNhYLsWNOB1AhfBxjFQHw6SAo+waxoPWsqeBEPgUiv
o8DLQBmBBTN6SMISxaBGON4BD3I4g3VHiJZQlHEABHwABj9QghFuMLNrhUCgCV1jTIFlpgSYoVNt
FUg5eGDAE2Cnl4JMHmkthIAd/0Trr9JKg7pEetMhJOACKtCBEZbwgxJM7pNFWYYI5OQeMhKgdCS4
X1hbFz/Ouei6+coQWw9gU4FMYkoDCBxB6CrbD2K3TD+IFG4JEo0ffgpm9piCeppLxmsdwIvJrQCH
EGQfBHGwDVEliBYUgCAFIEGy4pABgWc4QwWIYSCBWAB8WEGQYZQIAQaw3UBaseAEnMAbEnqDhBm8
wATMIFobQsAC+mCQQiz4AAmIAGjxIYX98jdHCCqCKo4Cj2KcAhOGkMMYxiCHSJQCGfIwiDFQoQpV
rOIXfRWIPHaxiiZb+cpNXkUxBtIMJqOClwNpxycoQQlSqI4bVXZyLeBxyWQwGXTLWF7FLjiGZidX
tCDgeLMqTiGL4QjkGq/wRCTugIYvpGEQm9DFOZqiGJWmZSCKcdijJ03pSlv60pjOtKY3zelOe/rT
oA61qEdN6lKb+tSoTrWqV83qVrv61bCOtaxnTeta2/rWuM61rnfN6177+tfAtklAAAA7

--_004_DB9PR10MB59314877654629661A44EBB686092DB9PR10MB5931EURP_--


--===============1081513057947601024==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KaXBwbSBtYWls
aW5nIGxpc3QgLS0gaXBwbUBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRv
IGlwcG0tbGVhdmVAaWV0Zi5vcmcK

--===============1081513057947601024==--