[spring] Re: Requirements on SRv6+VPN+ICMP (was New draft : draft-varhal-6man-icmp-srv6-vpn-00.txt)
Krzysztof Szarkowicz <[email protected]> Thu, 5 Mar 2026 14:21:50 +0100
| Newsgroups | gmane.ietf.spring,gmane.ietf.ipv6 |
|---|---|
| Message-ID | <[email protected]> |
--===============6088944114830868678== Content-Type: multipart/alternative; boundary="Apple-Mail=_0D88363D-8FC0-4660-9E2A-A34DA4234A36" --Apple-Mail=_0D88363D-8FC0-4660-9E2A-A34DA4234A36 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 HI Bal=C3=A1zs, I am not sure, what you mean by =E2=80=9Ccompliant to existing = standards=E2=80=9D. Are you planning for =E2=80=9CInformational" (not = =E2=80=9CStandard Track=E2=80=9D) RFC? Please note, that = draft-varhal-6man-icmp-srv6-vpn changes (comparing to =E2=80=9Cexisting = standards=E2=80=9D) the ICMP processing on PE node, while = draft-ali-6man-srv6-vpn-icmp-error-handling changes the ICMP processing = on P node -> both proposals modify some existing standards. For the requirements, in addition to listed requirements (except R5, = which is not fully clear to me), important is: 1) should work in mixed MPLS/SRv6 environment (migration scenarios): = Mo6, 6oM, MPLS<->SRv6 encap conversions 2) invoking node, initiating IPv4 traceroute, should be able to display = real IPv4 address of the P node, if P node has IPv4 address, in addition = to IPv6 address (again, mixed MPLS/SRv6 environment during migrations) 3) invoking node, initiating IPv4 traceroute, should be able to display = real IPv6 address of the P node, if P node has only IPv6 address (pure = SRv6 environment) 4) should work in architectures with multi-level IP encapsulations (i.e. = at some transit node without service awareness additional IP = encapsulation is pushed on the packet -> for example expansion of B-SID = with =E2=80=98Encaps=E2=80=99 flavor) Cheers, Krzysztof > On 2026 Mar 4, at 15:42, Bal=C3=A1zs Varga A = <[email protected]> wrote: >=20 > Hi, > =20 > this is a mail thread to sort out the expectations on=20 > a VPN ping/trace solution in SRv6 networks. It was=20 > triggered by discussions on the mailing list, after > two solutions were drafted (so far). > The two drafts are: > - draft-ali-6man-srv6-vpn-icmp-error-handling > - draft-varhal-6man-icmp-srv6-vpn > =20 > Background: > Diagnostics in VPNs has its own challenges. It was=20 > identified and solved for MPLS based VPNs in the past.=20 > MPLS technology has its special encapsulation, i.e.,=20 > the MPLS header is a label stack. In case of MPLS, P=20 > routers have no options to identify the ingress of=20 > the MPLS tunnel, as labels in the header point=20 > towards the network egress point. This characteristic=20 > restricted the possible solutions to provide VPN=20 > specific ICMP handling in MPLS networks. > =20 > SRv6 has a different encapsulation, that could make=20 > it possible to remove some of the restrictions of > the MPLS based approach. Maybe one the most painful=20 > limitation of MPLS VPN trace is that it requires > failure-free path between the ingress PE and the=20 > egress PE, what limits its usability during=20 > troubleshooting.=20 > =20 > So, now we have the opportunity to make VPN trace > differently in SRv6 networks, IF it is worth to do > so. Please, share your view and help to extend or > simplify the requirement list below. > =20 > List of minimum expectations identified so far: > R1) able to identify the location of a broken=20 > connectivity between ingress-PE and egress-PE > R2) keep P nodes service agnostic > R3) support IPv6-only P nodes=20 > R4) support any VPN topology > R5) compliant to existing standards, like [RFC4443] > R6) ... other ??? > =20 > It is always good to agree on WHAT we intend to solve.=20 > Please, chime in and share your view. > =20 > Thanks & Cheers > Bala'zs > _______________________________________________ > spring mailing list -- [email protected] <mailto:[email protected]> > To unsubscribe send an email to [email protected] = <mailto:[email protected]> --Apple-Mail=_0D88363D-8FC0-4660-9E2A-A34DA4234A36 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html aria-label=3D"message body"><head><meta http-equiv=3D"content-type" = content=3D"text/html; charset=3Dutf-8"></head><body = style=3D"overflow-wrap: break-word; -webkit-nbsp-mode: space; = line-break: after-white-space;">HI Bal=C3=A1zs,<div><br></div><div>I am = not sure, what you mean by =E2=80=9Ccompliant to existing standards=E2=80=9D= . Are you planning for =E2=80=9CInformational" (not =E2=80=9CStandard = Track=E2=80=9D) RFC? Please note, = that draft-varhal-6man-icmp-srv6-vpn changes (comparing to = =E2=80=9Cexisting standards=E2=80=9D) the ICMP processing on PE node, = while draft-ali-6man-srv6-vpn-icmp-error-handling changes the ICMP = processing on P node -> both proposals modify some existing = standards.</div><div><br></div><div>For the requirements, in addition to = listed requirements (except R5, which is not fully clear to me), = important is:</div><div><br></div><div>1) should work in mixed MPLS/SRv6 = environment (migration scenarios): Mo6, 6oM, MPLS<->SRv6 encap = conversions</div><div>2) invoking node, initiating IPv4 traceroute, = should be able to display real IPv4 address of the P node, if P node has = IPv4 address, in addition to IPv6 address (again, mixed MPLS/SRv6 = environment during migrations)</div><div>3) invoking node, initiating = IPv4 traceroute, should be able to display real IPv6 address of the P = node, if P node has only IPv6 address (pure SRv6 = environment)</div><div>4) should work in architectures with multi-level = IP encapsulations (i.e. at some transit node without service awareness = additional IP encapsulation is pushed on the packet -> for example = expansion of B-SID with =E2=80=98Encaps=E2=80=99 = flavor)</div><div><br></div><div>Cheers,</div><div>Krzysztof</div><div><br= id=3D"lineBreakAtBeginningOfMessage"><div><br><blockquote = type=3D"cite"><div>On 2026 Mar 4, at 15:42, Bal=C3=A1zs Varga A = <[email protected]> wrote:</div><br = class=3D"Apple-interchange-newline"><div><meta charset=3D"UTF-8"><div = class=3D"WordSection1" style=3D"page: WordSection1; caret-color: rgb(0, = 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; = font-variant-caps: normal; font-weight: 400; letter-spacing: normal; = orphans: 2; text-align: start; text-indent: 0px; text-transform: none; = white-space: normal; widows: 2; word-spacing: 0px; = -webkit-text-stroke-width: 0px; text-decoration-line: none; = text-decoration-thickness: auto; text-decoration-style: solid;"><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">Hi,<o:p></o:p></div><div style=3D"margin: 0in; font-size: = 12pt; font-family: Aptos, sans-serif;"><o:p> </o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">this is a mail thread to sort out the expectations on<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">a VPN ping/trace solution in SRv6 networks. It was<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">triggered by discussions on the mailing list, = after<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; = font-family: Aptos, sans-serif;">two solutions were drafted (so = far).<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; = font-family: Aptos, sans-serif;">The two drafts = are:<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; = font-family: Aptos, sans-serif;">- = draft-ali-6man-srv6-vpn-icmp-error-handling<o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;"><span lang=3D"DE">- = draft-varhal-6man-icmp-srv6-vpn<o:p></o:p></span></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;"><span lang=3D"DE"><o:p> </o:p></span></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">Background:<o:p></o:p></div><div style=3D"margin: 0in; = font-size: 12pt; font-family: Aptos, sans-serif;">Diagnostics in VPNs = has its own challenges. It was<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">identified and solved for MPLS based VPNs in the past.<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">MPLS technology has its special encapsulation, i.e.,<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">the MPLS header is a label stack. In case of MPLS, P<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">routers have no options to identify the ingress of<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">the MPLS tunnel, as labels in the header point<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">towards the network egress point. This characteristic<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">restricted the possible solutions to provide VPN<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">specific ICMP handling in MPLS = networks.<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; = font-family: Aptos, sans-serif;"><o:p> </o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">SRv6 has a different encapsulation, that could make<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">it possible to remove some of the restrictions = of<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; = font-family: Aptos, sans-serif;">the MPLS based approach. Maybe one the = most painful<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">limitation of MPLS VPN trace is that it = requires<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; = font-family: Aptos, sans-serif;">failure-free path between the ingress = PE and the<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">egress PE, what limits its usability during<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">troubleshooting.<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;"><o:p> </o:p></div><div style=3D"margin: 0in; = font-size: 12pt; font-family: Aptos, sans-serif;">So, now we have the = opportunity to make VPN trace<o:p></o:p></div><div style=3D"margin: 0in; = font-size: 12pt; font-family: Aptos, sans-serif;">differently in SRv6 = networks, IF it is worth to do<o:p></o:p></div><div style=3D"margin: = 0in; font-size: 12pt; font-family: Aptos, sans-serif;">so. Please, share = your view and help to extend or<o:p></o:p></div><div style=3D"margin: = 0in; font-size: 12pt; font-family: Aptos, sans-serif;">simplify the = requirement list below.<o:p></o:p></div><div style=3D"margin: 0in; = font-size: 12pt; font-family: Aptos, = sans-serif;"><o:p> </o:p></div><div style=3D"margin: 0in; = font-size: 12pt; font-family: Aptos, sans-serif;">List of minimum = expectations identified so far:<o:p></o:p></div><div style=3D"margin: = 0in; font-size: 12pt; font-family: Aptos, sans-serif;">R1) able to = identify the location of a broken<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">connectivity between ingress-PE and = egress-PE<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; = font-family: Aptos, sans-serif;">R2) keep P nodes service = agnostic<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; = font-family: Aptos, sans-serif;">R3) support IPv6-only P nodes<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">R4) support any VPN topology<o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">R5) compliant to existing standards, like = [RFC4443]<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; = font-family: Aptos, sans-serif;">R6) ... other ???<o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;"><o:p> </o:p></div><div style=3D"margin: 0in; = font-size: 12pt; font-family: Aptos, sans-serif;">It is always good to = agree on WHAT we intend to solve.<span = class=3D"Apple-converted-space"> </span><o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;">Please, chime in and share your view.<o:p></o:p></div><div = style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, = sans-serif;"><o:p> </o:p></div><div style=3D"margin: 0in; = font-size: 12pt; font-family: Aptos, sans-serif;">Thanks & = Cheers<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; = font-family: Aptos, sans-serif;">Bala'zs<o:p></o:p></div></div><span = style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: = 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; = letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; = text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; = -webkit-text-stroke-width: 0px; text-decoration: none; float: none; = display: inline = !important;">_______________________________________________</span><br = style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: = 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; = letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; = text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; = -webkit-text-stroke-width: 0px; text-decoration-line: none; = text-decoration-thickness: auto; text-decoration-style: solid;"><span = style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: = 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; = letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; = text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; = -webkit-text-stroke-width: 0px; text-decoration: none; float: none; = display: inline !important;">spring mailing list --<span = class=3D"Apple-converted-space"> </span></span><a = href=3D"mailto:[email protected]" style=3D"font-family: Helvetica; = font-size: 12px; font-style: normal; font-variant-caps: normal; = font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; = text-indent: 0px; text-transform: none; white-space: normal; widows: 2; = word-spacing: 0px; -webkit-text-stroke-width: = 0px;">[email protected]</a><br style=3D"caret-color: rgb(0, 0, 0); = font-family: Helvetica; font-size: 12px; font-style: normal; = font-variant-caps: normal; font-weight: 400; letter-spacing: normal; = orphans: 2; text-align: start; text-indent: 0px; text-transform: none; = white-space: normal; widows: 2; word-spacing: 0px; = -webkit-text-stroke-width: 0px; text-decoration-line: none; = text-decoration-thickness: auto; text-decoration-style: solid;"><span = style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: = 12px; font-style: normal; font-variant-caps: normal; font-weight: 400; = letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; = text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; = -webkit-text-stroke-width: 0px; text-decoration: none; float: none; = display: inline !important;">To unsubscribe send an email to<span = class=3D"Apple-converted-space"> </span></span><a = href=3D"mailto:[email protected]" style=3D"font-family: Helvetica; = font-size: 12px; font-style: normal; font-variant-caps: normal; = font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; = text-indent: 0px; text-transform: none; white-space: normal; widows: 2; = word-spacing: 0px; -webkit-text-stroke-width: = 0px;">[email protected]</a></div></blockquote></div><br></div></body><= /html>= --Apple-Mail=_0D88363D-8FC0-4660-9E2A-A34DA4234A36-- --===============6088944114830868678== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc3ByaW5nIG1h aWxpbmcgbGlzdCAtLSBzcHJpbmdAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFp bCB0byBzcHJpbmctbGVhdmVAaWV0Zi5vcmcK --===============6088944114830868678==--