[spring] Re: Requirements on SRv6+VPN+ICMP (was New draft : draft-varhal-6man-icmp-srv6-vpn-00.txt)

Krzysztof Szarkowicz <[email protected]> Thu, 5 Mar 2026 14:21:50 +0100
Newsgroups gmane.ietf.spring,gmane.ietf.ipv6
Message-ID <[email protected]>
--===============6088944114830868678==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_0D88363D-8FC0-4660-9E2A-A34DA4234A36"


--Apple-Mail=_0D88363D-8FC0-4660-9E2A-A34DA4234A36
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

HI Bal=C3=A1zs,

I am not sure, what you mean by =E2=80=9Ccompliant to existing =
standards=E2=80=9D. Are you planning for =E2=80=9CInformational" (not =
=E2=80=9CStandard Track=E2=80=9D) RFC? Please note, that =
draft-varhal-6man-icmp-srv6-vpn changes (comparing to =E2=80=9Cexisting =
standards=E2=80=9D) the ICMP processing on PE node, while =
draft-ali-6man-srv6-vpn-icmp-error-handling changes the ICMP processing =
on P node -> both proposals modify some existing standards.

For the requirements, in addition to listed requirements (except R5, =
which is not fully clear to me), important is:

1) should work in mixed MPLS/SRv6 environment (migration scenarios): =
Mo6, 6oM, MPLS<->SRv6 encap conversions
2) invoking node, initiating IPv4 traceroute, should be able to display =
real IPv4 address of the P node, if P node has IPv4 address, in addition =
to IPv6 address (again, mixed MPLS/SRv6 environment during migrations)
3) invoking node, initiating IPv4 traceroute, should be able to display =
real IPv6 address of the P node, if P node has only IPv6 address (pure =
SRv6 environment)
4) should work in architectures with multi-level IP encapsulations (i.e. =
at some transit node without service awareness additional IP =
encapsulation is pushed on the packet -> for example expansion of B-SID =
with =E2=80=98Encaps=E2=80=99 flavor)

Cheers,
Krzysztof


> On 2026 Mar 4, at 15:42, Bal=C3=A1zs Varga A =
<[email protected]> wrote:
>=20
> Hi,
> =20
> this is a mail thread to sort out the expectations on=20
> a VPN ping/trace solution in SRv6 networks. It was=20
> triggered by discussions on the mailing list, after
> two solutions were drafted (so far).
> The two drafts are:
> - draft-ali-6man-srv6-vpn-icmp-error-handling
> - draft-varhal-6man-icmp-srv6-vpn
> =20
> Background:
> Diagnostics in VPNs has its own challenges. It was=20
> identified and solved for MPLS based VPNs in the past.=20
> MPLS technology has its special encapsulation, i.e.,=20
> the MPLS header is a label stack. In case of MPLS, P=20
> routers have no options to identify the ingress of=20
> the MPLS tunnel, as labels in the header point=20
> towards the network egress point. This characteristic=20
> restricted the possible solutions to provide VPN=20
> specific ICMP handling in MPLS networks.
> =20
> SRv6 has a different encapsulation, that could make=20
> it possible to remove some of the restrictions of
> the MPLS based approach. Maybe one the most painful=20
> limitation of MPLS VPN trace is that it requires
> failure-free path between the ingress PE and the=20
> egress PE, what limits its usability during=20
> troubleshooting.=20
> =20
> So, now we have the opportunity to make VPN trace
> differently in SRv6 networks, IF it is worth to do
> so. Please, share your view and help to extend or
> simplify the requirement list below.
> =20
> List of minimum expectations identified so far:
> R1) able to identify the location of a broken=20
> connectivity between ingress-PE and egress-PE
> R2) keep P nodes service agnostic
> R3) support IPv6-only P nodes=20
> R4) support any VPN topology
> R5) compliant to existing standards, like [RFC4443]
> R6) ... other ???
> =20
> It is always good to agree on WHAT we intend to solve.=20
> Please, chime in and share your view.
> =20
> Thanks & Cheers
> Bala'zs
> _______________________________________________
> spring mailing list -- [email protected] <mailto:[email protected]>
> To unsubscribe send an email to [email protected] =
<mailto:[email protected]>

--Apple-Mail=_0D88363D-8FC0-4660-9E2A-A34DA4234A36
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html aria-label=3D"message body"><head><meta http-equiv=3D"content-type" =
content=3D"text/html; charset=3Dutf-8"></head><body =
style=3D"overflow-wrap: break-word; -webkit-nbsp-mode: space; =
line-break: after-white-space;">HI Bal=C3=A1zs,<div><br></div><div>I am =
not sure, what you mean by =E2=80=9Ccompliant to existing standards=E2=80=9D=
. Are you planning for =E2=80=9CInformational" (not =E2=80=9CStandard =
Track=E2=80=9D) RFC? Please note, =
that&nbsp;draft-varhal-6man-icmp-srv6-vpn changes (comparing to =
=E2=80=9Cexisting standards=E2=80=9D) the ICMP processing on PE node, =
while&nbsp;draft-ali-6man-srv6-vpn-icmp-error-handling changes the ICMP =
processing on P node -&gt; both proposals modify some existing =
standards.</div><div><br></div><div>For the requirements, in addition to =
listed requirements (except R5, which is not fully clear to me), =
important is:</div><div><br></div><div>1) should work in mixed MPLS/SRv6 =
environment (migration scenarios): Mo6, 6oM, MPLS&lt;-&gt;SRv6 encap =
conversions</div><div>2) invoking node, initiating IPv4 traceroute, =
should be able to display real IPv4 address of the P node, if P node has =
IPv4 address, in addition to IPv6 address (again, mixed MPLS/SRv6 =
environment during migrations)</div><div>3) invoking node, initiating =
IPv4 traceroute, should be able to display real IPv6 address of the P =
node, if P node has only IPv6 address (pure SRv6 =
environment)</div><div>4) should work in architectures with multi-level =
IP encapsulations (i.e. at some transit node without service awareness =
additional IP encapsulation is pushed on the packet -&gt; for example =
expansion of B-SID with =E2=80=98Encaps=E2=80=99 =
flavor)</div><div><br></div><div>Cheers,</div><div>Krzysztof</div><div><br=
 id=3D"lineBreakAtBeginningOfMessage"><div><br><blockquote =
type=3D"cite"><div>On 2026 Mar 4, at 15:42, Bal=C3=A1zs Varga A =
&lt;[email protected]&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div><meta charset=3D"UTF-8"><div =
class=3D"WordSection1" style=3D"page: WordSection1; caret-color: rgb(0, =
0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: 400; letter-spacing: normal; =
orphans: 2; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration-line: none; =
text-decoration-thickness: auto; text-decoration-style: solid;"><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">Hi,<o:p></o:p></div><div style=3D"margin: 0in; font-size: =
12pt; font-family: Aptos, sans-serif;"><o:p>&nbsp;</o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">this is a mail thread to sort out the expectations on<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">a VPN ping/trace solution in SRv6 networks. It was<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">triggered by discussions on the mailing list, =
after<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; =
font-family: Aptos, sans-serif;">two solutions were drafted (so =
far).<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; =
font-family: Aptos, sans-serif;">The two drafts =
are:<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; =
font-family: Aptos, sans-serif;">- =
draft-ali-6man-srv6-vpn-icmp-error-handling<o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;"><span lang=3D"DE">- =
draft-varhal-6man-icmp-srv6-vpn<o:p></o:p></span></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;"><span lang=3D"DE"><o:p>&nbsp;</o:p></span></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">Background:<o:p></o:p></div><div style=3D"margin: 0in; =
font-size: 12pt; font-family: Aptos, sans-serif;">Diagnostics in VPNs =
has its own challenges. It was<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">identified and solved for MPLS based VPNs in the past.<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">MPLS technology has its special encapsulation, i.e.,<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">the MPLS header is a label stack. In case of MPLS, P<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">routers have no options to identify the ingress of<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">the MPLS tunnel, as labels in the header point<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">towards the network egress point. This characteristic<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">restricted the possible solutions to provide VPN<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">specific ICMP handling in MPLS =
networks.<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; =
font-family: Aptos, sans-serif;"><o:p>&nbsp;</o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">SRv6 has a different encapsulation, that could make<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">it possible to remove some of the restrictions =
of<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; =
font-family: Aptos, sans-serif;">the MPLS based approach. Maybe one the =
most painful<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">limitation of MPLS VPN trace is that it =
requires<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; =
font-family: Aptos, sans-serif;">failure-free path between the ingress =
PE and the<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">egress PE, what limits its usability during<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">troubleshooting.<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in; =
font-size: 12pt; font-family: Aptos, sans-serif;">So, now we have the =
opportunity to make VPN trace<o:p></o:p></div><div style=3D"margin: 0in; =
font-size: 12pt; font-family: Aptos, sans-serif;">differently in SRv6 =
networks, IF it is worth to do<o:p></o:p></div><div style=3D"margin: =
0in; font-size: 12pt; font-family: Aptos, sans-serif;">so. Please, share =
your view and help to extend or<o:p></o:p></div><div style=3D"margin: =
0in; font-size: 12pt; font-family: Aptos, sans-serif;">simplify the =
requirement list below.<o:p></o:p></div><div style=3D"margin: 0in; =
font-size: 12pt; font-family: Aptos, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in; =
font-size: 12pt; font-family: Aptos, sans-serif;">List of minimum =
expectations identified so far:<o:p></o:p></div><div style=3D"margin: =
0in; font-size: 12pt; font-family: Aptos, sans-serif;">R1) able to =
identify the location of a broken<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">connectivity between ingress-PE and =
egress-PE<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; =
font-family: Aptos, sans-serif;">R2) keep P nodes service =
agnostic<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; =
font-family: Aptos, sans-serif;">R3) support IPv6-only P nodes<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">R4) support any VPN topology<o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">R5) compliant to existing standards, like =
[RFC4443]<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; =
font-family: Aptos, sans-serif;">R6) ... other ???<o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in; =
font-size: 12pt; font-family: Aptos, sans-serif;">It is always good to =
agree on WHAT we intend to solve.<span =
class=3D"Apple-converted-space">&nbsp;</span><o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;">Please, chime in and share your view.<o:p></o:p></div><div =
style=3D"margin: 0in; font-size: 12pt; font-family: Aptos, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in; =
font-size: 12pt; font-family: Aptos, sans-serif;">Thanks &amp; =
Cheers<o:p></o:p></div><div style=3D"margin: 0in; font-size: 12pt; =
font-family: Aptos, sans-serif;">Bala'zs<o:p></o:p></div></div><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline =
!important;">_______________________________________________</span><br =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration-line: none; =
text-decoration-thickness: auto; text-decoration-style: solid;"><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;">spring mailing list --<span =
class=3D"Apple-converted-space">&nbsp;</span></span><a =
href=3D"mailto:[email protected]" style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; widows: 2; =
word-spacing: 0px; -webkit-text-stroke-width: =
0px;">[email protected]</a><br style=3D"caret-color: rgb(0, 0, 0); =
font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: 400; letter-spacing: normal; =
orphans: 2; text-align: start; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration-line: none; =
text-decoration-thickness: auto; text-decoration-style: solid;"><span =
style=3D"caret-color: rgb(0, 0, 0); font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: 400; =
letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; text-decoration: none; float: none; =
display: inline !important;">To unsubscribe send an email to<span =
class=3D"Apple-converted-space">&nbsp;</span></span><a =
href=3D"mailto:[email protected]" style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; widows: 2; =
word-spacing: 0px; -webkit-text-stroke-width: =
0px;">[email protected]</a></div></blockquote></div><br></div></body><=
/html>=

--Apple-Mail=_0D88363D-8FC0-4660-9E2A-A34DA4234A36--


--===============6088944114830868678==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc3ByaW5nIG1h
aWxpbmcgbGlzdCAtLSBzcHJpbmdAaWV0Zi5vcmcKVG8gdW5zdWJzY3JpYmUgc2VuZCBhbiBlbWFp
bCB0byBzcHJpbmctbGVhdmVAaWV0Zi5vcmcK

--===============6088944114830868678==--